Privacy
Last updated 2 October 2026. MailVakt is operated by 42eleven. Questions: support@mailvakt.com.
MailVakt is free. We do not show ads, we do not sell or share personal data, and we do not track you across other sites. We set an essential session cookie, plus short-lived sign-in cookies (the signed OAuth state cookie, about 5 minutes) during GitHub sign-in. We set no analytics or advertising cookies. We do count page views, without cookies; see Page analytics below.
Domain checks
When you check a domain we look up its public DNS records and store the resulting report so it can be shared by link. A report contains the domain, the public DNS data we found, the grade, the time and whether the check was run signed in or anonymously; it does not record who ran it, and we do not store your IP address for domain checks. Reports are public to anyone with the link, but report links are unlisted and not indexed by search engines (the domain’s own page, below, may be). Because reports are not linked to your account, deleting your account does not remove them. To have a report removed, email us.
Checking a domain reads only its public DNS records. The result is published as a public page for that domain at mailvakt.com/domain/<domain>, which search engines may index. Whoever checked it is never shown. If you control a domain, you can remove its page by adding one DNS record: open the domain’s page and choose “Remove this page” (mailvakt.com/domain/<domain>/remove).
Inbox tests
An inbox test stores the full email you send to the test address, including its headers and content, together with our analysis. The test address expires after 30 minutes, and inbox-test messages are deleted after 7 days. The test id in the result link is the only thing needed to open the result, including the analysed headers and message details, until the test is deleted after 7 days, so share that link only with people you trust. For tests started without signing in we store a one-way hash of your IP address, never the address itself. Only send messages you are allowed to share.
Accounts
If you sign in we store your email address and, for GitHub sign-in, your GitHub name and avatar URL, your GitHub account identifier, and the OAuth access token and granted scopes in our account records. These are used only to complete sign-in and are removed when you delete your account. Sign-in links expire after 5 minutes. For each active session the sign-in system records the IP address and browser user agent to protect your account. Expired sessions are deleted within two days, and all of your sessions are deleted when you delete your account. If you connect an AI assistant (ChatGPT, Claude, Cursor) we store the access it was granted until you revoke it or delete your account.
Domains and DMARC reports
Domains you add are stored with a private report address. Receivers then send DMARC aggregate reports to it. These reports describe mail sent as your domain (sending IP addresses, message counts and authentication results) and contain no message content. The raw DMARC report emails are deleted after 30 days. The parsed results are kept so we can show summaries, until you remove the domain or delete your account.
Abuse protection and statistics
To stop abuse we keep short-lived request counters keyed by IP address or account. For usage statistics we record, per request, the tool used, the outcome, the grade, the duration and a one-way hash of the domain; no IP addresses or email addresses. Our hosting provider keeps operational logs for a limited time for debugging.
Page analytics
To see which pages people arrive on and which sites send them here, we count page views with PostHog, in its European Union region. Each page view records the page address, the referring site, any campaign parameters in the link, and your browser, operating system, device type and screen size. We set no analytics cookie: a random session identifier is held in your browser’s sessionStorage and discarded when you close the tab, so nothing recognises you on a later visit or on any other site. PostHog is configured to discard your IP address, so no address and no location is stored. We record no clicks, no keystrokes, no form contents and no session recordings, and page analytics is never linked to your account or to a domain report.
Using MailVakt from an AI assistant
When you use MailVakt in ChatGPT, Claude, Cursor or another assistant, that assistant sends us the inputs of each request (for example a domain or pasted headers) and receives our results. The assistant provider’s own privacy policy covers what it stores.
Where data is processed
Cloudflare runs the whole service: Workers, D1, R2, Queues, Email Routing and Email Service. To check a domain we send DNS queries for the submitted domain name to the Cloudflare (1.1.1.1) and Google (dns.google) DNS-over-HTTPS resolvers and, when authoritative lookups are enabled, directly to the domain’s own nameservers. What is transmitted is the domain name you submit, names derived from it (such as its DMARC, DKIM and MTA-STS records) and the record types queried. GitHub is involved only if you sign in with GitHub. Page-view counts are processed by PostHog in the European Union; nothing else is sent to it.
Your choices
You can remove a domain at any time, and you can delete your account in Settings. Deleting your account removes your sign-in record, sessions, linked sign-in accounts, domains, their DMARC data, inbox tests run while signed in and AI assistant access. Public domain reports are not linked to your account and remain; email us to have one removed. For anything else, including access, correction or report removal requests, email support@mailvakt.com.