Skip to content
Inspect My DNS

Privacy

Last updated 19 Sep 2026

Inspect My DNS audits the public DNS, mail and web configuration of a domain. Almost everything it reports is already public — it’s what your nameservers tell the world. This page is about the small amount that isn’t: what we keep, for how long, and what we never touch.

What you send us

A domain name, and optionally an API key. That’s the whole input. We don’t have accounts, we don’t ask for your name or email to run a scan, and there’s nothing to sign up for.

What a scan produces and how long we keep it

A scan queries the domain’s authoritative nameservers, mail servers and web endpoints, and stores the resulting report so it can be shared and compared over time. Each report gets a share URL. That URL is unguessable but not secret: anyone who has it can read the report, and reports are not password-protected.

Reports and their change history are kept indefinitely, so a domain’s history stays comparable over time. You can have a domain’s history removed at any time — see Contact.

Reports are not listed publicly

Scanning a domain does not add it to any public directory, home-page list or sitemap. Report pages are marked noindex so they stay out of search results. A report is reachable only by its share URL or by scanning the same domain again.

Scanning domains you don't own

You can scan any domain, because the data is public and the checks are read-only. If you run a domain and don’t want us scanning it, tell us and we’ll block it — see Contact. We honour blocks and don’t work around them.

Analytics

We use self-hosted Umami to count page views. It sets no cookies, doesn’t track you across sites, and doesn’t build a profile. We use it to see which pages get used, nothing more. We do not use Google Analytics or any advertising or cross-site tracking.

Your analytics choice: analytics enabled (default, cookieless). You can turn it off below.

Stored in your browser only, never sent to us. If your browser sends Do Not Track or Global Privacy Control, analytics is skipped regardless of what is set here.

Asked first. If you are in the EEA, the UK or the Crown Dependencies — or we can’t tell where you are — nothing loads until you accept. We also honour Do Not Track and Global Privacy Control: with either on, nothing is loaded and no event is sent, from your browser or from our server. Nothing here needs analytics to work.

API keys

A key is optional and only raises your rate limit and moves rate-limit identity off your IP address. We store the SHA-256 hash of the key and its usage counts, never the key itself. We don’t sell, share or mine your query history.

Server logs and IP addresses

Like any web service we keep short-lived request logs — timestamp, requested path, response code — to run the service and stop abuse. Your raw IP address is never stored. The only thing we derive from it is a salted daily hash — sha256(address + secret + day), which cannot be reversed to an address — used for rate limiting and re-check enforcement.

Those hashes are deleted after 24 hours. We do not retain IP addresses tied to individual scans — there is no raw address to retain.

Outbound connections

Checking a domain means connecting to that domain’s nameservers, web server and mail servers. Those operators will see requests from this service, identified by a User-Agent naming the tool and linking back here. We never send MAIL FROM or RCPT TO to a mail server, so this is not, and cannot be used as, an address validator.

What we never store

No passwords, no payment details, no third-party cookies, no fingerprinting, and no data sold to anyone.

Where data lives

Our servers are in the United States, and we may also host in Australia.

Changes

If this policy changes materially we’ll update this page and its date. The current version is always here. About explains what each check does and why.

Contact

Abuse reports, scan opt-out and privacy questions all go through the contact form.