Privacy policy
Last updated: 5 September 2026
Who we are
Spoofhound is a DMARC, TLS-RPT and BIMI monitoring service operated by GoCloudConsulting. This policy covers both this website and the Spoofhound application.
What we collect and why
- Account data — your email address, password (stored only as a salted hash), and multi-factor authentication material (authenticator secrets are encrypted at rest). Used solely to operate your account.
- Email authentication reports — DMARC aggregate, DMARC forensic and SMTP TLS reports that mailbox providers send for domains you have verified you control. These describe mail flows (sending servers, volumes, authentication results); aggregate and TLS reports contain no message content. Forensic reports can include message headers and fragments — they are stored only for your own verified domains and are visible only to your account's members.
- Audit and security logs — sign-ins, configuration changes and administrative actions, kept so you can see exactly what happened in your account, including any access by our staff.
- Contact form submissions — name, email and message, used to reply to you, and recorded in our contact database as described below.
Our contact database, and when we may email you
When an email address reaches us through one of our forms or tools, we keep a record of the address, how it reached us, and when, in a database held in the EU. Each record is marked either as an address whose owner gave it to us directly, or as an address we merely encountered — and that mark decides everything:
- We may send occasional product email only where you gave us your own address and either asked us for access to the product or ticked an unticked marketing checkbox — in which case we also store the exact consent wording you saw at the time.
- Addresses we merely encounter — inside DMARC reports, in email headers submitted for analysis, or invited into an account by a customer — are recorded as never-marketable and are not sent marketing, full stop.
Every marketing message carries a one-click unsubscribe — no login, no confirmation page. Unsubscribing (or a bounce or complaint) puts the address on a permanent suppression list that is checked before every send and survives everything else, including the contact record being deleted.
What we don't do
- No advertising, no sale of data, no sharing with third parties beyond the infrastructure below.
- No tracking cookies on this website. The application uses a single, strictly necessary session cookie.
Where data lives
Spoofhound runs on Cloudflare's network — the application, the database and report storage. It sends email (sign-in codes, alerts, digests) via Amazon Web Services (SES): mail for customers on the US instance is sent from AWS's us-east-1 region, and mail for every other instance is sent from AWS's eu-west-2 (London) region. IP addresses appearing in your reports may be looked up against the ipinfo.io service to show you network names and countries.
The full list of the companies that process data on our behalf is on our sub-processors page.
Partner companies
If your organisation's administrator attaches a partner company to your account, that partner's staff can view your account's service-health information, read-only, until your administrator removes them. Every partner view is recorded in your account's audit log.
Data residency
Spoofhound runs as separate, self-contained instances — each with its own database, region and report inbox, nothing shared between them. Where your data sits depends on the instance your account is on:
- Customers on the EU instance: your data is held on Cloudflare's EU jurisdiction.
- Customers on the US instance: your data is held on Cloudflare's US jurisdiction.
- The Rest-of-world, KSA and UAE instances run as isolated instances without a contractual jurisdiction — separate and self-contained, but not tied to a specific legal jurisdiction. We do not claim Middle East data residency.
Retention and your rights
We keep report data only as long as it stays useful, and the product enforces these limits automatically:
- Full report detail — the raw records and forensic reports — for 90 days.
- Aggregate history — the trends built from those reports — for 13 months.
- The original report emails we received are deleted after 395 days.
- Reports received for domains nobody has claimed are held briefly (at most 60 days) and then deleted.
You can request an export or deletion of your account's data at any time via the contact page, and we will act on legitimate requests without undue delay.
AI analysis and its providers
AI analysis is optional and off unless you switch it on for a domain. What happens to your data depends on which option you choose:
- Managed AI — Anthropic processes the report-derived analysis data on our behalf.
- Bring your own AI — the provider you choose (Anthropic, OpenAI, Google, Moonshot or OpenRouter) processes the data under your own agreement with that provider, and Spoofhound sends data only to the provider you configured.
- No AI — if you enable no AI, there is no AI sub-processor and no analysis data leaves Spoofhound.
DNS record contents are stripped from what the help assistant sends. The providers above are listed on our sub-processors page.
Data processing agreement
For the report data we process on your behalf, you are the data controller and Spoofhound acts as your processor. Our data processing agreement sets this out in full and can be read online or downloaded as a PDF.
Contact
Privacy questions: use the contact form. Security reports: see security.txt.