MAIL DNS DIFF

Privacy & limits

Check without an account

We accept a bare domain only, never a URL or query string. Queries go to Google Public DNS with client-subnet forwarding disabled. Our service does not scrape websites or contact the domain’s mail server.

Your choice to keep or share

Anonymous results expire after one hour. Explicitly shared receipts expire after 30 days unless attached to a watch. Watches keep the original baseline and 30 days of observations. Public receipts omit unrelated TXT records and DMARC reporting destinations. Domain names and SPF mechanisms are visible when you share.

Email is opt-in

A six-digit code verifies your inbox. Change alerts and weekly reminders are separate choices. Manage them in your dashboard or use the unsubscribe link in any notification. No newsletter, prospecting, payments or third-party tracking pixels.

Measure return visits

First-party Secure, HttpOnly cookies last up to 90 days for your session and anonymous visit identifier. Product events use a salted actor hash and aggregates; no fingerprinting or third-party analytics script. Clearing cookies changes the anonymous identifier. Infrastructure security logs are managed by the host.

Know the limits

One resolver, exact names, roughly daily checks, two watched domains per account and 40 launch slots. DNS failure means unknown, not missing. Two matching observations at least an hour apart confirm a change. We do not test SMTP, DKIM, DMARC inheritance, recursive SPF or global propagation. Queuing an email is not proof of inbox delivery.

Manage or delete a watch. Deletion removes its baseline, history and pending app notifications; already queued platform mail can be cancelled through the platform unsubscribe link. Account and security metadata are separate from watch history.