Skip to content
DMARCLoop
  • Scan
  • Features
  • Tools
  • Pricing
  • FAQ
  • Contact
Log in Start free

Privacy Policy

Last updated 5 September 2026

DMARCLoop is committed to providing quality services to you, and this policy outlines our ongoing obligations to you in respect of how we manage your Personal Information.

We have adopted the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (the Privacy Act). The APPs govern the way in which we collect, use, disclose, store, secure and dispose of your Personal Information. A copy of the Australian Privacy Principles may be obtained from the website of the Office of the Australian Information Commissioner at oaic.gov.au.

1. Who we are

DMARCLoop is a trading name of Visolute Pty Ltd, an Australian company registered in Brisbane, Queensland, Australia. In this policy, "DMARCLoop", "we", "us" and "our" mean Visolute Pty Ltd trading as DMARCLoop.

DMARCLoop is a DMARC monitoring and reporting product, plus a set of free DNS and DMARC tools. This policy covers everything at dmarcloop.com and the services we provide through it. Privacy questions, access and correction requests, and complaints all go to [email protected].

2. What is Personal Information and why do we collect it?

Personal Information is information or an opinion that identifies an individual. Examples of Personal Information we collect include names, email addresses, billing addresses and payment details. We collect it for the primary purpose of providing our services to you, answering your enquiries, billing you for services you order, and keeping the service secure and available. We may also use it for secondary purposes closely related to that primary purpose, in circumstances where you would reasonably expect such use.

We collect Personal Information through our website at dmarcloop.com, by email, through our contact form, and through our payment processor when you order a paid service. We do not buy contact lists or collect Personal Information from data brokers. Where we collect it, we explain why at the point of collection wherever that is practicable. The specifics are below.

Queries you run through the free tools

When you use the Domain Scan, Domain Checker, DMARC Inspector, SPF Check, DKIM Inspector, DKIM Validator or DMARC Record Wizard, we receive the domain name (and, for DKIM, the selector) you asked about. We log that query string with a timestamp so we can rate-limit abuse and cache results. The tools need no account and no sign-in, and query logs are not attached to any analytics identity or visitor profile.

Domain names are usually about organisations rather than people, but a lookup on a personal domain can still identify someone — so we treat these logs as Personal Information and apply the retention limits in section 11.

Domain scan reports you ask us to email

The domain scan works without any details from you. If you ask for the full report as a PDF, we collect your email address and the domain you scanned. We use them to generate and email you that report, to notify ourselves that you asked for it (so a person can answer questions about it), and to send you at most one follow-up email a few days later asking whether you need a hand. We do not add you to a mailing list. The report itself is kept on our servers for a short time (see section 11) so the download link in the email keeps working, then deleted.

Files you put through the XML-to-human Converter

The XML-to-human Converter runs entirely in your browser. Aggregate report files you open with it are parsed locally on your own device and are never uploaded, transmitted to us, or stored by us — there is no server involved in that tool at all.

Messages you send us

The contact form collects your name, email address, the topic you pick, and your message. We store that enquiry and email it to ourselves so we can read and reply to it. We use it to answer you and to keep a record of the conversation — not for marketing, unless you separately ask to hear from us. If you ever do join a mailing list of ours, you can unsubscribe at any time by using the unsubscribe link or by writing to us at the address in section 17.

Your account, if you create one

Signing in to the DMARCLoop service means creating an account. We collect your name, email address and the credentials you set, and we keep a record of sign-in activity — timestamps, and where you have enabled multi-factor authentication, the fact that it was used. Account sign-in is handled for us by Kinde, described in section 8; passwords are held by Kinde and are not stored by us.

Billing information, if you order a paid service

If you subscribe to or order a paid DMARCLoop service, we collect the information needed to bill you and to meet our tax and accounting obligations: your name, billing contact details and billing address, your business name and any tax registration details (such as an ABN), the plan and domains you are billed for, and a record of invoices, payments, refunds and chargebacks.

We do not collect, see or store full card numbers. Card details are entered directly with our payment processor, Stripe — see section 7. What comes back to us is a payment token plus non-sensitive details such as the card brand, expiry month and last four digits, which we use to identify the payment method for reconciliation and support.

Technical and security logs

Our content delivery network and web application firewall record standard request data — IP address, user agent, the URL requested, and a timestamp — for security, abuse prevention and rate limiting. Our application logs are deliberately built not to record client IP addresses; the IP stays in the edge access logs, where it is needed for those purposes and nothing else.

