Privacy
Operator: AuthEmailTest.com / GetOnline Limited (company number 03151203), registered in England and Wales. References to “we”, “us”, and “our” on this page mean GetOnline Limited.
AuthEmailTest.com is designed for short-lived email authentication and delivery diagnostics. This page explains what is processed when you create a test, send a diagnostic message, or use the contact form.
Diagnostic Tests
When you create a test we store the email address you say you will send from, the generated test address, the creation time, expiry time, requester IP address, and sender-domain pre-check results. When a message arrives we store the raw message, SMTP session details, message-format analysis, authentication analysis, and spam-filter analysis, including connecting IP, HELO name, envelope sender, recipient address, message hash, originator and authentication-result headers, MIME and transport-format findings, DKIM signatures, SPF result, DMARC alignment, ARC verification, scanner scores, actions, and rule matches.
Message Content
Accepted diagnostic messages are stored so the service can analyse and display the inbound result. Messages are also scanned by Rspamd and SpamAssassin to provide spam-filtering diagnostic scores. For deeper spam filter analysis, send the actual message you are sending rather than forwarding it. Avoid confidential, sensitive, regulated, privileged, or unnecessary personal content. Messages over 1 MB, including headers and body, are rejected.
Retention
Anonymous addresses are short-lived and accept one message only. Account persistent addresses remain active while the account and plan allow, and accept only messages covered by their current credit allocation. Anonymous result pages and diagnostic data are currently retained for 7 days. Account reports are retained for 30 days. Deliberately disabled account addresses are removed after 60 days, while plan-suspended addresses are retained for possible reactivation; issued address identifiers remain reserved so they cannot be allocated to another user. Raw messages remain subject to the shorter configured raw-message retention period. Cleanup jobs remove expired data. A completed anonymous report also includes a delete option that removes the stored diagnostic result before normal expiry. Operational reports may include aggregate counts such as tests created, messages received, queue status, scanner status, DNSBL/RBL query-blocking notices, service status, and disk usage.
Accounts
If you create an account, we store your verified email address, an Argon2id password hash, account status and plan, security tokens in hashed form, session records, account security events, persistent test addresses, optional details you add for your own reference, monthly credit allocations and usage, credit ledger events, and links between your account, addresses, and reports. Address details are private to the account dashboard and should not contain passwords, confidential information, or unnecessary personal data. Raw activation, password-reset, email-confirmation, and session tokens are not stored. Account reports are retained for 30 days. Raw message content remains subject to the shorter raw-message retention period.
New passwords are assessed locally for predictable patterns and screened against the Have I Been Pwned password range service using only the first five characters of a SHA-1 password hash. The complete password and complete hash are not sent. Account activation, recovery, email-change, and security emails are delivered through AuthSMTP and may be queued for retry.
Contact Form
If you use the contact form, we process the name, email address, subject, message, requester IP address, and submission time so we can receive and respond to your message. Contact submissions are stored before delivery is attempted, and may be retried if email delivery is temporarily unavailable.
Service Providers
Website requests pass through Cloudflare's content-delivery and security network. Cloudflare may process request and response metadata such as IP address, host, URL, timing, browser and network information to proxy, protect and operate the service. Browser Network Error Logging may send limited connection and failure information to Cloudflare's reporting endpoint. Form submissions are also checked using Cloudflare Turnstile for spam prevention. Contact form messages, account emails, and operational reports are sent using the AuthSMTP email service. Those providers may process technical request data and message content as part of delivering, protecting, and securing the service.
Content Security Policy violation reports may send the affected page, blocked resource, violated policy directive and requester IP address to this service. Reports are rate-limited, sanitised and recorded in operational logs for security diagnosis. The endpoint does not intentionally collect page content or submitted form bodies.
Security and Abuse Prevention
We use random addresses, short lifetimes or credit-limited acceptance, duplicate detection, request limits, recipient validation, message-size limits, Rspamd and SpamAssassin scanning, cleanup jobs, Cloudflare protection, and firewall rules to reduce abuse and protect the service. We may reject, block, rate-limit, remove, or investigate activity that appears abusive, automated, unauthorised, or outside the intended diagnostic purpose.
Questions
If you have a privacy question about AuthEmailTest.com, please contact us.