Privacy Policy
Last updated 18 August 2026
The short version
- There are no accounts. We never ask for your name, address, phone number or payment details, and there is nothing to sign up for.
- We do not keep a history of your lookups linked to you. Queries are answered and discarded.
- Your IP address is used to apply a rate limit. It is stored only as an irreversible hash, alongside timestamps, for about a minute.
- When you run a lookup, the domain or IP you typed is sent to the services that can answer it — public DNS resolvers, registries and, for the connection tools, the host itself.
- We show ads through Google AdSense and measure traffic with Google Analytics. Both set cookies, and in the EEA, UK and Switzerland neither runs until you consent.
- We do not sell your personal information for money.
The rest of this page is the detail behind those points.
1. Who we are
DNS Fetcher is a free network diagnostics website at dnsfetcher.com, operated as an independent project by Russell Benzing. For the purposes of the UK and EU General Data Protection Regulation, that operator is the data controller for the processing described here.
Privacy enquiries: privacy@dnsfetcher.com.
We have not appointed a Data Protection Officer, and are not required to: the site processes no special-category data, carries out no large-scale monitoring of individuals, and holds no user accounts.
2. What this policy covers
This policy applies to the DNS Fetcher website and its lookup tools. It does not apply to the third-party sites and services described below, each of which acts under its own policy, nor to any host you choose to run a lookup against.
3. Information we collect
3.1 What you type into the tools
To answer a lookup we necessarily process what you submit: a domain name or IP address, and depending on the tool, a TCP port number or a DKIM selector. These are the query itself — without them there is no result to return.
We do not store these submissions in a database, and we do not build a profile or search history from them. They exist for the life of the request. Two exceptions are worth stating plainly:
- If a lookup fails unexpectedly, the tool name and the target you entered are written to the server error log so the fault can be diagnosed. This is a technical log, reviewed only when something is broken.
- Registry lookups are cached briefly — by the answer, not by who asked. A cached answer contains no information about you.
Please note: a hostname can itself contain personal information, for example jane-smith.example.com. Anything you type is transmitted onward to the services described in section 7, so treat the input box as public.
3.2 What is collected automatically
Like any web server, ours records technical details of each request. This includes your IP address, the page or endpoint requested, the date and time, the HTTP status returned, your browser's user-agent string, and the referring page if your browser sends one.
Your IP address is additionally used to enforce a rate limit. It is never written to disk as an address: it is hashed with SHA-256, and only that hash — together with the timestamps of recent requests — is stored. The hash cannot be read back as an IP address.
As a convenience, the tool page pre-fills the target box with the IP address your request appears to come from. That happens in the page you are served; it is not recorded.
3.3 What cookies and third-party tags collect
Where you have consented, Google AdSense and Google Analytics collect information about your visit through cookies and similar technologies. See sections 5, 8 and 9.
4. Information we deliberately do not collect
To be unambiguous about the boundaries of this site:
- There is no registration, login, or user account of any kind.
- We do not ask for or process your name, postal address, telephone number, date of birth, or government identifiers.
- We take no payments and hold no card or bank details.
- There is no file upload, no contact form, and no newsletter.
- We do not process special categories of personal data (health, biometrics, race, religion, sexual orientation, political opinion, trade union membership) or criminal offence data.
- We do not link lookups to an identified individual, and we make no attempt to re-identify the hashed addresses used for rate limiting.
5. Cookies and similar technologies
Cookie choices on this site are managed through a consent banner provided by CookieScript. You can reopen it at any time to change or withdraw your choice. Withdrawing consent is as easy as giving it, and does not affect the lawfulness of anything done before you withdrew.
Only the first category below is set without your consent, because the site cannot function securely without it.
| Cookie | Set by | Category | Purpose | Duration |
|---|---|---|---|---|
| dnsfetcher_session | This site | Strictly necessary | Holds the anti-forgery token that proves a lookup came from this page and not from another site acting as you. Contains no identifier for you and is not used for analytics. | Until you close the browser |
| CookieScript consent record | CookieScript | Strictly necessary | Remembers the choice you made in the banner, so you are not asked on every page. Recording a refusal is itself a legal requirement. | Up to 12 months |
| Google Analytics (_ga, _ga_*) | Analytics — consent required | Distinguishes one visitor from another so we can count visits and see which tools are used. | Up to 2 years | |
| Google advertising cookies | Google and its ad-technology partners | Advertising — consent required | Selects and measures ads, limits how often you see the same one, and detects invalid traffic. | Varies by cookie; see Google's disclosure |
You can also block or delete cookies in your browser settings. Blocking the strictly necessary cookie will prevent lookups from running, because the security check that protects the endpoint will fail.
