Terms of service

Last updated 2026-08-25.

These terms govern use of the DomainCanary service at domaincanary.com.

Who we are

The service is operated by Final Dynamics LLC, doing business as DomainCanary.

Contact: contact@domaincanary.com.

Creating an account is acceptance of these terms.

The service

DomainCanary is a DMARC monitoring service. You publish a DNS record naming an address we control. Mailbox providers then send us aggregate reports about mail claiming to be from that domain. We parse those reports and email you a weekly digest.

The service is monitoring only. It is read-only with respect to your mail. Publishing our reporting address does not change how mailbox providers deliver your mail.

Eight free tools are on the public site and need no account: checkers for DMARC, SPF and DKIM, one checker that reads all three at once, a generator for an SPF record and one for a DMARC record, a pre-flight that compares a proposed SPF record against the published one, and an analyzer that reads a DMARC aggregate report you paste or upload. None of them stores what you submit, and what each one does with it is in the privacy policy.

Plans and payment

The free plan covers one domain. It is not a trial, it does not expire, and it needs no card.

Each account can start one 14 day trial of every paid feature from the dashboard, with no card. When the trial ends the account returns to the plan it holds, which is ordinarily the free one; a paid plan bought while the trial ran keeps running. Nothing is deleted. Domains beyond that plan's limit pause until a plan covers them.

There are paid plans as well. Which plans exist, how many domains each one covers, and what each one costs are what the pricing page shows, and Stripe shows you the amount again before you confirm the checkout.

Paid plans are billed monthly through Stripe. Your card details are entered on Stripe's own pages and held by Stripe. We never see a card number and we never store one. What we do hold about a subscription is listed in the privacy policy.

Stripe is the seller of record for the payment. The checkout page, the receipt and the invoice come from Stripe under the Link brand, and your card statement shows LINK.COM* DOMAINCANARY. The service is ours and these terms govern it, but the payment itself is a transaction with Stripe, under Link's terms. This is also why the emails about your payments arrive from Link rather than from us.

Stripe works out any sales tax, VAT or GST from the billing address you give at checkout, and pays it to the tax authority. Where it lands depends on the currency you pay in. In US and Canadian dollars, the price on the pricing page excludes tax and Stripe adds it on top. In every other currency, the price you are shown already includes it. The checkout page shows the full amount, and any tax on its own line, before you confirm.

Stripe also converts the price into your own currency at checkout, so the figure you pay may not be the dollar figure on the pricing page. Stripe handles tax this way in more than 80 countries; where it does not, the checkout adds none.

The price of a plan can change. You get at least 30 days' notice by email to the account address before a new price applies to you, and a price change never applies to a period you have already paid for. If you do not want the new price, cancel before it takes effect. A change in the tax rate where you live is not a price change and needs no notice from us, because we neither set it nor receive it.

You can cancel at any time. Two places do it: the billing portal, which you reach from the billing page in your dashboard, and your Link account at link.com, where Stripe lists everything you have bought through it. Either one ends the subscription.

Cancelling stops the next payment. It does not cut off the period you have already paid for: the paid plan runs to the end of that period, and the account moves to the free plan when the period ends and Stripe tells us the subscription has ended. Nothing you hold is deleted at that point. We do not work out charges, credits or proration ourselves; Stripe does that under the settings on our account with them.

A failed payment does not end a plan by itself. Stripe retries the card, and your plan stays as it is while it does. What ends a paid plan on our side is Stripe reporting the subscription cancelled, unpaid or expired.

Moving to a plan that covers fewer domains deletes nothing. The domains you added first keep the weekly digest; the rest stop receiving it, keep every report we already hold, and start again as soon as a plan covers them. The paid features stop with the plan: realtime alerts, one consolidated digest instead of one per domain, the digest-skip option, and the DNS cleanup views end for every domain the plan no longer covers, and for every domain on the account when it moves to free. The reports behind them are kept either way.

