Privacy Policy.
Sender Registry
Effective Date: 21 July 2026
Our Commitment.
Sender Registry is committed to protecting the privacy of our users while helping organisations identify and defend against phishing, fraud and other email-based threats.
We have designed our service around the principle of data minimisation. We collect only the information necessary to provide our services and retain only the minimum technical information required to improve our threat detection capabilities.
How Sender Registry Processes Submitted Emails.
When a user forwards a suspicious email to Sender Registry, the email is analysed using automated systems to identify phishing attempts, malicious infrastructure, impersonation, malware indicators and other security threats.
The analysis may examine information including:
- Email headers
- Sending infrastructure
- Domain authentication (SPF, DKIM and DMARC)
- URLs
- Attachments
- Technical metadata
- Other indicators of compromise
The purpose of this analysis is solely to identify security threats and provide an assessment to the reporting user.
Removal of Personal Information.
Once analysis has been completed, Sender Registry removes identifying personal information from the submitted email wherever reasonably possible.
Sender Registry does not retain original email content for the purpose of building a database of personal communications.
Instead, the platform retains only anonymised technical threat intelligence and statistical information necessary to:
- Improve phishing detection
- Identify emerging attack campaigns
- Detect repeat malicious infrastructure
- Produce anonymous threat statistics
- Improve the accuracy of future analyses
- Help protect the wider Sender Registry community
Where retained information can no longer reasonably be linked to an identifiable individual, it is no longer treated as personal data.
Information We Retain.
Examples of information that may be retained include:
- Domain reputation
- IP addresses of sending mail servers
- SPF, DKIM and DMARC validation results
- Message fingerprints and cryptographic hashes
- Malware indicators
- URLs associated with phishing campaigns
- Threat classifications
- Risk scores
- Anonymous statistical information
- Detection confidence scores
This information is retained solely for cybersecurity and threat intelligence purposes.
Information We Do Not Intentionally Retain.
Sender Registry is designed so that it does not intentionally retain:
- Personal email correspondence
- Recipient names
- Personal message content
- Email signatures
- Contact lists
- Personal conversations
except where temporary processing is required to perform the requested analysis or where retention is required by law.
Customer Account Information.
To provide our services we may collect limited account information, including:
- Email address
- Authentication credentials
- Subscription information
- Account preferences
- Billing information (where applicable)
This information is used solely for operating the Sender Registry service and is never sold to third parties.
Security.
Sender Registry employs appropriate technical and organisational measures designed to protect customer information from unauthorised access, alteration, disclosure or destruction.
Access to operational systems is restricted to authorised personnel with a legitimate business need.
Data Minimisation.
Sender Registry follows the principle of data minimisation.
We deliberately avoid collecting unnecessary personal information and retain only the minimum data required to:
- Operate the service
- Improve detection accuracy
- Protect users against email threats
- Meet legal and regulatory obligations
Our Privacy Philosophy.
Sender Registry is an email threat intelligence platform, not an email archiving service.
Our objective is to identify malicious activity, not to collect or store personal communications.
Wherever possible, identifying personal information is removed following analysis, leaving only anonymised technical threat intelligence that helps improve protection for all users.
This privacy-first approach reduces the amount of personal information retained while continually strengthening the effectiveness of the Sender Registry network.
Contact.
If you have any questions regarding this policy or our handling of personal information, please contact:
Sender Registry
Website: https://www.senderregistry.com