What we collect, and what we do with DNS access
Last updated: August 2026
This business asks people to trust us with DNS access — that's a real, meaningful thing to hand over, so this page is written to actually explain what happens, not to sit there unread. If anything here is unclear, email us and ask.
The free domain check on /audit
When you type a domain into the checker on the audit page, your browser queries a public DNS resolver (Cloudflare's DNS-over-HTTPS service) directly. That lookup does not pass through a Brillux server — we don't see, log, or store the domains people check with that tool. The only party that sees the query, in the ordinary way any DNS lookup works, is the resolver itself.
The contact form
The contact form on this site opens your own email client with the message pre-filled, and sends the message the same way any email you write does — as email, to our inbox. We don't run it through a separate database or third-party form service. Whatever you type is only stored the same way any email we receive is stored.
Cookies and tracking
This site does not currently set cookies or use any third-party analytics or advertising trackers. If that changes in the future, this policy will be updated first.
What DNS access is used for, during an actual engagement
If you engage us for a paid fix, we may ask for access to make changes at your DNS provider (or ask you to paste in exact records we provide, if you'd rather keep access yourself). Where we do have access, it's used for exactly one thing:
- Reading and modifying the specific records needed for SPF, DKIM, and DMARC — nothing else.
What DNS access is never used for
- We don't read, modify, or export records unrelated to email authentication (A records, MX records you haven't asked us to touch, nameserver settings, etc.) unless a change there is specifically part of what we've agreed to do.
- We don't access any other account or service tied to the same DNS provider login.
- We don't sell, share, or use your domain or DNS information for marketing to anyone else.
Retention
Direct DNS access (if you grant it, rather than us handing you records to paste in yourself) is used for the duration of the engagement and the staged rollout that follows it, then not used again unless you ask us back. Contact-form and email correspondence is kept as long as is reasonably needed to do the work and maintain ordinary business records.
White-label engagements
For agency partners, the same rules apply to the end client's DNS, and end-client information is only used to complete the specific engagement the agency has brought us — never used to contact that client directly outside of what's been agreed with the agency.
Questions
Email founder@briluxlabshq.com for anything not covered here, including requests to see or delete information we hold about you.
Written in plain language on purpose, and kept accurate to how this site and this business actually operate. If your business has specific compliance requirements (GDPR, CCPA, or similar), it's worth having this reviewed by someone qualified before it's your only privacy policy in production — this is a solid starting point, not a substitute for that review.