Privacy policy
How DMARC123 handles account and email authentication data.
Effective July 20, 2026. This policy describes the information processed by DMARC123, a service built and operated by PM Technologies.
Information processed
DMARC123 processes account names, authorized user names and email addresses, password hashes, session records, managed domain configuration, DNS validation results, DMARC aggregate and failure reports, TLS-RPT reports, source IP addresses, reverse DNS results, geolocation data, blacklist evidence, and security or operational logs.
How information is used
Information is used to authenticate users, isolate account data, generate and validate email authentication configuration, import and display reports, investigate sending sources, maintain security, diagnose service operation, and provide administrative support.
Passwords and sessions
Passwords are stored as one-way Argon2id hashes. Browser sessions use opaque random tokens, while the database stores only token hashes. Sessions can expire, be revoked, or be invalidated after password changes and administrative actions.
Third-party infrastructure
DMARC123 may use DNS resolvers, geolocation data, reverse DNS, SpamCop, Spamhaus DQS, Abusix Guardian Mail, mailbox-provider reports, hosting infrastructure, and certificate services to deliver its features. Provider access keys remain in protected server configuration.
Data access
Application administrators can access all accounts for service administration. Account users are restricted to the domains assigned to their account. Access controls are enforced in application queries and write operations, not only in the visible interface.
Retention and security
Report, DNS, enrichment, authentication, and audit data may be retained as needed for ongoing operation, troubleshooting, security, and historical analysis. Reasonable technical and organizational safeguards are used, but no internet service can guarantee absolute security.
Contact
Privacy questions can be sent to eric@pmtechllc.com.
