Privacy policy
What we hold, and what we never touch.
Effective 10 September 2026
This policy describes what Signet collects and why, in the same plain terms the product uses everywhere else. Where it says we do not do something, that is a description of the system, not a promise about intent.
01Who we are
Signet at emailsecurity.pro is built and operated by eSec Forte Technologies, Gurugram, India. eSec Forte Technologies is the data controller for the personal data described in this policy. You can reach us at [email protected].
02The short version
We never read your email. We hold no passwords. The free tools work without an account. If you sign up, we collect your email address to let you in and to send you the reports and alerts you asked for. The DMARC reports we process on your behalf contain counts, IP addresses and authentication results, not messages. Forensic reports, which can contain fragments of messages, are redacted before they are stored.
03The free tools
The domain scan reads public DNS records for the domain you enter and fetches the domain’s public MTA-STS policy over HTTPS. The result may be stored and shown at a public report address, because DNS records are public and a report of them is not personal data. We log the scanned domain, the time and the requesting IP address for abuse prevention and rate limiting, and keep those logs for no longer than 90 days.
The message check works by you sending an email to a one-time address we generate. We verify SPF, DKIM and DMARC alignment against what the message carries and show you the result. The check, and the message data it holds, expires 24 hours after it was created, and the one-time address does not accept further mail once the check has expired.
04Accounts
Sign-in is by a link sent to your email address. There is no password and therefore no password database. We store your email address, the organisation you belong to, the domains you monitor, and the alert channels you configure. A sign-in session lasts 14 days. An invitation to join an organisation expires after 7 days if unused.
We use your address to send sign-in links, the digests and alerts you enable, and notices about the service itself. We do not send marketing email and we do not sell or share your address with anyone.
05DMARC and TLS reports
When you publish a DMARC or TLS-RPT record pointing reports at us, mailbox providers send us aggregate reports about mail claiming to be from your domain. These contain the sending IP address, message counts, and the SPF, DKIM and DMARC results. They do not contain message content, subjects or recipient addresses. We store them, classify each source, and show them to you.
If you also enable forensic (failure) reports, those can contain headers and fragments of individual messages. We strip recipient addresses and message content from them before writing anything to storage, not merely before displaying it. What remains is the sending source, the authentication results and the timestamp.
Reports are received through Amazon Web Services in the Asia Pacific (Mumbai) region and are removed from the receiving mailbox once processed, so there is no second copy outside our retention rules. Report data is retained for as long as your account is active and for the retention period your plan provides, after which it is deleted.
06Hosted records
If you use Signet to host an MTA-STS policy or a DMARC reporting address, we serve those records on your behalf. Serving them involves ordinary web server and mail server logs, which are used for operating the service and for nothing else.
07What we do not collect
We have no integration with your mailbox and no OAuth access to Google Workspace or Microsoft 365. We do not read, store or scan your email. We do not track you across other websites, we set no advertising cookies, and we do not use third-party analytics on this site. The only cookie we set is the session cookie after you sign in.
08Sub-processors
We use Amazon Web Services to receive report email and to store data, and a transactional email provider to deliver sign-in links and alerts. These providers process data on our instructions and do not use it for their own purposes. We will update this section if the list changes.
09Your rights
You can ask us at any time what we hold about you, ask for it to be corrected, or ask for your account and its data to be deleted. Deleting your account removes your email address, your organisation’s domains and the reports we hold for them. Write to [email protected] and we will act within 30 days. Where a law such as the Digital Personal Data Protection Act 2023 or the GDPR gives you additional rights, those rights apply in full.
10Security
Data is encrypted in transit and at rest. Access to production systems is limited to the people who operate the service. Because there are no passwords, there is no password database to be stolen. Our own domain’s posture is published hourly at /security, whether or not the result flatters us. If you find a vulnerability, please read the contact page for how to report it.
11Changes
When this policy changes we update the effective date above and, for changes that affect how your data is handled, tell account holders by email before the change takes effect.