DNSVERIFY POLICIES
Privacy Policy
This notice explains what personal information DNSVerify processes, why it is used and the choices available to you.
Effective 14 July 2026
Who is responsible for your information
DNSVerify is the controller of personal information processed for this service. Contact us through the contact form for privacy questions or requests.
Information we collect
- Account information: your email address, account type and status. Passwords are stored only as salted, computationally expensive hashes; we do not store the password you entered in readable form.
- Authentication and security information: session tokens in hashed form, session times, user agent, security events, abuse-prevention counters and network information needed to protect forms and accounts. Rate-limit identifiers are hashed rather than storing their original discriminator in the application database.
- Service information: domain names, monitoring choices, DKIM selectors, verification state, DNS results and history, registration data, certificate observations and your certificate-review decisions.
- Communications: your name, email address, selected topic and message when you contact us, together with messages needed to support the account.
- Technical request information: information ordinarily processed by our network and hosting providers, such as IP address, request time, browser details and security signals.
DNS, RDAP, WHOIS and Certificate Transparency information is obtained from public technical sources. Although usually about a domain or organisation, it can sometimes contain information relating to an identifiable person.
How and why we use information
- to create and secure accounts, verify email addresses and provide monitoring, results, alerts and support;
- to confirm authority over domains, prevent abuse, enforce limits and investigate operational or security problems;
- to maintain limited histories, improve reliability and understand whether checks and notifications are working;
- to meet legal obligations and establish, exercise or defend legal claims where necessary.
We rely on performance of our agreement with you where processing is needed to provide the requested service. We rely on legitimate interests for proportionate security, abuse prevention, service reliability and improvement. We may rely on legal obligation where the law requires processing. We do not use account data for third-party advertising and do not sell personal information.
Providers and disclosures
Cloudflare provides network protection, Workers hosting, database services, email delivery and Turnstile bot protection. Turnstile evaluates browser and network signals and we send its verification service the challenge token and visitor IP address. Our private collector hosting provider processes public Certificate Transparency and fallback WHOIS work plus operational telemetry; it does not receive account passwords.
We may also disclose limited information to professional advisers, service providers, courts, regulators or law-enforcement bodies where reasonably necessary and lawful. Providers may process information in the UK, EEA or other countries under their contractual and legal transfer safeguards.
Retention
Account and configured-domain information is generally kept while the account or domain remains active, whether or not optional domain verification has been completed. Certificate history is currently limited to 12 months and the latest 100 observations per domain; other result and change histories are deliberately bounded.
Expired sessions, one-time verification and reset records, and rate-limit records are automatically cleared on short operational schedules. Support correspondence and necessary security records are kept only for as long as reasonably needed for support, abuse prevention, dispute handling and legal obligations. Infrastructure providers may retain limited security logs under their own documented schedules.
Cookies and local storage
DNSVerify does not currently use advertising or audience-measurement cookies. The application uses a strictly necessary secure session cookie after login. A theme preference may be stored for up to one year in a cookie and your browser's local storage. Cloudflare Turnstile processes browser and network signals on protected forms and may use its own strictly necessary technologies to distinguish legitimate users from automated abuse.
Your rights
Depending on the law that applies to you, you may have rights to access, correct or erase personal information; restrict or object to processing; receive portable information; and complain to a data-protection regulator. Where processing is based on consent, you may withdraw that consent without affecting earlier processing.
You may object at any time to processing based on legitimate interests. Contact us using the details above. We may need to verify your identity before completing a request. UK users may also complain to the Information Commissioner's Office.
Security and changes
We use access controls, encrypted transport, restricted administrative access, hashed credentials, request validation and monitoring to protect information. No internet service can guarantee absolute security.
We may update this notice as DNSVerify develops. The current version and effective date will remain available here.