Deleting your account cancels a running subscription first. If that cancellation fails, nothing is deleted and the account stays as it was, because erasing it while the subscription ran would leave you paying for a service you no longer had. The one exception is a subscription Stripe no longer holds: there is nothing left to cancel, so the deletion goes ahead rather than leaving you with an account you cannot erase.

The product enforces no refund rule. If a refund is in question, write to contact@domaincanary.com and we deal with it case by case.

Stripe can also refund you without us. It handles support for the payments it sells, and its agreement with us lets it refund a customer on its own, including when it asks us about a case and we do not answer in time. A refund in full ends the subscription it paid for, and the account moves to the free plan.

What can change, and what cannot

Four things hold for an account that already exists, and the paid plans do not take any of them back:

If your domain's report volume starts costing real money to ingest, you get an email about it and a conversation. You do not get an invoice you did not agree to.

Everything else can change. We can change these terms, and we can change what a paid plan costs on the notice set out under Plans and payment. Existing users get notice by email to the account address before either takes effect.

Retention

We keep at least 12 months of report-level detail, source by source, plus daily totals per sending source for the life of the account. That floor applies on every plan, including free.

Today the code keeps more than the floor: nothing deletes reports or report records by age, so they stay until you delete the domain or the account.

The original report files, as providers sent them, are kept in the raw report archive for 12 months from the day they arrive, and the archive bucket deletes them after that. Deleting a domain or an account removes its parsed reports at once; the archived originals age out on that same 12-month schedule.

Rendered digest HTML is kept for 56 days. The abuse ledgers described in the privacy policy are cleared at 7 and 14 days by a cleanup pass that runs every 15 minutes. That same pass deletes the record of a tripped signup check 90 days after it was written, and empties the signup IP address and user-agent from an account row 90 days after the account was created. The account row itself stays.

Reports are not guaranteed

We depend entirely on third-party mailbox providers choosing to send aggregate reports. We do not warrant that any provider will send them, that a given report will arrive, or that a report is complete.

Ingest has budgets. Every path has a size limit, a decompression limit, and a record limit. Report mail forwarded to us also passes a per-domain daily circuit breaker: a domain that goes over its budget for the day stops being processed until the next one, and reports that arrive in that window are not parsed. Reports you upload by hand in the dashboard keep the per-request limits and skip the daily breaker.

Acceptable use

You may only add domains you control. The service requires a DNS TXT record before any digest is sent.

Do not attack the service, work around its rate limits, or automate account creation.

Do not publish the ingest_secret. It is the one value on your domain page that stays private.

Your account

You sign up with an email address and a password. We store a scrypt hash of the password, never the password itself.

You can also sign in with Google where the deployment has Google credentials. An account created that way holds no password until you set one through the password reset flow. The privacy policy sets out what a Google sign-in stores.

You are responsible for the password and for what is done while signed in to the account.

You publish the reporting address (its local part is public_id) and a verify_token in DNS. The ingest_secret is never published; do not put it in DNS.

An address other than the account's own must confirm before it receives a digest. The person at that address can refuse without having an account.

Publishing the record sends us reports naming IP addresses that belong to other people. The privacy policy sets out what that means for them and for you.

Email

We send transactional mail: address verification, password reset, a notice when someone tries to sign up with an address that already has an account, digest-address confirmation requests, and a notice to the account address when a Google account is linked to an account that already exists, unless that address has told us to stop mailing it.

A digest sends only when the domain is verified, the weekly digest is on for it, a recipient resolves (the domain's own digest address, else the account's), that mailbox has confirmed, and that mailbox is not suppressed. A suppression comes from a permanent bounce, a spam complaint, or a decline. The weekly schedule and a duplicate-send guard also have to allow the run.

