Privacy policy

Last updated 30 September 2026

MailWatch monitors the email infrastructure of your domains. To do that it processes account data about you and your team, and the reports that mailbox providers send about mail using your domains. This policy explains what we collect, why, how long we keep it and what your rights are. All of it is stored in the European Union, and none of it is sold or used for advertising.

Who we are

MailWatch is operated by MailWatch. For anything about privacy, including requests to exercise your rights, write to hello@mailwatch.eu.

Controller and processor

  • For account data (who you are, how you use MailWatch, billing status) we are the controller.
  • For the report data we receive for your domains, you decide what we monitor and we process it on your behalf: you are the controller and we are your processor. The data processing terms in our terms of service apply.

Your account

  • Account details: your name, email address and a one-way hash of your password (we never store the password itself).
  • Organizations: the organizations you belong to, your role in them, and the domains, alert rules, webhooks and settings you configure.
  • Invitations: the email address of people you invite to an organization.
  • Activity log: important actions in an organization (for example adding a domain, inviting a member or creating an API token) with the time, the user, their IP address and browser user agent. Owners and admins of the organization can see this log.
  • API tokens: a name, the permissions you gave it, and when and from which IP address it was last used. The token itself is shown once and only a hash is stored.
  • Emails we send you: invitations, alerts and monthly summaries, sent to the addresses you and your team configure.
  • Billing: payments are handled by Creem, our merchant of record. Creem collects your payment and invoice details under its own privacy policy. We only receive your Creem customer and subscription IDs, the plan and the subscription status. We never see your card details.
  • Server logs: our web server records requests (IP address, time, page and user agent) to keep the service secure and to troubleshoot problems.

Report data

When you point the rua address of a domain's DMARC record (or its TLS-RPT record) at your MailWatch reporting address (…@reports.mailwatch.eu), mailbox providers such as Google and Microsoft send us daily reports about mail that used that domain.

DMARC aggregate reports contain

  • the organization that sent the report and the period it covers;
  • the DMARC policy published for your domain;
  • for each sending server: its IP address, the number of messages, and the SPF, DKIM and DMARC results;
  • the domains used in the From header, the envelope sender and the DKIM signatures, and the DKIM selectors.

Aggregate reports contain no message content, subjects or recipient addresses. Sending-server IP addresses are usually those of companies and email services, but an IP address can be personal data, for example for a server run by an individual.

TLS reports contain

The IP addresses of the sending and receiving mail servers, the mail server host names, the MTA-STS policy that was applied, and counts of successful and failed TLS connections with the reasons for failures.

Other messages

MailWatch only uses aggregate DMARC reports and TLS reports. Anything else sent to a reporting address, such as DMARC failure (forensic) reports, which can include message headers or content, is not processed but is kept with the raw messages until they are deleted (see Retention). Do not point the ruf address of your DMARC record at MailWatch.

Enrichment

To show you who is sending as your domain, we look up each sending IP address in public DNS: its reverse DNS name, and its network (ASN) and country through Team Cymru's DNS-based IP-to-ASN service. These lookups send only the IP address; no report or account data is shared.

Domain monitoring

We regularly query the public DNS records of the domains you add (SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT and BIMI records). For MTA-STS and BIMI we also download the policy file, logo and mark certificate from the web servers those records point to. This is public information about the domain; it is stored with your organization to detect changes.

The free domain check on our website runs the same lookups once, without an account. We do not store which domains you check: the result is kept in a cache for up to 10 minutes so that reloading or sharing the page doesn't repeat the lookups, and your IP address is used only to limit how many checks can be run in a short time.

Purposes and legal bases

  • Providing the service (account, monitoring, reports, alerts, API and webhooks): performance of our contract with you (GDPR Art. 6(1)(b)), and for report data, your instructions as controller.
  • Security, abuse prevention and the activity log: our legitimate interest in keeping MailWatch and your organization secure (Art. 6(1)(f)).
  • Billing and accounting: contract performance and our legal obligations (Art. 6(1)(b) and (c)).
  • Service emails such as invitations, alerts and important changes to the service: contract performance. We do not send marketing email without your consent.

Retention

DataKept for
Raw report messages, as received90 days
Individual report records (sending IPs, counts, results)12 months
Daily aggregated statistics per domain24 months
DNS check history90 days
Webhook delivery log30 days
Invitations that were not accepted30 days after they expire
Account, organization and activity logWhile the account or organization exists
Server logsNormally no longer than 30 days

How much history you can see depends on your plan; data older than that is not shown and is deleted at the end of the periods above. When you delete a domain, its reports are deleted too. When you close your account or organization, we delete its data within 30 days. Encrypted database backups are kept for up to 12 months and then overwritten; deleted data disappears from them as they expire. We keep billing records as long as tax law requires.

Who receives data

We use a small number of service providers (sub-processors), each bound by a data processing agreement:

  • Hosting provider in the European Union: servers, database and storage for all data.
  • Transactional email provider: delivers invitations, alerts and summaries (recipient address and message content).
  • Creem: payments, invoicing and VAT as merchant of record.
  • Team Cymru: answers DNS lookups of sending IP addresses (only the IP address).

Data also goes where you send it: webhook endpoints you configure, API clients that use your tokens, and the addresses that receive alerts and summaries. If your organization is managed by an agency on MailWatch, that agency can see your organization's domains and reports. We disclose data to authorities only when the law requires it. We never sell data.

Where data is stored

MailWatch stores and processes all account and report data in data centres in the European Union. Team Cymru is based in the United States and receives only the IP addresses we look up. If a provider processes personal data outside the European Economic Area, we rely on an adequacy decision or the European Commission's standard contractual clauses.

Cookies

MailWatch uses only cookies that are strictly necessary: a session cookie to keep you signed in, a “remember me” cookie if you tick that box, and a cookie that protects forms against cross-site request forgery. We use no analytics, advertising or third-party tracking cookies, so there is no cookie banner.

Security

Connections use HTTPS, passwords are hashed with a modern algorithm, sign-in and the API are rate limited, and every request is checked against the organization it belongs to so one customer can never see another's data. Uploaded reports are parsed with strict size and decompression limits, and outgoing requests to your servers (MTA-STS, BIMI, webhooks) can never reach internal networks. Backups are encrypted and stored in a separate location.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • have incorrect data corrected;
  • have your data deleted, or its processing restricted;
  • receive your data in a portable format;
  • object to processing based on our legitimate interests.

Write to hello@mailwatch.eu; we answer within one month. If a request concerns report data of an organization, we pass it to that organization, as it is the controller. You can also lodge a complaint with the data protection authority of the country where you live or work.

Changes

We update this policy when MailWatch or the law changes. The date at the top shows the latest version. If a change materially affects how we use your data, we tell organization owners by email before it takes effect.

Questions about this page can go to hello@mailwatch.eu. See also the terms of service.