Privacy
What we keep, and what we do not.
Last updated August 2026.
We keep the domain you check. We do not keep you.
Every checker on this site reads public DNS and answers. When a domain is checked we write down one row about the domain: the name, the Vitals score and band it received, whether it can be spoofed, the first and last date it was checked, how many times, which tool was used, and the two-letter country Cloudflare attached to the request. Nothing about you is stored: no account, no IP address, no cookie, no session, no history tied to whoever ran it. The row says example.com scored 42 on Tuesday, from India, and there is no way to get from it to the person who typed it.
The sender check takes an IP address as well as a domain. That address is not stored: it is used for the evaluation and forgotten, and the row records only that the domain was examined. The same is true of a selector you add to the DKIM check, which stays in your own browser and is never sent anywhere but the lookup itself.
A checkup runs as three requests, and the score is only final once all three have answered. The row records which of the two it is, so a provisional number is never read as a settled one. Correcting it changes the score in the row and nothing else.
We keep it because it tells us which domains are struggling, and that is how this site finds the people worth offering help to. It is the honest version of what most free tools do without saying so. If you would rather not be on that list, write to support@themaildoc.co with the domain and it is removed the same day, no questions and no reply needed beyond confirming it is done.
A domain drops off by itself 90 days after it was last checked. There is no archive behind that: the row is deleted, not hidden.
Results are also cached for a minute at the edge so a popular domain does not get looked up a thousand times, and that cache holds the DNS answer, not you. Separately, Cloudflare keeps request logs for a few days for debugging, which include the address the request came from. Those are Cloudflare's, we do not read them for anything but faults, and they expire on their own.
Your DMARC reports never leave your browser
Bloodwork decompresses, parses and analyses report files in the tab you have open. The file is never uploaded. You can disconnect from the internet after the page loads and it still works, which is the easiest way to check that claim yourself.
One thing on that page does leave: if you press Identify these senders, the sending IP addresses from your report are sent to Cloudflare's public DNS resolver to look up their names. Only the addresses go, never the report, and only when you press the button.
The consultation form
If you ask for a consultation we store what you typed, because we cannot reply otherwise: your name, email address, and optionally your company, domain and message. Alongside it we store the page you came from, the country your request came from, and your browser's user agent string, which help us answer sensibly and spot automated submissions.
If you arrive at the form from a result, the form says so on screen before you send it, and the score it names is stored with your request: the domain, the Vitals number and whether the domain was spoofable. That is one line of a chart you had already run, kept so the first reply is about your domain rather than a request to run it again. Reach the form any other way and there is nothing to attach, so nothing is.
We use it to reply to you and for nothing else. It is not added to a mailing list, not sold, and not shared with any third party. It is stored in Cloudflare D1 in encrypted form at rest, and deleted within 24 months of our last exchange, or sooner if you ask.
What we never collect
- No analytics scripts, no tracking pixels, no advertising network.
- No cookies. The site sets none at all.
- No email content. We read DNS records and files you choose to open locally.
- No passwords or DNS credentials. We never ask for access to anything.
Your rights
Write to support@themaildoc.co and we will tell you what we hold about you, correct it, or delete it. There is no form to fill in and no verification hoop. Under the UK and EU GDPR and India's DPDP Act you have those rights by law; we would do it anyway.
Who runs this
The MailDoc is run by Sumit Raj. Hosting is Cloudflare, which processes requests on our behalf and holds the consultation database. No other processor is involved.
Every fix on this site is yours to implement. If you would rather someone did it, I take this work directly.