Terms of Service
Last updated 2026-07-27.
Last updated July 2026
These terms govern your use of the DMARCHub service, operated by Inside Technology Ltd (company number 10442174, VAT number GB239614981; the "Provider", "we", "us"). By using DMARCHub, you (the "Customer", "you") agree to these terms. By checking the box when you set up an account on DMARCHub, you agree to these terms.
1. Definitions
Subscription means a paid plan for the Service.
Customer Data means the data you provide in connection with the Services, including DMARC reports, your account data and any personal data.
Confidential Information means non-public information disclosed by one party to the other that is marked as, or would reasonably be understood to be, confidential.
Data Protection Laws means the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and the Privacy and Electronic Communications Regulations 2003, each as amended or replaced.
2. The service
DMARCHub is a hosted DMARC monitoring platform. We provision a dedicated reporting mailbox per customer organisation, ingest the DMARC aggregate and forensic reports sent to that mailbox, parse them, and present the results in our portal. We also publish hosted MTA-STS policies on your behalf if you enable that feature. Collectively, the “Services”.
3. Acceptable use
When using DMARCHub, you agree to:
· only use it for monitoring DMARC reports about domains you own or operate;
· only use it for lawful purposes; and
· only invite colleagues from your organisation to join your account;
When using DMARCHub, you agree not to:
· monitor, or attempt to monitor, DMARC reports for any domain you do not own or legitimately operate;
· add a domain that you are not authorised to control;
· use the reporting mailbox, hosted DMARC records, or MTA-STS publishing to mis-direct, intercept or interfere with mail for a domain you do not control;
· submit malware, exploits, decompression bombs or deliberately malformed reports intended to harm the platform, its ingestion pipeline or our other customers;
· use the Services to facilitate or evade defences against unsolicited commercial email (spam), phishing or email spoofing;
· use the Services to harass any individual or organisation;
· attempt to access another customer’s data, exceed your plan quota, deliberately overload the ingestion or processing pipeline or otherwise interfere with the operation of the platform;
· reverse-engineer, scrape or otherwise extract the platform’s source code, API or internal data structures beyond what is publicly documents; or
· resell the Services to third parties without an explicit reseller agreement with us.
If you want to increase your plan quota, please visit the billing page.
If you believe you have found a vulnerability in the Services, please email security@dmarchub.io with details.
If you believe another user is abusing the Services, please email abuse@dmarchub.io.
If we believe you have breached our acceptable use provisions, we may ask you to stop or we may restrict, suspend or terminate your account in accordance with clause 11(Termination).
4. Account and access
Sign-in to DMARCHub is via your supported identity provider (Microsoft Entra ID or Google Workspace). You are responsible for keeping access to that account secure.
New accounts complete a short onboarding step in which you confirm your company profile (legal company name, registered company number, VAT number if applicable, postal address and contact phone). We may require manual approval before activating your account; we will tell you by email when your account is approved, and if we are unable to approve an account we will let you know.
You may invite team members to your organisation via the in-app team management. Colleagues who sign in from the same directory as an existing organisation can request access; an account owner or administrator must approve them before they can use DMARCHub. You are responsible for the actions of users you invite or approve.
5. Subscriptions, billing, cancellation
Free-tier accounts are free of charge with the limits stated on our pricing page. Paid subscriptions are billed monthly or annually in advance by Stripe in GBP, plus applicable VAT.
Paid subscriptions renew automatically for successive periods of the same length unless you cancel before the applicable renewal date. We may change the fees for a renewal period by giving you at least 30 days’ notice before that renewal date. For the avoidance of doubt, a fee change does not affect the period that you have already paid for. You may upgrade or downgrade your plan at any time from your billing page. Upgrades take effect immediately with a prorated charge for the remainder of your current cycle. Downgrades take effect at the end of your current cycle.
You may cancel your subscription at any time from your billing page. Cancellation takes effect at the end of your current billing cycle. You keep access and remain liable to pay fees until that date.
6. Service level
We publish status transparently at dmarchub.io/status. We do not offer a contractual service level agreement. The Services are provided on an “as is” and “as available” basis. To the extent permitted by law and except as expressly stated in these terms, we give no warranty as to availability, uptime, or fitness for a particular purpose.
7. Data protection
Our processing of personal data is described in our Privacy Notice. DMARCHub provisions a dedicated reporting mailbox per organisation and, where you enable it, publishes hosted DMARC and MTA-STS policies on your behalf. By using DMARCHub you confirm that you are entitled to monitor the domains you add and that you have a lawful basis to share the data you provide, or cause to be sent, to the service.
