Querying every nameserver directly — this takes a few seconds.
Querying every nameserver directly — this takes a few seconds.
We use Google Analytics to see which pages get used. It sets cookies and sends data to Google. Nothing on this site needs it — declining costs you nothing. Privacy
Effective [EFFECTIVE DATE] · Last updated [LAST UPDATED DATE]
The short version. We store the DNS records we looked up, which are public information. We never store your IP address — only a salted hash of it that is useless the next day. We use analytics, described below. Scan history for a domain is public, and you can have it removed by asking.
This service is operated by [LEGAL ENTITY NAME] (ABN [ABN]), trading as Inspect My DNS, at inspectmydns.com. In this policy, “we”, “us” and “our” mean that entity.
We are committed to providing quality services to you, and this policy outlines our obligations in respect of how we manage your Personal Information. We have adopted the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth). The APPs govern the way in which we collect, use, disclose, store, secure and dispose of your Personal Information. A copy of the Australian Privacy Principles may be obtained from the Office of the Australian Information Commissioner at oaic.gov.au.
Personal Information is information or an opinion that identifies an individual. Most of what this service handles is not Personal Information at all — it is DNS data published by domain owners, which any DNS query returns to anyone who asks. What we do collect is:
We collect this information for the primary purpose of providing the service to you, keeping it available and preventing abuse of it. We may use it for secondary purposes closely related to that primary purpose, in circumstances where you would reasonably expect such use. Where appropriate and possible, we explain why we are collecting information at the point we collect it.
We use two analytics tools. They exist to tell us which pages are used and where people get stuck — not to build a profile of you, and not for advertising.
Your analytics choice: not made yet.
Stored in your browser only, never sent to us. If your browser sends Do Not Track, analytics is skipped regardless of what is set here.
Opting out. We honour your browser’s Do Not Track setting: with it on, the analytics code is never loaded at all, so no request is made and no cookie is set. Google Analytics does not do this on its own — we check before loading it. You can also block them with any content blocker, opt out of Google Analytics specifically using Google’s opt-out add-on, or use the site with cookies disabled. Nothing on this site requires analytics to work, and blocking them does not degrade any feature.
Cookies. The analytics tools above set cookies. Beyond those, the site sets a cookie only if you sign in to manage API keys — a signed, HttpOnly session cookie that we need in order to know it is you. Your light/dark preference is kept in your browser’s local storage and is never sent to us.
[CONFIRM CONSENT APPROACH BEFORE PUBLISHING — see the note below] Australian law does not require a cookie consent banner, but the GDPR and the UK GDPR do require prior consent for analytics cookies from visitors in the EU and UK. This site has a global audience. Decide whether to show a consent banner, restrict Google Analytics to non-EU visitors, or run Matomo in its cookieless configuration, and then delete this notice.
sha256(ip + secret salt + today’s date). The address itself is never written to the database. Because the date is part of the input, today’s hashes cannot be matched against yesterday’s, so the table cannot be used to reconstruct a browsing history — including by us. Note this applies to the application’s own storage; addresses may still appear transiently in server logs, and the analytics tools handle addresses as described above.Sensitive information is defined in the Privacy Act to include information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union or professional membership, criminal record, sexual orientation, or health information.
We do not seek or knowingly collect sensitive information. Nothing this service does calls for it. Were we to receive it — for example because it appears in a public domain registration record — we would use it only for the primary purpose for which it was obtained, for a directly related secondary purpose, with your consent, or where required or authorised by law.
Where reasonable and practicable, we collect your Personal Information only from you. In some circumstances we may be provided with information by third parties — for example, registry and registrar records returned by RDAP or WHOIS. In such a case we take reasonable steps to ensure you are made aware of it.
The third parties involved in running this service are:
We do not guarantee the website links or privacy policies of authorised third parties.
Your Personal Information may be disclosed:
Overseas disclosure. Google Analytics involves disclosure to recipients outside Australia, including in the United States, as described above. Our own servers are located in [SERVER LOCATION]. We do not otherwise sell, rent or trade Personal Information.
Every completed scan is kept, and the history for a domain is visible to anyone who visits its page. Someone can see that a domain moved its nameservers to Cloudflare in March, or its mail from Google to Microsoft in June.
That is deliberate — a change log is the most useful part of the tool — but it is also information some domain owners would rather not have published, and none of them asked us to publish it. Report pages are excluded from search engine crawling for the same reason.
To have a domain’s history removed, email contact@inspectmydns.com. No justification needed, and we will not ask for one. Removal takes the domain out of history, the sitemap and the recently-checked list.
Checking a domain means connecting to that domain’s nameservers, web server and mail servers. Those operators will see requests from this service, identified by a User-Agent naming the tool and linking back here.
We never send MAIL FROM or RCPT TO to a mail server, so this is not, and cannot be used as, an address validator.
Your Personal Information is stored in a manner that reasonably protects it from misuse and loss and from unauthorised access, modification or disclosure. In practice: traffic is encrypted in transit with TLS, API keys are stored only as hashes, key management is behind a signed session cookie, and the database is not reachable from the public internet.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches scheme.
When your Personal Information is no longer needed for the purpose for which it was obtained, we take reasonable steps to destroy it or permanently de-identify it. Specifically:
RETENTION_SCAN_REQUESTS_HOURS=0). They remain unlinkable across days, because the date is part of the hashed input.You may access the Personal Information we hold about you and ask us to update or correct it, subject to certain exceptions. If you wish to access your Personal Information, please contact us in writing at the address below.
[LEGAL ENTITY NAME] will not charge any fee for your access request, but may charge an administrative fee for providing a copy of your Personal Information. In order to protect your Personal Information we may require identification from you before releasing the requested information.
It is important to us that your Personal Information is up to date. We take reasonable steps to make sure it is accurate, complete and current. If you find that the information we hold is out of date or inaccurate, please tell us as soon as practicable so we can update our records.
This policy may change from time to time and the current version is always available on this page. Material changes will be noted by updating the “last updated” date at the top.
If you have any queries or complaints about this Privacy Policy, or believe we have breached the Australian Privacy Principles, please contact us:
We will respond within a reasonable time, ordinarily within 30 days. If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner at oaic.gov.au.
About explains what each check does and why.