How long is my data kept?
Short answer: retention follows your plan — 30 days of history on Free, a full year on Starter — and stored data is physically deleted only after an extra 60-day grace period beyond your plan's window. Deletion on request is always available. Here is exactly what that means.
What we store
When an aggregate report arrives for your domain, we parse the XML and keep the structured rows. For each sending source in a report, that is:
- the source IP address and the message count it sent;
- the authentication results — SPF and DKIM outcomes and the DMARC disposition that was applied;
- the domains involved — the header-from and envelope-from;
- the reporter and period — which operator sent the report (Google, Microsoft, Yahoo and so on) and the date range it covers;
- derived fields we compute ourselves: the sending country, resolved from the IP inside our own database, and the provider grouping shown under sending sources.
For a guided tour of what these fields mean and how to interpret them, see How to read DMARC reports.
Just as important is what is not stored, because it never arrives in the first place: aggregate reports contain no message content — no bodies, no subject lines, no recipient addresses. That is the nature of the RUA format itself, and it is covered in more detail in Security and privacy at DMARCmetric.
How long we keep it
Retention has two layers, and the difference matters:
What you can see — the plan window. Dashboards, exports and summaries read at most your plan's retention window: 30 days on Free, a full year (365 days) on Starter. Range selectors beyond your plan's window are locked, and charts label the window actually shown.
What we store — the window plus a 60-day grace. Report data older than your plan's window is not deleted immediately: a nightly job physically removes data only once it is older than your window plus 60 days — roughly 90 days of storage on Free, about 14 months on Starter. The grace period exists for one reason: upgrading instantly reveals still-stored history. Move from Free to Starter and the dashboard immediately shows everything inside the last year that has not yet been purged.
The purge covers all report-derived data consistently: aggregate report rows (measured by the report's own period, so a late-arriving old report still honours the window), the plain-English summaries computed from them, and alerts. Forensic failure samples have their own fixed 30-day window, unchanged by plan. What each plan includes is covered in Pricing and the free tier.
Deletion on request
You do not have to wait for a retention policy in order to get rid of data:
- Removing a domain removes its data. Deleting a domain from your workspace deletes its stored reports and their rows from the application database immediately — a hard delete, not a soft hide.
- Everything else: just ask. Self-service account deletion is not in the product yet, so it is handled by hand — email [email protected] from your account's address and we will delete your account and its data.
Dashboard ranges and the plan window
The 7 / 30 / 90-day and 12-month selectors on the dashboards choose how much of your stored data the current view reads. Within your plan's window they are just a lens: switching from 12 months down to 7 days discards nothing, and switching back shows the full window again.
The plan window is the boundary. On Free, views read at most the last 30 days — even though up to ~90 days may still be stored during the grace period, that older slice becomes visible again the moment you upgrade, not before. On Starter, all four selectors work at full depth.
The same applies to CSV export: it exports whatever the current view's window contains. If a number looks lower than you expected, check the selected range — and your plan's window — before suspecting deletion.