· We both agree to comply with Data Protection Laws. The details of the processing we carry out as your processor are:Subject matter: providing the Services;
· Duration: for as long as you use the Services;
· Nature and Purpose: ingesting, parsing, storing and displaying DMARC aggregate and forensic report data;
· Personal data involved: any personal data in Customer Data, sending IP addresses, together with any personal data in a forensic report before it is scrubbed at the point of ingest;
· Data subjects: any individuals who can be identified from that report data.
As your processor, we will:
· Process the personal data only on your documented instructions, unless required otherwise by law;
· Ensure that the people we authorise to process it are subject to confidentiality provisions;
· Implement appropriate technical and organisational measures to protect it;
· Engage sub-processors only under a written contract on terms consistent with this clause and remain responsible for their performance (you give general authorisation to the sub-processors identified in our Privacy Notice and we will notify you of any intended additions or replacements so that you may object);
· Not transfer personal data outside the UK except under applicable safeguards;
· Assist you in responding to data subject requests and in meeting your security, breach notification and DPIA obligations;
· Delete or return any personal data at the end of the Services (as set out in our Privacy Notice); and
· Make available information reasonably necessary to demonstrate compliance with this clause and permit audits on reasonable notice (at your cost).
8. Intellectual property
DMARCHub and all related materials are the property of Inside Technology Ltd. You are granted a limited, non-exclusive, non-transferable, non-sublicensable licence to use the service in accordance with these terms. Your Customer Data remains yours; we claim no ownership over the DMARC reports you upload or the metadata derived from them.
9. Confidentiality
Each party will keep the other’s Confidential Information confidential, use it only to perform or receive the Services and disclose it only to those of its personnel or contractors who need it and who are bound by equivalent obligations. This does not apply to information that is or becomes public through no breach of these terms, was lawfully known before disclosure, or is required to be disclosed by law.
10. Limitations of liability
If you are using the Service as a beta tester (that is, before we notify you that the Service has become generally available) our total aggregate liability to you under or in connection with these terms is limited to £100. You acknowledge that during this period the Service is provided on a pre-release, “as is” and “as available” basis (as set out in clause 6) and may be incomplete, interrupted or withdrawn.
At all other times, our aggregate liability to you under or in connection with these terms in any rolling 12-month period is limited to the greater of £500 or the fees you have paid us in that period.
In each case, we are not liable for indirect, consequential, or special losses (including loss of profit, loss or corruption of data, or business interruption).
Nothing in these terms limits or excludes liability that cannot be limited or excluded under English law, including liability for death or personal injury caused by negligence or for fraud.
11. Termination
Either party may terminate the agreement at any time per the cancellation terms above. Either party may terminate these terms by written notice if the other party materially breaches them and, where the breach is capable of remedy, fails to remedy it within 14 days of notice. We may also suspend or restrict your account immediately where necessary to protect the Services or other customers, or where you breach the acceptable use provisions. Upon termination, your right to use the service ends; we will retain or delete your Customer Data per the retention periods in our Privacy Notice. On termination you should retrieve any reports or data you wish to keep before your account is closed. After closure your data is retained for a short recovery period and then permanently deleted, as described in our Privacy Notice.
12. Changes to these terms
We may update these terms from time to time. We will notify you of material changes by email at least 30 days before they take effect. Continued use of the service after the effective date constitutes acceptance. Reacceptance on next sign-in para.
13. Governing law and jurisdiction
These terms are governed by the laws of England and Wales. Any dispute arising under or in connection with them is subject to the exclusive jurisdiction of the courts of England and Wales.
14. General
Force Majeure. Neither party is liable for any failure or delay in performing its obligations (other than payment) that is caused by an event beyond its reasonable control, including failures or outages of third-party infrastructure or communications networks, cyber attacks or acts of government. The affected party will take reasonable steps to mitigate the effect. If the event continues for more than 30 days, either party may terminate these terms by written notice.
Third Parties. We are not liable for failures, outages or changes in third-party services that are beyond our reasonable control. A person who is not party to these terms has no rights to enforce any provisions.
Entire Agreement. These terms constitute the entire agreement between the parties and supersede all prior discussions, representations or arrangements.
Waiver and severability. A failure or delay in exercising any right under these terms is not a waiver of it. If any provision is found to be invalid or unenforceable, it is to be severed to the minimum extent necessary and the remaining provisions continue in full force.
Survival. Termination does not affect any rights or liabilities that have accrued before it. Clauses that by their nature are intended to survive termination shall continue in full force and effect.
13. Contact