mailampel
FAQDeutsch

Privacy notice

What arises when you use mailampel and what happens to it. Short, because this tool needs very little data. The German version is the authoritative one.

Controller

Company
Mani IT e.U., owner Florian Mani
Address
Dr.-Bilcik-Gasse 14, 3100 St. Pölten, Austria
Data protection officer
Not appointed; there is no obligation to do so.

In detail

1. Visiting the website

On every request our host processes technical access data: IP address, time, address requested, volume of data transferred, browser and operating system identifiers, and where applicable the previously visited page. This is technically necessary to deliver the site and to defend against attacks.

The legal basis is our legitimate interest in secure operation under Art. 6 (1) (f) GDPR. Our host retains this data briefly and then deletes it; we do not evaluate it in relation to individuals.

2. The domain check

When you enter a domain and press “Check”, that domain name is sent to our server. There it is used solely to query publicly available DNS records for that domain and to build the report from them.

The domain name is not stored. There is no history and no analysis of the domains checked. Once the report has been produced, the input no longer exists. The report itself is assembled in your browser and is not retained by us. We only keep a running total of how many checks have been made — a bare number with no connection to you or your domain, see section 5.

The legal basis is Art. 6 (1) (b) and (f) GDPR: you requested the check yourself, and the processing is necessary to carry it out.

After the check, the domain appears in the address bar so that the result stays shareable and switching language does not discard it. That address therefore appears in your browser history and in our host's access logs. It is not passed on to other websites: we set the Referrer-Policy header to strict-origin-when-cross-origin, so that following an external link transmits only our own domain name, not the domain you checked.

3. Abuse protection

To prevent automated bulk querying, our server keeps a count in memory for at most ten minutes of how many requests came from an IP address. This is never written to disk and is discarded afterwards. The legal basis is Art. 6 (1) (f) GDPR.

4. DNS queries to third parties

The check queries DNS servers. We use Cloudflare (1.1.1.1) and, as a fallback, Google Public DNS. Those services learn the name of the domain being checked and the IP address of our server — not yours. The query originates from us, not from your device.

What is queried is not only the domain name you entered but also the names derived from it that belong to the check: _dmarc.your-domain, for instance, the names of the mail servers listed, and their addresses written in reverse for the reverse lookup. All of these are publicly available records — the same ones any mail server queries when delivering anyway.

If the checked domain has MTA-STS configured, our server additionally retrieves the policy file published there over HTTPS. That request likewise originates from our server.

5. The counter

We count how often this tool has been used. All that is stored is a single running number. What is not stored: the domain checked, your IP address, the time of the check, and anything else from which an individual check could be traced.

That number shows the tool is being used — and nothing else. There is no personal reference, so it is not personal data under the GDPR. We mention it here regardless, because we want this page to be complete.

Technically the counter is held by Upstash, Inc. (USA) in a data centre in Frankfurt, Germany. All that is transmitted is the instruction to increase the number by one.

6. Settings kept in your browser

Two things are stored in your browser's local storage: your choice between the light and dark appearance, and whether you dismissed the note about the other language version. Neither leaves your device or is transmitted to us. They are stored only if you actually operate the respective control, and you can delete them at any time via your browser's site data.

Which language your browser prefers is read only at the moment the page loads, in order to decide whether to show that note. It is neither stored nor transmitted to us, and no automatic redirection takes place — you decide with a click.

7. Report by email (double opt-in)

On the result page you can have the report sent to you by email. For that we store: your email address, the checked domain, the overall result (score), the chosen language, and the times of request and confirmation. Your IP address is not stored.

Delivery happens in two steps: first you receive a confirmation email with a link that is valid for 24 hours and works exactly once. Only after your confirmation do we check the domain again and send the report. If you do not confirm, the request is deleted automatically — at the latest three days after the link expires.

If you additionally tick the separate, never pre-selected box, you consent to receiving occasional mail security tips from us. That consent, too, only takes effect with your confirmation and is recorded with the times of request and confirmation — the proof the law requires. You can revoke it at any time, informally: by writing to kontakt@mailampel.com or by replying to any of our emails. We retain confirmed requests and consents as proof until you revoke or request deletion.

Legal bases: for the requested report Art. 6 (1) (b) GDPR (you ordered it), for the tips your consent under Art. 6 (1) (a) GDPR and § 174 of the Austrian Telecommunications Act 2021.

We use Resend as a processor to send these emails; sending happens via the service's EU region (Ireland). The stored details live in a database at Neon in a data centre in Frankfurt, Germany. Data processing agreements under Art. 28 GDPR are in place with both providers; details in the recipients table below.

8. Getting in touch

The enquiry button opens your own email program with prepared text. No data is transmitted to us at that point — we receive it only once you send the message yourself.

If you write to us, we process your details in order to handle the enquiry (Art. 6 (1) (b) and (f) GDPR). Enquiries that lead to an engagement are subject to statutory retention periods of seven years under Austrian tax law; other enquiries are deleted once they are resolved.

9. No automated decision-making

The report assesses the technical configuration of a domain. No automated decision-making about individuals within the meaning of Art. 22 GDPR takes place, and no profiling.

Recipients and transfers to third countries

RecipientPurposeData
Vercel Inc., USAOperating and serving the websiteTechnical access data including IP address
Cloudflare, Inc., USADNS queries for the checkName of the checked domain, IP of our server
Google LLC, USADNS queries as a fallbackName of the checked domain, IP of our server
Upstash, Inc., USA (data centre Frankfurt)Counter of checks performedOnly the instruction to increase a number by one
Resend, Inc., USA (sending via EU region Ireland)Sending the confirmation and report emails, only at your requestEmail address, content of the report email (checked domain and result)
Neon, Inc., USA (data centre Frankfurt)Database for report requests and consentsEmail address, domain, result, timestamps — no IP address

These providers also process data in the United States. Such transfers rely on the European Commission's standard contractual clauses, or on the EU-US Data Privacy Framework where the provider is certified under it.

Data processing agreements under Art. 28 GDPR are in place with our host as well as with Resend, Neon and Upstash (with these providers they form part of the terms of service). The two DNS services are not processors of your data: they receive only the name of the domain being checked, and learn neither your IP address nor anything else about you.

Your data is not passed on for advertising purposes. No data is sold.

Your rights

You have the right to obtain information about data held about you, to rectification, erasure, restriction of processing, data portability, and to object to processing based on a legitimate interest.

You also have the right to lodge a complaint with a supervisory authority. In Austria this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna.

Changes

If the way this tool works changes, we will update this notice. The version published here is the one that applies.

Back to the check