Skip to content
notspoofed.comSPF · DKIM · DMARC

Privacy

What these tools store, what they do not, and for how long.

The headers you paste are not stored

They are sent to the server, parsed in memory to produce a result, and discarded when the request ends. They are never written to disk and never written to the database. That matters because email headers are not neutral data: they contain recipient addresses, subject lines, internal hostnames, message IDs and — in this particular tool — unsubscribe URLs carrying tokens that identify a specific subscriber.

Nothing derived from them is kept either, beyond the result described below. No copy, no hash, no log line containing the input.

What is stored

The result, for 90 days

Every check produces a structured result — the pass, fail and warning states, the explanatory text, and the suggested fixes — and that record is stored so the result has a shareable link. It is deleted 90 days after it is created, and it becomes unreadable at that moment regardless of when the deletion runs, because every read filters on the expiry date.

The record contains one value taken from your message: the domain in your DKIM signature, which is your own sending domain and is shown on the result page for context. It does not contain your headers, the From address, the recipient address, the subject, or the unsubscribe URL.

Result links are unlisted rather than secret. They carry a random identifier, are marked noindex, and are excluded from the sitemap — but anyone with the link can open it, so treat one as public if you share it.

A rate-limit counter

Your IP address is used as the key for a counter that resets every minute, so that one visitor cannot run unlimited checks (30 a minute) or unlimited live endpoint tests (10 a minute). The rows are deleted within minutes. The address is not associated with any result, any check, or anything else.

An email address, only if you type one

If you enter an address into the optional monitoring form, it is stored on its own so we can tell you when that product exists. It is not linked to any result, any domain, or any headers — the rows live in a separate table with nothing joining them. It is never required to use the tool, and the result is shown whether or not you fill it in. Ask and it will be deleted.

The live endpoint test

When you tick the box, the server sends one HTTP POST to the unsubscribe URL from your own header. This is the only outbound request any of these tools make, and it has a real effect: it unsubscribes whoever the token in that URL identifies, exactly as a mailbox provider would. It is off by default. The URL is used for that request and is not stored.

Requests are refused before connecting if the hostname resolves to a private, loopback or link-local address, so the tool cannot be pointed at anything inside our network.

Analytics

Page views and a small number of named events — a check was started, a check finished, a guide was read — are recorded without cookies and without any identifier that follows you between visits. There is no advertising, no remarketing, and nothing is shared with a third party for their own purposes.

The rest of this site

The domain checker, the header analyzer and the guides are a separate application with a stricter posture: it stores no results at all, and the header analyzer never uploads anything, because it runs entirely in your browser. Its about page covers it. This page describes only the tools under /tools.

Getting in touch

To have a stored result or an email address deleted, or to ask what is held, email hello@notspoofed.com — for a result, include the link.