OnlyDMARC ("we", "us", "our") operates the OnlyDMARC platform at onlydmarc.com and related subdomains. OnlyDMARC is designed for professional use by domain owners, IT teams, security teams, and managed service providers.
We act as a controller for account, contact, billing, security, and website data we collect directly. Where we process DMARC reports, DNS records, notification destinations, or user-management data on behalf of an organisation, we may act as a processor for that organisation.
When you create or receive an account, we collect information such as your email address, display name, organisation or billing relationship, password hash or passwordless-login state, verification status, role, security stamp, last-login information, and domain-access permissions. If you sign up for self-service onboarding, we may also store the domain you intend to monitor so the onboarding flow can continue after email verification.
To provide the service, we collect and process monitored domain names, public DNS records, DNS snapshots and changes, domain-verification challenges, sender/source classification, DMARC aggregate report metadata, individual aggregate-report rows, authentication results, policy results, sending IP addresses, message counts, and related analysis outputs.
DMARC aggregate reports are normally operational telemetry rather than message content. They can still contain personal data in edge cases, such as an IP address associated with an individual or a report producer including unexpected fields. OnlyDMARC is not designed to ingest message bodies or mailbox contents for ordinary DMARC aggregate monitoring.
If you use public tools such as DMARC, SPF, DKIM, or configuration-report checks, we process the domain, DNS results, submitted email address where required to send a report link, request metadata, rate-limit data, and anti-abuse signals such as IP address and user agent. Hosted report links and one-time or single-purpose tokens may be generated to deliver the requested result.
We record security-relevant events such as sign-in attempts, password reset or login-code events, email verification, API-key issuance or revocation, administrative actions, domain-verification actions, notification delivery state, and relevant application errors. API keys, account tokens, and verification secrets are stored hashed or otherwise protected where the application needs only to verify them.
We collect server and application logs that may include IP address, timestamps, request paths, browser or device metadata, referrer, rate-limit decisions, errors, and diagnostic context. This helps us secure, troubleshoot, and improve the service.
If you contact us by email, form, or another support channel, we retain the correspondence and related metadata so we can respond and maintain an accurate support history.
Where UK GDPR or EU GDPR applies, we rely on the following legal bases:
We do not sell personal data. We share data only where needed to provide the service, protect it, or meet legal obligations:
A current sub-processor list is available on request.
We keep account and organisation data while the account is active and for a reasonable period afterwards for support, security, legal, tax, and fraud-prevention purposes. DMARC report and DNS history retention can vary by plan, operational need, and customer agreement.
Some product areas have specific retention behaviour. Public configuration-report links expire after their configured lifetime; public checker ledgers are anonymised after their configured retention window; stale unverified self-service accounts, expired verification rows, and terminal login-code records are pruned by scheduled maintenance. Backups and logs may take longer to expire.
If you need deletion or export of personal data, contact us. We will honour valid requests unless we need to retain limited information for legal, security, accounting, or abuse-prevention reasons.
We use technical and organisational safeguards appropriate to the service, including TLS for browser and API traffic, hosted database protections, least-privilege access, role-based application permissions, hashed passwords, hashed single-use account tokens, API-key hashing, antiforgery controls on browser forms, rate limiting on sensitive flows, and audit logging for important security and administration actions. See our Security page for more detail.
No internet service can be guaranteed 100% secure. If you believe your data or account has been compromised, contact security@onlydmarc.com.
OnlyDMARC is operated from New Zealand and uses cloud and service providers that may process data in other countries. Hosting, support, security, email, DNS, logging, and other providers may involve processing outside your country.
Where UK/EU transfer rules apply, we use appropriate safeguards such as adequacy decisions, standard contractual clauses, processor terms, or equivalent mechanisms where required.
Depending on where you live and the role in which we process the data, you may have rights to access, correct, delete, restrict, port, or object to processing of your personal data, and to withdraw consent where processing is based on consent.
To exercise a right, contact privacy@onlydmarc.com. If your organisation controls the data, we may direct the request to that organisation or work with them to respond. You may also have the right to complain to a supervisory authority.
OnlyDMARC uses cookies and similar browser storage for authentication, antiforgery protection, login-code flow state, one-time success markers, public-report delivery, and theme preference. These are used to operate the service and protect users; they are not used by OnlyDMARC to sell or broker personal data.
| Name | Category | Typical duration | Purpose |
|---|---|---|---|
| .AspNetCore.Cookies | Necessary | Session or up to 30 days when "Remember me" is selected | Authenticated application session. |
| OnlyDmarc.Antiforgery or __Host-OnlyDmarc.Antiforgery | Necessary | Session | Antiforgery protection for browser form posts. |
| OnlyDmarc.Theme | Functional | About 1 year | The OnlyDmarc.Theme cookie stores only your appearance preference (dark or light) — no personal information, no tracking. It is a functional cookie set only when you are signed in, and it clears when you log out. |
| OnlyDmarc.LoginCode | Necessary | Short-lived login-code flow | Protected pending-login state for passwordless email-code sign-in, when enabled. |
| OnlyDmarc.LoginCodeSuccess | Necessary | About 60 seconds | One-time marker used to show a successful login-code sign-in message. |
| crr_token | Necessary | Short-lived report-delivery flow | Delivers the configuration-report result link after a public form submission. |
If optional analytics or marketing cookies are introduced, we will describe them here or in a cookie banner before using them where consent is required. You can also control cookies through your browser settings; disabling necessary cookies may prevent sign-in or form submissions from working.
OnlyDMARC is intended for professional and organisational use. It is not directed at children, and we do not knowingly collect personal data from children.
We may update this Privacy Policy from time to time. We will update the "Last updated" date and, for material changes affecting active users, provide notice by email, in-app notice, or another appropriate channel.
If you have questions or concerns about this policy or our data practices, contact us:
OnlyDMARC
Email: privacy@onlydmarc.com
Postal address: Available on request where required for legal or contracting purposes.