Both tools run entirely in your browser. There is no backend server operated by us that receives, logs, or stores the domain names, IP addresses, or email headers you enter. When you close the tab, that session's input is gone.
To perform live checks, DNS SOC sends the domain or IP you enter directly from your browser to these third-party public services. Each is governed by its own privacy policy, which we don't control:
cloudflare-dns.com) and Google (dns.google) — for all DNS record lookups, SPF/DMARC/MTA-STS checks, blacklist (DNSBL) queries, and ASN lookups (via Team Cymru's DNS service).rdap.org) — for domain expiry and registration data.haveibeenpwned.com) — for the known-breach-history check.The Email Header Analyzer sends nothing anywhere — header parsing is 100% local to your browser. The only network activity it triggers is if you click one of its "check in DNS SOC" links, which opens DNS SOC with that domain or IP pre-filled.
If you enable drift/change detection in DNS SOC, a snapshot of that domain's results is saved using your browser's local storage, scoped to your device only. It is never transmitted anywhere. You can clear it at any time by clearing your browser's site data for this page.
No accounts, no cookies, no analytics or advertising trackers, no fingerprinting. We don't know who you are or what you've searched, because nothing you enter ever reaches a server we operate.
By using DNS SOC or the Protocol Threat Inspector, you agree to these terms. If you don't agree, don't use the tools.
Both tools are provided free of charge, "as is," for informational and diagnostic purposes. We may modify, limit, or discontinue either tool, or any individual check within them, at any time without notice — including if an underlying third-party service (a DNS resolver, RDAP registry, or blocklist) changes or becomes unavailable.
The tools, their design, and their original content are the property of Xaephyr Reliance Group Inc. Vendor and product names referenced in check results (Cloudflare, Proofpoint, Mimecast, Microsoft, Spamhaus, and others) are trademarks of their respective owners, used here solely to identify what's being detected — this does not imply affiliation, sponsorship, or endorsement in either direction.
These tools are provided without warranty of any kind, express or implied, including accuracy, completeness, or fitness for a particular purpose. DNS, email, and network data changes constantly and is sourced from third-party services we don't control — a result that was correct when generated may be stale minutes later.
Nothing here is a substitute for a professional security audit, penetration test, legal compliance review, or an assessment performed by a qualified practitioner. Use these tools as a starting point for investigation, not a final answer.
Email header parsing (Received chains, Authentication-Results, DKIM signatures) is regex-based and best-effort. These formats vary across mail server vendors and are not fully standardized — a parsing gap or unexpected format is not itself evidence of anything suspicious about a message.
Neither tool is affiliated with, endorsed by, or sponsored by Cloudflare, Google, Microsoft, Proofpoint, Mimecast, Barracuda, Cisco, Spamhaus, Have I Been Pwned, Team Cymru, or any other third party its checks reference.
To the fullest extent permitted by law, Xaephyr Reliance Group Inc. is not liable for any decision made, or action taken, on the basis of output from these tools.