Skip to content
Legal — Cookie Policy

Ten entries we can store. Two of them we cannot turn off.

Every cookie this site can set, what it holds, how long it lives, and exactly which ones matter if you block them. Everything here is checkable in your own browser.

Last updated September 10, 2026No advertising cookies
The short version
One cookie records your answer to the banner and is set either way, because a site cannot remember that you declined without writing it down. Analytics and session-replay tags are denied by default and load nothing until you allow them. There are no advertising or cross-site tracking cookies on this site.
01Everything this site can store

Everything this site can store

Every entry below is checkable in your browser’s own storage inspector right now. Two are set on every visit because the site cannot remember your cookie choice without them. The Cloudflare challenge script loads with the newsletter form in the footer of every page, and its cookies are set when a challenge runs. Everything else depends on what you allowed and which page you are on.

NameTypeWhat it is forLifetime
ddmarc-consentCookieRecords your cookie choice so the banner does not ask again. Secure, SameSite=Strict, and readable only by this site.12 months
ddmarc-consentLocal storageA mirror of the same choice, so a return visit in the same browser applies it before the first paint instead of after a round trip.Until cleared
_gaCookieGoogle Analytics 4. Distinguishes one browser from another so a repeat visit is not counted as a new person. Set only after you allow analytics.Up to 2 years
_ga_<id>CookieGoogle Analytics 4 session state for this property. Set only after you allow analytics.Up to 2 years
_clckCookieMicrosoft Clarity session replay. Identifies your browser across visits. Set only after you allow analytics.12 months
_clskCookieMicrosoft Clarity session identifier. Set only after you allow analytics.1 day
CLID, ANONCHK, MR, MUID, SMCookieSet by the Microsoft Clarity script (clarity.ms, c.clarity.ms, bing.com) to identify your browser for session replay. Set only after you allow analytics.Session to 13 months
ddmarc_refCookieRemembers which partner's link (?ref=) brought you here, so they can be credited if you sign up. First-party, shared with app.ddmarc.com so the credit survives sign-up on that subdomain. Set only after you allow analytics.30 days
cf_chl_*, __cf_bmCookieCloudflare Turnstile bot challenge on the contact, newsletter and security-packet forms. Strictly necessary — these forms cannot filter automated submissions without it.Session to 30 minutes
ddmarc-one-pagerLocal storageOnly on the partner one-pager. Holds the details you type into that document so you do not retype them. Never sent anywhere.Until cleared
No marketing cookies
This site sets no advertising, retargeting or cross-site tracking cookies. Google Analytics, Microsoft Clarity and Cloudflare Turnstile are the third-party tags on this site, all listed above, and Sentry runs as a cookieless browser SDK. That is a statement about what is here, not a promise about the future — if it ever changes, this page changes first and the banner asks again.
02The one you cannot turn off, and why

The one you cannot turn off, and why

ddmarc-consent is set whichever way you answer the banner, including when you reject everything. It stores your answer and the date you gave it.

There is no way around this one: a site that remembers “this person declined” has to write that down somewhere, and the alternative is asking you again on every page. It carries no identifier, is readable only by this site, and is not shared with anyone.

What it contains
A small JSON object: whether you allowed analytics, the timestamp of your choice, and a schema version. Nothing else — no visitor id, no fingerprint, and nothing that can identify you across sites.
03Analytics is off until you say otherwise

Analytics is off until you say otherwise

We use Google Analytics 4 and Microsoft Clarity session replay, and both start denied. Before the Google tag loads, the page tells it that analytics storage is not granted; the tag runs in that state and sets no analytics cookies at all until you allow them. Clarity is not injected at all until you allow analytics — there is no denied-but-loaded state for it. If you never answer the banner, or you decline, none of the cookies above marked “optional” are ever written.

Where you do allow it, the configuration is:

  • GA4 does not store IP addresses — there is no anonymization setting because there is nothing to anonymize.
  • Google Signals and ad personalization off — the data is not used for advertising.
  • Data sharing with other Google products turned off.
  • 14-month retention on GA4, after which the underlying event data expires; Clarity follows Microsoft's own retention for recordings and heatmaps.
  • Clarity's masking is set to hide form-field text; it never records what you type into a field.

What we look at is aggregate: which pages get read, which free tools get used, and where people give up. We do not build profiles of individual visitors and there is nothing in the analytics data tied to a DDMARC account.

The same allow choice also covers ddmarc_ref below. It is not an analytics cookie — it credits a partner for referring you — but this site has one optional category, and a second toggle for a single cookie would only add a step. If you decline, neither is set.

04Changing your mind, at any time

Changing your mind, at any time

Three ways, all of which take effect immediately, not at the next visit:

  • Use the “Cookie Preferences” button in the site footer, under Legal. Turning analytics off stops both tags collecting anything further.
  • Clear this site's cookies and storage in your browser. You will see the banner again on the next page you open.
  • Block cookies for this site entirely. The pages all still work — the only thing you lose is that the banner asks again each time.

We also ask again on our own account: your choice is stored for twelve months, after which the banner reappears instead of assuming an answer you gave a year ago still holds.

05The free tools set nothing extra

The free tools set nothing extra

The domain checker needs no account and sets no cookie of its own. A domain you type is sent to our checking service to be looked up in public DNS, and the result comes back to your browser. We keep no per-visitor record of what you checked, beyond standard server logs.

The DMARC lookup and DKIM checker work differently: they query public DNS directly from your browser over DNS-over-HTTPS, using Cloudflare’s resolver with Google Public DNS as a fallback. The domain you look up and your IP address go to whichever resolver answers the query, not to us. The MTA-STS and BIMI checkers send the domain to our API, because fetching a policy file or a logo from another site is something a browser cannot do. As with the domain checker, we keep no per-visitor record of those checks beyond standard server logs.

The one exception is the partner one-pager, which stores what you type into that document in your own browser so you do not have to retype it. That never leaves your machine, and the “Reset” button on the page clears it.

06Where the rest of it is written down

Where the rest of it is written down

This page covers storage in your browser. What we do with data once it reaches us — what we collect, how long we keep it, who processes it and what rights you have over it — is in the privacy policy. Customers processing personal data through the platform should also read the data processing agreement.

If something on this page does not match what you see in your browser’s storage inspector, that is a bug and we want to know. Tell us and we will either fix the site or fix the page.