How the scan behaves
The scan is passive. It reads DNS records, fetches your website's front page as any visitor would, completes TLS handshakes with your web and mail servers, and reads public indexes. It does not try passwords, probe ports or attempt a way in. Anything intrusive needs your written permission and is a separate piece of work. A check that cannot finish is recorded as unknown, never as a pass.
Who can change your DMARC policy
One of our engineers, by approving a step. A rule-based reviewer checks each proposed step first, and its verdict is advice. No AI decides anything. The record we host never starts weaker than the one you had, and reject is never applied automatically. Nothing in the partner API can change a policy.
How the platform is protected
| Control | What it means |
|---|---|
| Content-Security-Policy on every page | No script runs unless we served it and marked it. |
| HSTS, no MIME sniffing, a strict referrer policy | On every response. |
| No server banner | We switch off the banner our own scanner flags on your site. |
| Protection against forged requests | Every action that changes something carries a one-time token. |
| Rate limits | On sign-in, sign-up, scans, DNS checks, imports, key creation and more. |
| Locked-down cookies | Secure, tied to one host, and out of reach of any other site. |
| Sign-in without passwords | An emailed link or code, a Microsoft work account, or a passkey. |
| API keys stored hashed | Shown once, then never again. |
| Webhooks that cannot be turned inwards | A destination is checked to be a public address before every delivery. |
| An audit log | Every consequential action, kept for 24 months. |
| Partner data kept apart | Every read is scoped to the partner. |
| Reports kept out of search engines | A report link pasted in public never puts a company's report in search results. |
| Backups | Regular snapshots, with a copy kept off the server. |
| Watched from outside | Availability is tested every 10 minutes from five locations. |
What we keep, and for how long
| What | Kept for |
|---|---|
| A free check run without leaving an email address, and its report link | 90 days |
| The record of your address on the network, used to limit how many checks one visitor runs | 24 hours |
| The findings of a customer's posture scans | 90 days |
| Sign-up attempts, failure reports, the original files of DMARC and TLS reports | 90 days |
| DMARC report summaries, sender evidence, posture scans, TLS reports, the audit log | 24 months |
| A deleted account's personal data | Removed at once, and gone from backups within about 7 days |
You can ask us to delete your data at any time. The account holder can also delete the account from the portal.
Who else handles your data
| Who | For what |
|---|---|
| Microsoft Azure | Hosting, backups, sending email |
| Microsoft | Sign-in, when you sign in with a Microsoft work account |
| Cloudflare | Sits in front of the portal and the scanner; hosts our DNS; receives the DMARC and TLS reports mailed to us (Email Routing) |
| GoCardless | Direct Debit payments, and the one-off Instant Bank Pay payment for the Full Report |
| Web3Forms | Delivers this website's contact form to our inbox |
Where it runs
OuterMark runs on Microsoft Azure in the UK South region. Backups stay in Azure. Cloudflare sits in front of it.
Reporting a vulnerability
Our security.txt is at /.well-known/security.txt, and says where to send a report. We will acknowledge your report, tell you what we find and credit you if you would like. Please give us a reasonable time to fix a problem before you publish it.
What we do not claim
OuterMark holds no ISO 27001 or SOC 2 certificate of its own, and it is not an inbox filter or a penetration test. If we gain a certificate, this page will say which, for what and since when.