When you visit our Mail Sentry service page, you will notice an interactive tool right near the top. It allows anyone to enter a domain name and instantly inspect its public email security posture (specifically its SPF, DKIM, DMARC, and BIMI records), complete with a client-side generated PDF report.
With most websites, standard practice dictates that, every form submission, button click, and domain search gets tracked, logged, and fed into a marketing telemetry pipeline or sales CRM.
We deliberately choose not to do that.
When you test a domain in our widget, we do not log your request, we do not harvest the domain name, and we do not store any record of who checked what. The analysis runs live, the report generates right there in your browser client-side, and once you close the page, the session vanishes.
Here is why we built it this way, and why privacy must be a core architectural choice rather than a corporate afterthought.
If you work in IT infrastructure or cyber security in South Africa, you have likely encountered online diagnostic tools that demand an email address before revealing your results. Or worse, tools that claim to be free while silently compiling a database of domains whose owners are actively investigating security vulnerabilities.
To us, that approach is fundamentally flawed. If a company claims to specialise in security and trust, the very first interaction you have with their systems should reflect those values.
When an IT manager, systems administrator, or business owner comes to our site to check their DMARC alignment, they are often in the middle of an audit or troubleshooting an active delivery issue. Forcing them to hand over personal telemetry or recording their query creates an unnecessary privacy risk.
By ensuring the domain inspection happens directly against public DNS and generates the report on the client side, we eliminate the need to store data on our servers altogether.
Under the Protection of Personal Information Act (POPIA), local organisations are rightly held accountable for how they collect, process, and retain data. The cleanest way to handle data privacy compliance is remarkably simple: do not collect data you do not need.
While public DNS records are technically public information, aggregate query logs can easily reveal operational intent. Knowing which domains are being queried, from which IP addresses, and at what time of day creates a digital footprint.
By choosing zero-retention by design, we protect both current clients and potential customers who are simply testing their posture:
No server logs: We do not maintain a database of searched domains.
Client-side reporting: PDF generation is handled in your browser rather than compiled on a remote server.
No registration: You do not need to log in or leave an email address just to run a health check.
Respecting user privacy is not a passive marketing statement for Prometheus Systems; it is an operational discipline. If a tool requires storing user inputs to function, it should be because the user explicitly asked for that state to be preserved. For an instant diagnostic utility, retention adds zero value to the end user and only serves to gather marketing intelligence at their expense.
We believe enterprise clients, financial institutions, and local businesses value transparency above all else. When you use our Mail Sentry tool to check your email domain posture, you get immediate, accurate engineering insights without leaving a trace on our infrastructure.
Give the tool a try on our Mail Sentry page whenever you need to review your domain's DMARC, SPF, or DKIM status.
Your privacy will always remain completely intact from the moment you load the page to the moment you download your report.