Privacy

Last updated 2026-09-14.

mail.maib.io is operated by mAIb Tech. This page describes what the service actually does with data, in the order that matters.

Message headers are never uploaded

The header analyser runs entirely in your browser. The text you paste is parsed by JavaScript on your own device; it is not sent to this server, is not logged, and is not stored. Closing the tab disposes of it.

If you choose to attach the findings to a repair calculation, only derived, non-identifying values are sent: the SPF, DKIM and DMARC verdicts, the signing domain and selector, the visible From domain, alignment booleans and the receiving system's name. Email addresses are reduced to their domain before anything leaves the browser, the Message-ID token is discarded, and the message body is discarded before parsing begins.

Domain scans

When you scan a domain we store the domain, the normalised scan result, the rules that fired, the DNS evidence, the engine and ruleset versions, and the time. This is what makes a result reproducible and what makes before-and-after comparison possible.

We also store a salted hash of your IP address, used only for rate limiting. The address itself is not stored, and the hash cannot be reversed to recover it.

Scan results are private by default. A scan is only reachable by its own unguessable URL, results pages carry noindex, and a shareable link exists only if you explicitly create one.

Payments

Payments are processed by Stripe. Card details are entered on Stripe's own checkout page and never reach this service. We store the Stripe session and customer identifiers, the amount, the currency, the status, and the email address Stripe collects, so that your purchase can be linked to your repair pack and so refunds work.

Stripe's handling of your payment data is governed by Stripe's own privacy policy.

Accounts

Accounts are optional and exist only to give you a way back to purchases and to a Guard dashboard. We store your email address and a scrypt hash of your password. We never store the password itself. You can delete your account at any time from the account page; deletion removes the session, scrubs the email address and the password hash, and cannot be undone.

Analytics

First-party only. No Google Analytics, no third-party scripts, no advertising pixels, no cross-site tracking. A random session identifier is held in your browser's sessionStorage so that a visit can be counted as one funnel rather than several; it is not a cookie, it is discarded when the tab closes, and it is not linked to anything identifying.

Event payloads are restricted by an allow-list to counts and short labels. Domains, email addresses, DNS record contents and header text are never placed in an analytics event.

Logs

Server logs record the request method, the path without its query string, the status, the duration and a random request id. Query strings are excluded because a scanned domain appears in one. Log output passes through a redaction step that removes anything resembling an API key.

Cookies

Three, all first-party and all strictly functional: an attribution cookie when you arrive from a campaign link, a repair pack access cookie after purchase, and a session cookie if you create an account. No advertising or analytics cookie is set.

Retention

Repair packs remain accessible for 30 days from purchase. Scans are retained so that historical comparison works. Monitoring history is retained for the life of the subscription. To have data about a domain you control removed, write to mAIb Tech.

What we never do

We do not sell data. We do not share it with advertisers. We do not collect your DMARC aggregate reports — those go to whatever address you put in your own rua tag, and this service is not it.