Analytics

We measure site usage with Umami, which we self-host on infrastructure we control and serve from our own analytics domain (umami1.visolute.net). It records page views, referring URLs, an approximate location derived from your IP address, and basic device and browser information.

We also record a small number of named events so we can see which parts of the site are actually used: that a tool was run and what severity the result was, that a generated record was copied, that an aggregate report was opened in the converter, that the contact form was submitted, and which call-to-action link was clicked. The content you put into the tools is never included — not the domain or selector you look up, not the DKIM key you paste, not the name or contents of a report file you open, and not your name, email address or message.

Umami does not store your IP address. It derives a daily-rotating identifier from your IP address and browser user-agent combined with a secret we hold, uses it to tell one visit from another within a day, and cannot reverse it back to you.

No third party receives this data. There is no Google Analytics, no advertising network, no social widget and no cross-site tracking anywhere on this site. The only script loaded from another origin is our own self-hosted Umami — infrastructure we operate, not a third-party company. We do not sell or share analytics data.

3. Sensitive Information

Sensitive information is defined in the Privacy Act to include information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.

We do not seek or require sensitive information to provide any part of DMARCLoop, and we ask that you do not include it in contact form messages or support correspondence. If we do come to hold sensitive information, it will be used by us only:

  • For the primary purpose for which it was obtained;
  • For a secondary purpose that is directly related to the primary purpose;
  • With your consent; or where required or authorised by law.

4. Third Parties

Where reasonable and practicable to do so, we will collect your Personal Information only from you. However, in some circumstances we may be provided with information by third parties — for example, billing and payment method details passed back to us by Stripe when you pay for a service, or your details supplied by a colleague who arranges a service on your organisation's behalf. In such a case we will take reasonable steps to ensure that you are made aware of the information provided to us by the third party.

This site links to external websites, including the RFC and standards documents referenced throughout our FAQ and tools. We do not guarantee the content, links or privacy practices of any third party site, even where we have linked to it.

5. How we use your information

  • To run the free tools and return results to you.
  • To provide, support and administer any paid service you order, including sending service and billing notices.
  • To reply to enquiries you send us.
  • To take payment, issue invoices, and keep financial records.
  • To keep the service available and secure — rate limiting, blocking abuse, investigating faults.
  • To understand aggregate usage so we can improve the tools and the documentation.
  • To meet legal, tax and regulatory obligations.

We do not sell Personal Information, and we do not disclose it to third parties for their own marketing.

6. Cookies

This site sets no cookies at all. Our analytics (Umami, above) is cookieless by design and stores nothing on your device — no cookie, no local storage. We set no advertising cookies and no third-party cookies, and there is nothing here to ask you to consent to.

Blocking requests to umami1.visolute.net stops that measurement. The free tools, the FAQ and the contact form all work normally either way.

7. Payments and Stripe

We use Stripe to process payments. When you enter card or other payment details to order a service, those details go directly to Stripe over an encrypted connection — they are not submitted to, routed through, or retained by DMARCLoop's servers.

Stripe handles that information as an independent controller of it in its own right, so your payment information is also subject to Stripe's privacy policy, which you can read at stripe.com/privacy. Among other things, Stripe uses payment and device data for fraud detection and to meet its own legal and regulatory obligations, and it may process and store that data outside Australia — including in the United States and the European Union. If you have questions about what Stripe does with your data specifically, that policy is the authoritative source, not this one.

Separately from Stripe, we keep our own billing and transaction records (invoices, amounts, dates, plan) because Australian tax and corporations law requires us to.

8. Authentication and infrastructure providers

Two other providers handle Personal Information on our behalf, in addition to the hosting and payment providers already described.

Kinde — authentication

We use Kinde to run sign-up, sign-in and session management for the DMARCLoop service. When you create an account or sign in, your name, email address, credentials and sign-in activity are processed and stored by Kinde on our behalf. Passwords are held by Kinde, hashed — we never receive or store your password, and neither we nor Kinde can read it back. Kinde also processes technical data about the sign-in attempt itself, such as IP address, device and browser, in order to detect suspicious sign-ins. Kinde's own privacy policy is at kinde.com/privacy-policy.

Hivelocity — backend compute and processing

We use Hivelocity for some of our backend compute and data processing — the server capacity behind parts of the DMARCLoop service, including aggregate report processing. Personal Information handled by those workloads is stored and processed on servers Hivelocity provides to us. Hivelocity supplies and maintains the underlying infrastructure and data centre; it does not use your information for its own purposes.

