Privacy
Privacy statement
DNS Radar has no accounts, advertising profiles or database of scan reports. Much of the processing happens in your browser, but external services are also used for DNS, registration data, abuse prevention and hosting. This statement explains which data leaves your device for each part of the service and what may be logged temporarily.
Last updated: 26 August 2026
Who operates DNS Radar
DNS Radar is operated by Joris de Vaan. This statement applies to the website, the domain scan and the separate tools on dnsradar.eu. DNS Radar uses received data only to perform the function you started, protect the service and investigate technical failures. The data is not sold, used for targeted advertising or added to a mailing or customer profile.
What stays on your device
The list of up to six recently scanned domains is kept in local browser storage and is not synchronised with DNS Radar. Scan results are processed for the open page and are not written as reports to a first-party database. The Mail headers tool parses the complete pasted header locally. Only extracted From and Return-Path domains are checked for mail routing through public DNS; local-parts, subject and message body are not sent. The optional blacklist check uses an IP address selected in Reverse DNS or detected in mail headers only when you request it. You can remove the recent-domain list by clearing the site data for DNS Radar in your browser.
What data the tools send
A DNS lookup contains at least the queried DNS name and record type; for reverse DNS it is a derived name containing the IP address. Depending on the selected tool, those queries go directly to public resolvers operated by Cloudflare, Google, DNS4EU, IIJ or AliDNS. The Mail headers tool queries only extracted From and Return-Path domains. RDAP requests contain the domain name and go to the relevant public registry or registrar service. If you select ‘Use my current public IP’ in Reverse DNS, the DNS Radar Worker reads the connecting IP address from that request only. When you start a blacklist check, DNSBL names containing the selected IPv4 address are queried through Cloudflare DNS. A pasted mail header is not included.
When a request uses the DNS Radar Worker
If your browser cannot reach a resolver or RDAP service directly, the lookup may run through a Cloudflare Worker. The Worker then receives the data needed for the selected task, such as the domain name, scan mode, record type and any DKIM selectors entered manually. During a full scan the Worker may also retrieve the public MTA-STS policy file. The application does not write the request body or resulting scan report to its own database, KV store, object storage or other application storage.
IP addresses, rate limiting and Turnstile
Every connection to the website or Worker makes the public IP address technically visible to Cloudflare. The Worker uses the request IP to limit the number of requests per user or network. The protected scan, RDAP and DNS routes also use Cloudflare Turnstile. Your browser sends a short-lived token, which DNS Radar asks Cloudflare Siteverify to validate together with the request IP. Cloudflare processes browser and network signals to identify automated or abusive traffic.
Operational logs and retention
Cloudflare Workers Observability is enabled for fault investigation and availability monitoring. Cloudflare may therefore retain invocation logs, request and response metadata, errors and technical context for a Worker request. The current maximum retention period for Workers Logs is seven days, after which Cloudflare removes the logs under the configured service limits. DNS Radar does not deliberately log the domain from the request body or the complete scan report, but technical connection data and the invoked route may appear in platform logs. External resolvers and registries apply their own logging and retention periods.
Web Analytics and cookies
DNS Radar uses Cloudflare Web Analytics for aggregated visitor and performance statistics. Its Web Analytics beacon works without analytics cookies, and Cloudflare states that the source IP is discarded at the nearest data centre and is not stored in the RUM dataset. DNS Radar does not set advertising or tracking cookies itself. Cloudflare may use strictly necessary cookies or comparable browser storage for network security and Turnstile; Cloudflare's privacy and cookie policies apply to that processing.
External services and processing outside the EEA
Cloudflare, Google, DNS4EU, IIJ, AliDNS, RDAP registries and DNSBL operators each process only the requests sent to their service. Depending on the selected resolver, registry and network route, processing may take place inside or outside the European Economic Area, including in the United States, Japan and China. DNS Radar does not control which individual anycast data centre handles a request to a public resolver. Each provider's own privacy terms govern that processing, transfer and retention.
Choices you control
You can run the domain scan in explicit browser mode, select a specific resolver where the tool supports it, and avoid optional functions such as ‘Use my current public IP’ or the blacklist check. A browser, firewall or ad blocker can block external DNS and Turnstile requests, but parts of the measurement may then fail. Do not place confidential information in a domain name, DKIM selector or mail header: DNS and RDAP are public systems, and pasted headers may contain personal data even though the complete header remains on your device during local analysis.
Changes to this statement
This statement is updated when DNS Radar adds a new data flow, external service or relevant storage method. The date above shows when the text was last changed materially. This page is updated as soon as reasonably possible after a relevant technical change; changing the wording alone never expands the actual data flows.