Mailscope — Privacy Policy
Last updated: 4 October 2026.
Mailscope does not ask for an account, shows no advertising, and does not record what you look up.
The checks run from your device. When you enter a domain, Mailscope looks up its public MX, SPF, DKIM and DMARC records over DNS-over-HTTPS, in order to display public technical information. The domains you check stay on your device. There is no backend server operated by us: we never receive the values you enter or their results.
When the domain has a mail server (MX), Mailscope can also open a connection to that server's port 25, read its greeting and see whether it offers encryption (STARTTLS), then disconnect; no mail is sent. As with any connection, that mail server sees the address it came from.
Compare from another country (VPN)
Optionally, you can add your own VPN key (vless://…) or a subscription link from your provider. Mailscope then builds a tunnel through that server so the same records can also be looked up, and the mail server's port 25 knocked on, as seen from there, and compared with what your own network sees. The app has no servers of its own; the server is yours or your provider's.
When you add a subscription link, the app downloads the server list from it. That request sends the provider the app name, the operating system and a random device number created by the app, which panels use to count devices. The link and its response are handled by your provider under its own terms.
While the tunnel is on, the whole device's traffic goes through that server, as with any VPN; Mailscope itself does not inspect, log or change that traffic. Checks "from there" go through a local tunnel entry on your device that is protected by a one-time password. The key, the subscription link and the server list are stored only on your device; delete them with "Remove key" or by uninstalling the app.
Install attribution. The app uses AppsFlyer, an attribution service, to learn which campaign or link an installation came from. For this it sends AppsFlyer the device's advertising identifier (Google Advertising ID), the fact of the installation, the times the app was opened, and basic device and network details such as the model, the operating system version and the country. AppsFlyer is a separate company and processes this data as a third party. It never receives anything you check in the app, and nothing about the tunnel.
You can limit this in Android: Settings → Privacy → Ads lets you delete the advertising identifier or opt out of personalisation, and the app keeps working either way.
Google Firebase: analytics, crash reports and notifications
The app uses Google Firebase, a set of services from Google LLC.
Analytics (Google Analytics for Firebase) counts installs, app opens and a few actions in the app: checking a domain’s mail records, the check from your own server, adding a key and the first successful tunnel, and opening the app from a notification. Only the fact of the action is recorded — never which servers, keys, links, domains, hosts or addresses were involved. Firebase receives an app instance identifier, the advertising ID (unless you have removed or limited it), the device model, OS and app version, and an approximate country derived from the network address. We use this to measure advertising campaigns (Google Ads) and to see which features are used.
Crash reports (Firebase Crashlytics): if the app crashes, Firebase receives a technical report — where in the code it happened, device model, OS and app version, free memory and a random installation identifier. Nothing about your traffic, keys or results.
Notifications (Firebase Cloud Messaging): to send occasional news about the app, Firebase issues a device token, and the app subscribes it to general topics — one for all users and one for the device language. No notification is addressed to you personally; you can turn them off in Android settings. AppsFlyer uses the same token only to learn that the app was uninstalled.
Google processes this data as a separate company under its own terms: https://firebase.google.com/support/privacy. The advertising ID can be deleted or limited in Android: Settings → Privacy → Ads.
Permissions: Internet access and network state, which the checks require; the VPN service, foreground service and notification, used only for the optional tunnel; notifications, also for occasional news about the app; and the advertising identifier, used only for the attribution described above.
The app is not directed to children.
Changes: if this policy changes, the updated version will be posted on this page.
Contact: you can reach the developer through the app's page on Google Play.
Политика конфиденциальности (русский)
Обновлено: 4 октября 2026 г.
Mailscope не просит регистрации, не показывает рекламу и не ведёт журнал того, что вы проверяете.
Проверки выполняются с вашего устройства. Когда вы вводите домен, Mailscope запрашивает его общедоступные записи MX, SPF, DKIM и DMARC по DNS-over-HTTPS и показывает результат. Проверенные домены остаются на устройстве. Своего сервера у нас нет: введённые значения и результаты проверок к нам не попадают.
