Short version: we don't want your data, we don't collect much, and what little there is doesn't stick around long. Longer version below.
WTFSPF doesn't use accounts. There's no sign-up, no email address, no name, nothing to fill in beyond the domain you want checked. When you submit a domain, our server resolves its public DNS records, SPF and related records like DMARC, along with everything the SPF record includes, to build the diagnosis you see on screen.
That result is cached against the domain for a few minutes so re-checks and shared links load instantly instead of re-running the same DNS lookups. The cache is keyed by domain name, not by who asked for it: we don't log which visitor checked which domain.
We also use Google Analytics to understand aggregate site usage, such as which pages are visited, approximate geography, browser and device information, referring pages, and interaction events. Google Analytics helps us see whether the tool is useful and where it needs work; we don't use it for advertising.
Like any web server, ours keeps short-lived request logs (IP address, user agent, timestamp, the URL requested) for operating and securing the service. We also rate-limit checks per IP address so one script can't hammer the DNS resolver for everyone else. Neither is used to build a profile of you; both exist to keep the tool free and working.
We set a cookie to remember your light/dark preference, plus the standard session and CSRF cookies any web app uses to keep form submissions secure. Google Analytics may also set analytics cookies or use similar storage to measure visits and usage patterns. No advertising cookies and no ad tracking: we don't run any of that here.
Google Analytics is provided by Google. Google may process analytics data according to its own policies, and may use IP address, device, browser, and usage data to provide measurement reports to us. You can learn more at Google's Privacy Policy.
A report lives at a plain URL: wtfspf.com/example.com. That's on purpose, it's what makes "send this to your MSP" possible, but it means the link isn't a secret. Anyone who has it, or who simply guesses a domain, can view that domain's report. We ask search engines not to index these pages, but that's a request, not a lock. Don't treat the URL as access control.
We link out to MyDMARC and OneDollarDNS, tools we also build, when they're relevant to what your report found. Those are separate sites with their own privacy practices. This policy only covers WTFSPF.
If this changes in any way that matters, we'll update this page and adjust the date below. We won't quietly start collecting more and call it the same policy.
Questions about any of this: hello@wtfspf.com.
Last updated 2026-08-20.
See who is actually sending mail as your domain, catch spoofing, and move DMARC from monitoring to enforcement.
Analyze DMARC reports with MyDMARC →Get alerted when SPF, DMARC, MX, or other DNS records change before a vendor surprise becomes a mail problem.
Monitor DNS with OneDollarDNS →