Privacy Policy
Last updated 24 Aug 2026
Who we are
This service is operated by [LEGAL ENTITY NAME] (ABN [ABN]), trading as Inspect My DNS.
What we collect
Personal Information is information that identifies an individual. Most of what this service handles is not Personal Information at all — it is DNS data published by domain owners, which any DNS query returns to anyone who asks. What we do collect is:
- What you send us through a form. The Contact and Security report forms take a message, an optional reply address and an optional link to a report. This is the main way we come to hold anything personal, and you choose what is in it.
- Your email address, if you create an API key. Held so we can send the sign-in link and show you your keys. We store the SHA-256 hash of each key and a short display prefix, never the key itself.
- Scan results. The DNS, mail and hosting records for the domains people check, plus the domain name and the time of the scan. This is public information published by the domain owner, registrar or registry. We display what is already public and add nothing personal to it.
- Server logs, for security and troubleshooting: the requester IP address, the request, the response code and how long it took.
- A salted daily hash of your IP address for rate limiting and re-check enforcement.
We collect this to run the service, keep it available and stop it being abused. We do not seek sensitive information — racial or ethnic origin, political or religious belief, health, sexual orientation and the rest — and nothing this service does calls for it.
Analytics and cookies
We use Umami Analytics to see which pages get used and where people get stuck. It is cookieless and does not track you across sites.
Your analytics choice: analytics enabled (default, cookieless). You can turn it off below.
Stored in your browser only, never sent to us. If your browser sends Do Not Track or Global Privacy Control, analytics is skipped regardless of what is set here.
Opting out. We honour your browser’s Do Not Track and Global Privacy Control settings: with either on, nothing is loaded and no event is sent, from your browser or from our server. The control above is narrower — it stops the script and everything your browser would send, but our server still records one page-view event per report, because your choice is stored in your browser and the server never sees it. A content blocker has the same reach as the control above. Nothing here needs analytics to work.
Cookies. Umami sets none. The site sets one cookie only if you sign in to manage API keys — a signed, HttpOnly session cookie needed to keep you signed in. Your light/dark preference lives in your browser’s local storage and is never sent to us.
Scan history is public
Every completed scan is kept, and the history for a domain is visible to anyone who visits its page. Someone can see that a domain moved its nameservers to Cloudflare in March, or its mail from Google to Microsoft in June.
Outbound connections
Checking a domain means connecting to that domain’s nameservers, web server and mail servers. Those operators will see requests from this service, identified by a User-Agent naming the tool and linking back here.
We never send MAIL FROM or RCPT TO to a mail server, so this is not, and cannot be used as, an address validator.
Changes to this policy
The current version is always on this page, and material changes are noted by updating the date at the top. About explains what each check does and why.