9. Disclosure of Personal Information

Your Personal Information may be disclosed in a number of circumstances, including the following:

  • To the service providers we need to run DMARCLoop, and only as far as they need it — Amazon Web Services (hosting, storage, logging and outbound email delivery), Stripe (payment processing and fraud prevention, as described in section 7), Kinde (authentication) and Hivelocity (backend compute and processing), both as described in section 8;
  • To third parties where you consent to the use or disclosure;
  • Where required or authorised by law.

Analytics is not on that list because we self-host Umami — there is no analytics vendor holding your data.

We may also disclose information where it is needed to establish or defend a legal claim, or to prevent a serious threat to someone's life, health or safety. If our business or assets are ever sold or restructured, information held about customers may transfer to the acquirer, who would remain bound by this policy until they notify you otherwise.

10. Overseas storage

Our site, API, databases and logs run on Amazon Web Services infrastructure in the United States (the us-east-1 region). Our Hivelocity servers are located in Hivelocity's data centres, which are principally in the United States. Stripe and Kinde each process data in the United States and elsewhere. This means Personal Information we hold is stored and processed overseas, and by using DMARCLoop you consent to that disclosure to overseas recipients for the purposes set out in this policy.

11. Retention, destruction and de-identification

When your Personal Information is no longer needed for the purpose for which it was obtained, we will take reasonable steps to destroy or permanently de-identify it. In practice:

  • Cached DNS results — expire automatically, typically within minutes to hours.
  • Tool query and application logs — retained for up to 12 months, then deleted automatically.
  • Emailed domain scan reports (the PDF files) — deleted automatically 30 days after they are generated. The record that you requested one (your email address and the domain) is kept so we can answer follow-up questions, and deleted on request.
  • Edge access and security logs — retained for one month.
  • Billing and transaction records — kept for a minimum of seven years, as Australian tax and corporations law requires.

12. Security of Personal Information

Your Personal Information is stored in a manner that reasonably protects it from misuse and loss and from unauthorised access, modification or disclosure. All traffic to this site is served over HTTPS. The site enforces a strict Content Security Policy and loads no third-party scripts. Access to production systems is restricted and least-privilege, and payment card data never reaches our infrastructure at all.

No system is perfectly secure, but if we ever have a data breach likely to cause serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.

13. Access to your Personal Information

You may access the Personal Information we hold about you and update and/or correct it, subject to certain exceptions. You can also ask us to delete it where we are not required to keep it. If you wish to access your Personal Information, please contact us in writing at [email protected]. We will respond within a reasonable period — normally 30 days.

We will not charge any fee for your access request, but may charge an administrative fee for providing a copy of your Personal Information. In order to protect your Personal Information we may require identification from you before releasing the requested information.

If you are in the United Kingdom or the European Economic Area, you may also have rights under the UK GDPR or GDPR — including access, rectification, erasure, restriction, portability and objection. The same address handles those requests.

14. Maintaining the quality of your Personal Information

It is important to us that your Personal Information is up to date. We will take reasonable steps to make sure that your Personal Information is accurate, complete and up-to-date. If you find that the information we have is not up to date or is inaccurate, please advise us as soon as practicable so we can update our records and ensure we can continue to provide quality services to you.

15. Children

DMARCLoop is a tool for email and DNS administrators. It is not directed at children, and we do not knowingly collect Personal Information from anyone under 16.

16. Policy updates

This Policy may change from time to time and is available on our website. The "last updated" date at the top always reflects the current version. If a change materially affects how we handle Personal Information, we will tell account holders by email before it takes effect.

17. Privacy policy complaints and enquiries

If you have any queries or complaints about our Privacy Policy, please contact us at:

Visolute Pty Ltd, trading as DMARCLoop
Brisbane, Queensland, Australia
[email protected]

Tell us first so we can try to put it right. If you are still not satisfied with how we have handled your Personal Information or your request, you can complain to the Office of the Australian Information Commissioner — oaic.gov.au.

Product

  • Features
  • For MSPs
  • Large organisations
  • Pricing

Tools

  • Domain Checker
  • DMARC Inspector
  • SPF Check
  • DKIM Inspector
  • DKIM Validator
  • MTA-STS Checker
  • MTA-STS Policy Generator
  • DMARC Record Wizard
  • XML-to-human Converter

Learn

  • FAQ
  • Why SPF/DKIM can pass and DMARC still fails
  • How DMARCLoop identifies sources
  • How to publish a DMARC record
  • Sending DMARC-compliant mail for others

Company

  • Start free
  • Log in
  • Contact
  • Privacy
  • Terms
DMARCLoop

© 2026 DMARCLoop. All rights reserved.