Responsible Disclosure
Report a security issue
We take security seriously and welcome reports from researchers who find a genuine issue in DMARCS.
Policy
How to report
Email security@dmarcs.com with a description of the issue, the steps to reproduce it, and its potential impact. Include your contact details if you'd like to be credited or kept updated.
What to include
- The affected URL, endpoint, or feature
- Steps to reproduce, or a proof of concept
- What you were able to access or do as a result
- Any tools or scripts used, if relevant
What we ask
- Give us a reasonable amount of time to investigate and fix an issue before disclosing it publicly
- Avoid accessing, modifying, or deleting data that isn't yours
- Don't run automated scans or load tests against production without checking with us first
- Don't attempt social engineering, phishing, or physical attacks against our staff or customers
What you can expect from us
We'll acknowledge genuine reports, investigate, and keep you informed as we work on a fix. A researcher who reports a real, previously-unknown issue in good faith and follows the guidelines above won't face legal action from us for that report.
Out of scope
- Reports generated purely by automated scanners without manual verification
- Issues that require physical access to a user's device
- Social engineering against DMARCS staff, customers, or support channels
- Denial-of-service testing against production systems