Last updated: June 2026
DMARC Engine is a hosted email-authentication platform that helps organisations configure, monitor and enforce DMARC, SPF, DKIM, MTA-STS and BIMI, including done-for-you progression to a p=reject enforcement policy. Because we ingest DMARC reports and hold the DNS configuration and delegation that protect your domains from spoofing, security is central to how we build and operate the service. We follow a defence-in-depth model: multiple independent layers of control so that no single failure exposes your data. Our controls follow the principles of recognised frameworks such as ISO 27001 and SOC 2, and the security obligations of the UK and EU GDPR. This page describes the technical and organisational measures we apply. It complements our Privacy Policy, our Sub-processors list and our Data Processing Addendum. It is provided in good faith for transparency and may be updated as our practices evolve.
DMARC Engine runs entirely on Cloudflare's global edge platform. We operate no self-managed servers, no traditional virtual machines and no datacentre hardware of our own, which removes whole classes of patching, configuration-drift and physical-security risk from our threat model. Our compute runs on Cloudflare Workers, our relational data is stored in Cloudflare D1, raw DMARC reports are stored in Cloudflare R2 object storage, and rate-limiting and caching state lives in Cloudflare Workers KV. Cloudflare maintains independent third-party attestations for the infrastructure on which we run, including a SOC 2 Type II attestation and ISO 27001 certification, which cover the physical security, environmental controls and operational practices of its global network.
Running on Cloudflare's anycast network means requests are served from the location nearest to the user, with automatic failover between points of presence. There is no single regional server to take the service down, and capacity scales with demand rather than with manually provisioned machines.
All connections to the marketing website and the authenticated application are encrypted in transit using TLS 1.2 or higher. We serve HTTP Strict Transport Security (HSTS) with a long max-age and submit our domain to the HSTS preload list, so compliant browsers connect over HTTPS from the very first request and will not downgrade to plaintext.
Data at rest is protected by the encryption Cloudflare applies to D1, R2 and KV at the storage layer. On top of that platform encryption, we apply application-level encryption using AES-GCM to particularly sensitive stored secrets, such as two-factor authentication secrets, single sign-on client secrets and notification-channel credentials we hold on your behalf, so that they are protected even within our own data store. Account passwords are never stored in plaintext; they are stored only as salted hashes and are never recoverable in clear.
We give you tools to keep your own account secure and apply least-privilege principles internally:
Security is built into how the application is written and served rather than bolted on afterwards:
Because DMARC Engine sits behind Cloudflare's edge, every request passes through Cloudflare's Web Application Firewall (WAF) and its distributed denial-of-service (DDoS) mitigation before it reaches our application. Cloudflare's anycast network absorbs and disperses volumetric attacks across its global capacity, and its WAF filters common malicious traffic patterns at the edge. This means network-layer protection is always on, applied close to the attacker rather than at a single origin, and maintained by a provider whose core business is operating that network at scale.
We collect only the data we need to operate the service: account details, your domain and DNS configuration, the DMARC aggregate (RUA) and failure (RUF) reports ingested for your domains, billing records held with our payment processor, support correspondence and technical server logs. DMARC reports routinely contain source IP addresses, sending hostnames, authentication results, message counts and limited header metadata, which can relate to identifiable individuals and is therefore treated as personal data and protected accordingly. We do not sell personal data, and we share it only as needed to provide the service. For a full description of what we collect, the lawful bases on which we process it, and how long we retain each category, see our Privacy Policy.
We rely on a small, carefully chosen set of sub-processors to deliver the service, principally Cloudflare for hosting and infrastructure, a transactional email provider for service notifications and alerts, and a third-party payment processor for billing. Each is engaged under contractual terms requiring appropriate technical and organisational measures and restricting their use of data to providing services to us. The current list, with the purpose and processing location of each, is published on our Sub-processors page.
We maintain an append-only audit log of security-relevant actions within the platform, so that significant events, such as authentication, configuration and access changes, are recorded in a durable activity trail. Operationally, we use queryable Workers Logs to investigate issues and detect anomalies across the edge. Server logs, including IP address, request paths and timestamps, are retained for a limited period for security monitoring, abuse prevention and debugging, and are then deleted or anonymised as described in our Privacy Policy.
Running on Cloudflare's global anycast network gives the service inherent geographic redundancy and automatic failover: there is no single regional origin whose failure would take the platform offline, and traffic is routed to healthy points of presence automatically. Stateful data in D1 and R2 benefits from the durability and replication built into those managed services, and raw DMARC reports retained in R2 provide a durable record from which derived analytics can be regenerated. We build the service to degrade gracefully and recover quickly, and we keep our deployment and recovery processes scripted and repeatable so the service can be restored predictably.
We welcome reports from security researchers and treat responsible disclosure as a core part of keeping the service safe. We publish a security.txt file at /.well-known/security.txt with our current contact and disclosure details. If you believe you have found a vulnerability, please report it to us at security@dmarcengine.com or via our contact page before disclosing it publicly, and give us a reasonable opportunity to investigate and remediate. We operate a good-faith safe harbour: provided you act in good faith, avoid privacy violations, service disruption and data destruction, and do not access or modify data beyond what is necessary to demonstrate an issue, we will not pursue legal action against you for your research. We triage reports promptly, prioritise fixes by severity and keep researchers informed of progress where appropriate.
DMARC Engine is a UK-based controller and processes personal data in line with the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR. Our security controls follow the principles of ISO 27001 and SOC 2, and our infrastructure runs on Cloudflare, which holds SOC 2 Type II and ISO 27001 certifications for the hosting platform we use.
To be clear about scope: those certifications belong to Cloudflare as our infrastructure provider. DMARC Engine does not currently claim to independently hold SOC 2, ISO 27001, PCI DSS, HIPAA or Data Privacy Framework certification in its own right. Where billing is involved, card and payment-instrument details are handled directly by our PCI-compliant third-party payment processor; we do not store full card numbers on our systems. For our contractual data-protection commitments, see our Data Processing Addendum.
Access to production systems and customer data is restricted to those who need it, governed by role-based access control and the same least-privilege principles we apply throughout the platform. Administrative access is protected by strong authentication, including two-factor authentication, and significant actions are recorded in our audit trail. Because we run on a fully managed edge platform with no self-managed servers, our operational footprint is deliberately small, which reduces the number of people and systems that can touch production. We treat security as an ongoing responsibility shared across how we hire, develop and operate, not a one-time exercise.
For security questions, to report a vulnerability, or to request more detail about our controls, contact our security team at security@dmarcengine.com or use our contact page. For privacy-specific enquiries see our Privacy Policy or write to privacy@dmarcengine.com, and for general enquiries you can reach us at hello@dmarcengine.com. This page is provided in good faith for transparency and may be updated from time to time; please check back for the latest version.