Privacy policy
Last updated 5 Oct 2026
This policy explains what personal data DMARC Done collects, why, who else handles it, how long we keep it, and what rights you have under the EU General Data Protection Regulation (GDPR).
Who is responsible
The controller of your personal data is:
- Dominyko, MB, Vilnius, Lithuania
- Registered address: TBD
- Company code: TBD
- Email: hello@dmarcdone.com
We have not appointed a data protection officer. For any privacy question or request, email hello@dmarcdone.com.
The short version
- Free checks are not stored. We look up the domain you type, show you the result, and do not save the domain or the result.
- Our analytics use no cookies. We count visits with a hash that changes every day, so we cannot follow you from one day to the next.
- Customers give us an email address, billing details (handled by Stripe) and their domain’s DMARC aggregate reports. Those reports list sending server IP addresses and message counts. They do not contain the content of any email.
- We do not sell personal data and we do not use it for advertising profiles.
What we collect and why
When you visit the website
Analytics. We record page views and a few actions, such as running a check, clicking a button, starting a checkout or completing a purchase. To count unique visitors without cookies, we combine your IP address and browser user agent with a secret value (a “salt”) that changes every day, and store only a shortened one-way hash of the result. We do not store the IP address or the user agent themselves. Because the salt changes daily, the same visitor gets a different hash each day.
For a check, the analytics event records the detected mail provider, the DNS host and the grade. It does not record the domain you checked.
- Legal basis: our legitimate interest in understanding how the site is used and whether our advertising works (GDPR Article 6(1)(f)).
- Retention: up to 24 months.
Hosting and security. The site runs on Cloudflare. Cloudflare processes your IP address and request details to deliver pages and protect the site from abuse.
Advertising measurement (only with your consent). If we run ads and you agree in the consent banner, we load the Google Ads conversion tag so we can tell which ads lead to purchases. Without your consent, it is not loaded. You can withdraw consent at any time in the banner settings.
When you use the free checker
To check a domain, our server looks up its public DNS records using DNS-over-HTTPS services run by Cloudflare, with Google Public DNS as a fallback. Those services see the domain name being looked up, coming from our server, not from your device.
We do not store the domain you check or the result. Your IP address is used briefly to limit the number of checks per visitor, which protects the service from abuse. It is not written to our database.
A domain name is usually not personal data. It can be if it contains a person’s name, which is one reason we do not keep it.
When you request a free plan
If you fill in the “free plan” request form, we store your email address, the domain and any message you write, along with how you found us (the campaign tags in the link you followed).
- Purpose: to reply to your request.
- Legal basis: steps you asked us to take before a possible contract, and our legitimate interest in replying (GDPR Article 6(1)(b) and (f)).
- Retention: 12 months after our last contact, unless you become a customer.
When you buy the service
Account and order. We store your email address, the domain you bought the service for, your order details and how you found us (campaign tags, and the Google click ID if you came from a Google ad). You sign in with a one-time link sent to your email. After you sign in, we set a session cookie, which is strictly necessary to keep you signed in to your dashboard.
Payment. Payments are handled by Stripe. You enter your card details on Stripe’s checkout page, not on ours, and we never see your full card number. Stripe sends us your name, email address, billing country, any VAT number you enter, and the payment status.
DMARC aggregate reports. The service works by having mailbox providers (such as Google, Microsoft and Yahoo) send your domain’s DMARC aggregate reports to an address at dmarcdone.com. These reports contain:
- the IP addresses of servers that sent email using your domain
- how many messages each server sent
- whether those messages passed SPF, DKIM and DMARC, and the domains involved in those checks
- the name of the organization that sent the report and the reporting period
They do not contain the content of any email, subject lines or recipient addresses. We store the parsed results so we can show you every sending service and its pass rate. A sending server’s IP address is rarely linked to a person, but it can be, for example for a home mail server, so we treat it as personal data.
Service emails. We send you sign-in links, guidance at each step, and alert emails if a legitimate sender starts failing. We do not send you marketing email unless you agree to it.
- Legal basis: performing our contract with you (GDPR Article 6(1)(b)), and our legal obligations for accounting and tax (Article 6(1)(c)).
- Retention: see the retention table below.
When you email us
Emails to addresses at dmarcdone.com are received through Cloudflare Email Routing and forwarded to our company mailbox. We keep the conversation as long as needed to answer you and deal with any follow-up, and no longer than 24 months after it ends, unless it forms part of an order record.
Who else handles your data
We use these service providers (processors), each under a data processing agreement:
| Provider | What it does for us | Data involved |
|---|---|---|
| Cloudflare, Inc. | Website hosting, database, DNS lookups, rate limiting, receiving email and DMARC reports | IP addresses, request data, analytics events, account and report data |
| Stripe | Payment processing and invoicing | Name, email, billing details, payment data |
| Resend (Plus Five Five, Inc.) | Sending our service emails | Email address, email content we send you |
Stripe also acts as an independent controller for some processing, such as detecting fraud and meeting anti-money-laundering obligations. Stripe’s own privacy policy applies to that.
If you consent to advertising measurement, Google also receives data through the Google Ads tag, under Google’s terms.
We may share data with authorities when the law requires it.
Transfers outside the EU
Cloudflare, Stripe and Resend are based in, or use group companies in, the United States. Where personal data is transferred outside the European Economic Area, we rely on the safeguards in their data processing agreements: the EU-US Data Privacy Framework where the provider is certified under it, and the European Commission’s Standard Contractual Clauses.
How long we keep data
| Data | How long |
|---|---|
| Free checks (domain and result) | Not stored |
| Analytics events | Up to 24 months |
| Free plan requests | 12 months after our last contact |
| Account, domain and order details | For the duration of the service, then as long as needed for accounting records |
| Invoices and payment records | 10 years, as required by Lithuanian rules on retaining accounting documents |
| DMARC report data | During the service, then deleted 12 months after the 60-day watch ends, or earlier if you ask |
| Emails with us | Up to 24 months after the conversation ends |
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you
- correct data that is wrong
- delete data, where we have no legal reason to keep it
- restrict how we use it
- receive your data in a portable format
- object to processing based on our legitimate interests, including analytics
- withdraw consent at any time, where we rely on consent
To use any of these rights, email hello@dmarcdone.com from the address we have on file. We reply within one month.
You also have the right to complain to a data protection authority. In Lithuania, that is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania, email ada@ada.lt, website https://vdai.lrv.lt/. You can also complain to the authority in the EU country where you live or work.
Automated decisions
The service uses automated rules to recommend when a domain is ready for a stricter DMARC policy. These recommendations are about your domain’s email setup. We do not make decisions about you as a person based solely on automated processing that have legal or similarly significant effects.
Security
Data is stored on Cloudflare’s infrastructure and sent over encrypted connections. Access to customer data is limited to the people who run the service.
Changes to this policy
If we change this policy, we update the date at the top. If a change materially affects how we use customers’ data, we tell customers by email before it takes effect.
Contact
Questions about privacy: hello@dmarcdone.com.