Security

Security and permissions

An agency trusting us with client sending infrastructure deserves a direct answer to "what can this actually do to my DNS." This page is that answer.

Permissions, by feature

FeatureAccess requiredStatus
Free scanNone. Public DNS lookup onlyLive
Sender connection (Instantly / Smartlead)Read-only domain listLive
Continuous scan schedulingNone beyond sender connectionIn development
DNS remediation (Cloudflare / GoDaddy)Scoped write access, granted explicitlyIn development

Review mode and rollback

Every domain defaults to review-before-apply: a proposed DNS fix is shown as a before/after diff and waits for a person to approve it. Automatic remediation is opt-in per domain and can be disabled at any time. When a fix is applied, reviewed or automatic, the record's previous value is retained so it can be restored. Nothing changes a client's DNS invisibly.

Audit logs

Every proposed, approved, or applied change is recorded with who made the decision, what changed, and when. This log is visible in the workspace, not just retained internally.

Data handling and retention

Scan results (the DNS records and blacklist status we looked up) and, if you provide one, your email address, are stored to show you scan history and to follow up on requests you've made, like asking for a manual audit after hitting the free-scan limit. We don't sell or share this data with third parties. Data is stored with Supabase (Postgres) using row-level security scoped to write-only access from the application. The application itself cannot read captured email addresses back out through its normal access path.

Contact

Security questions, a permission you want clarified before connecting an account, or something that looks wrong: kasper@zachodigital.com.