A paid plan also mails realtime alerts between the weekly digests. The account settings turn them off everywhere, and each domain's settings can override that either way. Two things trigger one: a source nobody has seen before shows up failing DMARC on one of your domains, or a source that had been passing for that domain starts failing. Either way the row is written as the report is parsed and the mail goes out on the next sweep, which runs every 15 minutes, rather than waiting for the weekly digest. An alert goes to that domain's confirmed digest address under the same consent as the digest, and a domain sends at most one alert a day across both kinds.

Every digest, every alert, and both product-update notes carry List-Unsubscribe, the RFC 8058 one-click POST header, and a visible unsubscribe link. Unsubscribing turns the matching notification setting off in our database.

We reach you at the account address, including for the notices these terms promise. Keep it working.

Support

Support is email to contact@domaincanary.com. There is no response-time commitment and no service level agreement.

Anything about the product itself comes to us: your domain, your reports, the digest, what a record means. Anything about the payment can go to us or to Stripe, because Stripe sells the payment and handles support for it. Your Link account at link.com holds your receipts and invoices and is where Stripe answers questions about a charge.

Your data

What we store, who else holds it, where it sits, how to export it, and how to delete it are in the privacy policy. That policy is part of this agreement.

Who owns what

We own the site, the free tools, the digest layout, and the words on the pages.

Your domain's report data is yours. Pointing your DMARC record at us gives us the permission we need to receive it, parse it, store it, and mail it back to you and to the digest address you confirmed. That permission covers running the service and nothing else. It ends when the data is erased.

We do not sell that data, publish it, or pool it across customers.

Closing an account

You can delete the account yourself at /dashboard/account/delete. You type the account address back and enter the password; an account created through Google has to set a password through the reset flow first, because the form asks for one. That erasure is described in the privacy policy.

If the account holds a running subscription, we cancel it at Stripe before anything is deleted. If that cancellation fails, nothing is deleted and you are told so. A subscription Stripe no longer holds is the exception: nothing is left to cancel, so the deletion goes ahead.

We can close an account that breaks the rules under Acceptable use.

The product has no operator closure tool today. Before we rely on that clause we will build one that erases exactly what self-serve deletion erases.

Either way the result is the one the privacy policy describes: almost everything goes at once, including any record of a tripped signup check filed under the account's own address; the suppression list and the digest-decline list are permanent because they record that a mailbox asked us to stop writing to it; and what is filed under somebody else's address is left to time out on its own, a confirmation-ledger row within seven days and a record of a tripped signup check within ninety.

If we stop running the service

You get notice at the account address before the service stops. The export at /dashboard/account/export works until it does.

After shutdown we erase the same data that account deletion erases, on the same terms.

No warranty

The service is provided as is.

We do not warrant that it will be available, that reports will arrive, that a digest is complete or free of errors, or that the service is fit for a particular purpose.

Liability

To the extent the law allows us to limit liability, our total liability to you for any claim about the service is the amount you paid us for it in the twelve months before the claim. For an account that has paid us nothing, that amount is zero.

These limits do not apply where the law does not allow them, and nothing in these terms excludes liability that cannot lawfully be excluded.

Indemnity

You confirm you control every domain you add, and the DNS TXT record is how we check.

If someone brings a claim against us because a domain on your account was not yours to add, you cover what it costs us to deal with it. That is the only indemnity in these terms, and it runs one way for one reason.

Changes to these terms

The rule is the one under What can change, and what cannot: existing users get notice before a change takes effect.

The date at the top of this file is the date of the current text.

The rest of the agreement

These terms and the privacy policy are the whole agreement about the service. The free-plan commitments above are part of it, even though they also appear on the pricing page.

If a court strikes out part of these terms, the rest still applies.

If we do not enforce a term once, we can still enforce it later.

If the business or the service is sold or transferred, these terms move with it and so does your account. You get the same notice as for any other change, and you can delete the account before it takes effect. You cannot hand your account to someone else.

After an account ends, these survive: no warranty, liability, indemnity, and the survival of the suppression list described in the privacy policy.

Contact

contact@domaincanary.com

Final Dynamics LLC, doing business as DomainCanary.