Establishing signal
LoadingEstablishing signal
LoadingLegal
What MailBaseline collects, why, who processes it, how long we keep it, and the controls you have. We collect as little as the job needs, and we say precisely what happens to the things you paste and upload.
Last updated July 28, 2026.
MailBaseline is operated by Eastbase Studio, the controller of the personal data described here. For any privacy request, email support@eastbase.studio.
We do not sell your personal data, and we do not use the content of your DMARC reports or pasted headers for anything beyond showing you their analysis.
Raw message headers are technical metadata, but they are not anonymous. A typical paste contains email addresses (From, To, Return-Path, Reply-To), IP addresses of the relays that handled the message, message IDs, routing and relay data from the Received chain, authentication results (SPF, DKIM, DMARC verdicts), and unsubscribe metadata such as List-Unsubscribe headers.
Please paste headers only. Do not paste message bodies, attachments, secrets, credentials, API keys, tokens, or confidential content — the analyzer has no use for them, and you should not send them to us.
Precisely what happens to a paste:
d= domain) — to your analyzer history, so you can compare messages over time. That record is kept until you delete your account, or ask us to remove it.We deliberately do not claim to “never store the content of your mail”: the raw paste is never stored, but the parsed result of a signed-in analysis is, and it contains the header fields listed above. Transport in between is out of our hands — headers travel to us over HTTPS and are processed by our hosting provider.
DMARC aggregate reports arrive as .xml, .xml.gz, or .zip files from mailbox providers. Handling is the same idea as the analyzer: the file is transient, the summary is kept.
Summaries are kept while the domain is monitored and are deleted with the domain or the account (section 09).
If you add a Slack or Discord webhook URL, we store it so we can post drift alerts to it, and we send it only to Slack or Discord. A webhook URL is a confidential credential — anyone holding it can post into your channel — so we never display it in logs, error reports, or analytics events, and you should keep it out of shared documents and public repositories.
Be aware of what the alerts themselves carry: the domain being monitored and the DNS and authentication details that changed (record values, check verdicts, score movement). Point the webhook at a channel whose audience should see that. You can remove or replace it any time in Settings; if it leaks, rotate it in Slack or Discord.
Optional analytics are off until you accept them. Nothing loads, no cookie or analytics identifier is written, and no event is queued before that choice. You can change your mind whenever you like via Cookie preferences in the footer.
/scan/[domain], not the domain you scanned. PostHog is hosted on US Cloud and sets analytics cookies/identifiers once you accept. If you later reject, we opt out and reset the stored identifier.Every analytics integration is also disabled entirely unless its keys are configured, so a self-hosted or preview deployment sends nothing at all.
We share data only with the vendors that run the service, each for a specific purpose:
You can update notification details in Settings. To request an export, correction, or account deletion (which removes your domains and stored scan history), email support@eastbase.studio from your account address. Depending on where you live, you may also have rights to restrict processing of your personal data or lodge a complaint with a supervisory authority.
Traffic is served over HTTPS, passwords are hashed with bcrypt, card data never touches our servers, and uploaded DMARC reports are parsed with strict size caps and external entities disabled. Pasted headers, uploaded report files, webhook URLs, and secrets are kept out of our application logs, error reports, and analytics by design. No system is perfectly secure, but we aim to collect little and protect what we hold.
We operate from Vietnam and some processors (for example, PostHog US Cloud) operate in the United States, so your data may be processed outside your country. MailBaseline is a business tool not directed to children; accounts require you to be at least 18 or otherwise legally able to contract (see the Terms), and we do not knowingly collect data from minors.
We'll update this policy as the product changes; the “last updated” date above always reflects the current version, and we'll flag material changes in-product or by email.
Email support@eastbase.studio and a human will reply. For setup help, the ESP guides and free tools cover the common cases.