How we protect your data
DMARCS handles your domain, DNS, and email authentication data. Here's what that means for how it's stored, accessed, and monitored.
Practices
Encryption at rest
Sensitive configuration and credential data is encrypted at rest using AES-256-GCM. This has been in place since August 2026 and covers every field that stores a secret or credential, not just a subset.
Data residency
DMARCS runs two independent regional deployments, one serving the EU and one serving the UAE, each with its own hosting, database, and mail processing. Your data stays in the region your deployment is hosted in.
Single sign-on
Organizations can enforce SSO with any SAML 2.0 identity provider (Azure AD, Okta, Google Workspace, and others), with OIDC also supported. An emergency fallback lets an admin bypass a misconfigured or unreachable identity provider without being locked out.
Role-based access control
Access within an organization is scoped by role: Viewer (read-only), Organization User, and Organization Admin. Day-to-day users don't automatically get settings, DNS-editing, or user-management access.
Audit logging
Every action taken in an organization is recorded, including who did it and when, with a clear record when a support engineer accesses a tenant to help with an issue. Nothing about tenant access happens without it showing up in the log.
API security
The public API authenticates with per-organization, scoped API keys (a key can be limited to read-only SIEM event access, for example) and is rate-limited. Every data export made through the API is itself written to your audit log.
Platform availability
Live uptime and incident history for both regions is public. See status.dmarcs.com.
Reporting a vulnerability
Found a security issue? See our Responsible Disclosure policy for how to report it.