Security

How we protect your data

DMARCS handles your domain, DNS, and email authentication data. Here's what that means for how it's stored, accessed, and monitored.

Encryption at rest

Sensitive configuration and credential data is encrypted at rest using AES-256-GCM. This has been in place since August 2026 and covers every field that stores a secret or credential, not just a subset.

Data residency

DMARCS runs two independent regional deployments, one serving the EU and one serving the UAE, each with its own hosting, database, and mail processing. Your data stays in the region your deployment is hosted in.

Single sign-on

Organizations can enforce SSO with any SAML 2.0 identity provider (Azure AD, Okta, Google Workspace, and others), with OIDC also supported. An emergency fallback lets an admin bypass a misconfigured or unreachable identity provider without being locked out.

Role-based access control

Access within an organization is scoped by role: Viewer (read-only), Organization User, and Organization Admin. Day-to-day users don't automatically get settings, DNS-editing, or user-management access.

Audit logging

Every action taken in an organization is recorded, including who did it and when, with a clear record when a support engineer accesses a tenant to help with an issue. Nothing about tenant access happens without it showing up in the log.

API security

The public API authenticates with per-organization, scoped API keys (a key can be limited to read-only SIEM event access, for example) and is rate-limited. Every data export made through the API is itself written to your audit log.

Platform availability

Live uptime and incident history for both regions is public. See status.dmarcs.com.

Reporting a vulnerability

Found a security issue? See our Responsible Disclosure policy for how to report it.