Responsible Disclosure

Report a security issue

We take security seriously and welcome reports from researchers who find a genuine issue in DMARCS.

How to report

Email security@dmarcs.com with a description of the issue, the steps to reproduce it, and its potential impact. Include your contact details if you'd like to be credited or kept updated.

What to include

  • The affected URL, endpoint, or feature
  • Steps to reproduce, or a proof of concept
  • What you were able to access or do as a result
  • Any tools or scripts used, if relevant

What we ask

  • Give us a reasonable amount of time to investigate and fix an issue before disclosing it publicly
  • Avoid accessing, modifying, or deleting data that isn't yours
  • Don't run automated scans or load tests against production without checking with us first
  • Don't attempt social engineering, phishing, or physical attacks against our staff or customers

What you can expect from us

We'll acknowledge genuine reports, investigate, and keep you informed as we work on a fix. A researcher who reports a real, previously-unknown issue in good faith and follows the guidelines above won't face legal action from us for that report.

Out of scope

  • Reports generated purely by automated scanners without manual verification
  • Issues that require physical access to a user's device
  • Social engineering against DMARCS staff, customers, or support channels
  • Denial-of-service testing against production systems