Если у домена есть почтовый сервер (MX), Mailscope может ещё и соединиться с его 25-м портом, прочитать приветствие и узнать, предлагает ли он шифрование (STARTTLS), после чего отключается; письма не отправляются. Как при любом соединении, почтовый сервер видит адрес, с которого оно пришло.
Сверка из другой страны (VPN)
По желанию можно добавить свой ключ VPN (vless://…) или ссылку подписки от своего поставщика. Тогда Mailscope прокладывает туннель через этот сервер, чтобы запросить те же записи и постучаться на 25-й порт почтового сервера так, как это видно оттуда, и сравнить с тем, что видно из вашей сети. Своих серверов у приложения нет: сервер ваш или вашего поставщика.
Когда вы добавляете ссылку подписки, приложение скачивает по ней список серверов. В этом запросе поставщик получает название приложения, систему и случайный номер устройства, созданный приложением, — по нему панели считают устройства. Ссылкой и ответом распоряжается ваш поставщик на своих условиях.
Пока туннель включён, через этот сервер идёт трафик всего устройства, как у любого VPN; сам Mailscope этот трафик не просматривает, не записывает и не меняет. Проверки «оттуда» идут через локальный вход туннеля на устройстве, защищённый одноразовым паролем. Ключ, ссылка подписки и список серверов хранятся только на устройстве; удалить их можно кнопкой «Удалить ключ» или вместе с приложением.
Атрибуция установок. Приложение использует сервис AppsFlyer, чтобы понять, из какой кампании или по какой ссылке пришла установка. Для этого AppsFlyer передаются рекламный идентификатор устройства (Google Advertising ID), факт установки, моменты запуска приложения и общие сведения об устройстве и сети — модель, версия системы, страна. AppsFlyer — отдельная компания и обрабатывает эти данные как третья сторона. Ничего из того, что вы проверяете в приложении, ей не передаётся, как и ничего о туннеле.
Это можно ограничить средствами Android: в «Настройки → Конфиденциальность → Реклама» рекламный идентификатор можно удалить или отключить персонализацию — приложение продолжит работать.
Google Firebase: аналитика, отчёты о сбоях и уведомления
Приложение использует Google Firebase — набор сервисов компании Google LLC.
Аналитика (Google Analytics for Firebase) считает установки, запуски приложения и несколько действий в нём: проверка почтовых записей домена, сверка через ваш сервер, добавление ключа и первое удачное включение туннеля, а также открытие приложения из уведомления. Записывается только факт действия — никогда не то, какие серверы, ключи, ссылки, домены, хосты или адреса в нём участвовали. Firebase получает идентификатор установки приложения, рекламный идентификатор (если вы его не удалили и не ограничили), модель устройства, версии системы и приложения и примерную страну по сетевому адресу. Мы используем это, чтобы оценивать рекламные кампании (Google Ads) и понимать, какими функциями пользуются.
Отчёты о сбоях (Firebase Crashlytics): если приложение упадёт, Firebase получит технический отчёт — в каком месте кода произошёл сбой, модель устройства, версии системы и приложения, свободная память и случайный идентификатор установки. Ничего о вашем трафике, ключах и результатах.
Уведомления (Firebase Cloud Messaging): чтобы иногда присылать новости о приложении, Firebase выдаёт устройству токен, и приложение подписывает его на общие темы — для всех и для языка устройства. Лично вам уведомления не адресуются; выключить их можно в настройках Android. Тот же токен AppsFlyer использует только для того, чтобы узнать об удалении приложения.
Google обрабатывает эти данные как отдельная компания на своих условиях: https://firebase.google.com/support/privacy. Рекламный идентификатор можно удалить или ограничить в Android: «Настройки → Конфиденциальность → Реклама».
Разрешения: доступ в интернет и чтение состояния сети — для проверок; служба VPN, служба переднего плана и уведомление — только для туннеля по желанию; уведомления — также для новостей о приложении; рекламный идентификатор — только для описанной выше атрибуции.
Приложение не предназначено для детей.
Изменения: если политика изменится, обновлённая версия будет опубликована на этой странице.
Связь: с разработчиком можно связаться через страницу приложения в Google Play.