6. Why we use information, and our legal basis
Where the UK or EU GDPR applies, we must have a lawful basis for each purpose. Ours are as follows.
| Purpose | Information used | Legal basis |
|---|---|---|
| Running the lookup you asked for and returning the result | The target, port or selector you submitted | Legitimate interests — performing the service you requested |
| Keeping the site available and preventing it being used as an abuse relay | Hashed IP address, request timestamps | Legitimate interests — network and information security |
| Protecting the endpoint against cross-site request forgery | Session cookie | Legitimate interests — securing the service; strictly necessary under the ePrivacy rules |
| Diagnosing faults | Server logs, error logs | Legitimate interests — maintaining a working service |
| Measuring how the site is used | Analytics cookies and the data they generate | Consent |
| Showing ads, which is what pays for the site | Advertising cookies and the data they generate | Consent |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights. Rate limiting is the clearest case: it uses the minimum possible — an irreversible hash, held for roughly a minute — and without it a free, unauthenticated tool that opens network connections would be abused within days.
7. Where your lookups are sent
This is the part most general-purpose privacy policies leave out, and it is the most important thing to understand about a diagnostics site. A lookup is not answered by us alone. Depending on the tool you choose, what you type is forwarded to one or more of the following.
- Public DNS resolvers. DNS queries are answered by the hosting provider's resolver, and where a record type requires it, by Google Public DNS (dns.google) or Cloudflare (cloudflare-dns.com) over HTTPS. These operators receive the name being looked up and our server's IP address.
- IANA. We fetch IANA's public registry files to determine which registry is authoritative for a domain or IP range.
- Domain and IP registries. WHOIS and RDAP queries go to the registry or registrar responsible for the name or address, which may be anywhere in the world. Those operators publish their own terms and may log and rate-limit queries.
- The host you named. The TLS certificate, HTTP path trace, port check and TCP ping tools connect directly to the host you enter. That host's operator will see a connection in their logs.
Those connections come from our server, not from your device. The host being tested sees our hosting provider's IP address, not yours. That is a privacy benefit to you, and it is also why the tools are rate limited — the responsibility for what is probed rests with us.
For that reason, please use the connection tools only against hosts you own or are authorised to test. Using them to scan or probe systems without permission may be unlawful where you are, and we may restrict access where we see it happening.
8. Advertising
DNS Fetcher is free, and ads are how it stays that way. Ads are served by Google AdSense.
- Google and its partners use cookies and similar technologies to select ads, measure their performance, cap how often you see the same ad, and detect fraudulent clicks.
- In the EEA, UK and Switzerland, no advertising cookie is set and no personalised ad is requested until you consent through the banner. If you decline, ads may still appear, but they are non-personalised — chosen from the page content rather than from a profile.
- You can control the ads you see across the web at Google My Ad Center, and review how Google uses data from partner sites at policies.google.com/technologies/partner-sites.
- Industry opt-outs are available at optout.aboutads.info and youradchoices.ca.
We do not receive your identity from Google. We see only aggregate earnings and performance reports.
9. Analytics
We use Google Analytics 4 to understand how many people visit and which tools they use. It runs only with your consent.
Google Analytics 4 does not log or store full IP addresses. Your address is used in transit to derive an approximate location — typically no more precise than a city — and is then discarded.
Measurement data is sent to Google endpoints including analytics.google.com, google-analytics.com and stats.g.doubleclick.net. Where Google's advertising features are active on the property, Google may use this data to build audiences and to support ad measurement. You can prevent that by declining analytics cookies, or by turning off ad personalisation in Google My Ad Center.
You can opt out of Google Analytics on every site using the Google Analytics opt-out browser add-on, or simply decline analytics cookies in our banner.
10. Who else receives information
We do not sell personal information, and we do not share it with anyone for their own independent marketing. Information reaches only the parties needed to run the site:
- Hostinger — hosting provider; processes server logs on our behalf.
- Google — advertising and analytics, as described above.
- CookieScript — consent management.
- The lookup services in section 7 — which receive the query, not information about you.
We may also disclose information where we are legally required to, or where it is necessary to establish or defend legal claims or to investigate abuse of the service. If the site were ever transferred to a new operator, this policy would transfer with it and we would say so here before the change took effect.
11. International transfers
Google and CookieScript operate internationally, and the registry and DNS operators contacted during a lookup may be located anywhere. Where personal data is transferred out of the UK or EEA, it is done under the safeguards those providers maintain — principally the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, and, for participating US organisations, the EU–US and UK–US Data Privacy Framework.
A DNS or WHOIS query is not, in itself, a transfer of your personal data: it carries our server's address, not yours.
12. How long we keep information
| What | Kept for |
|---|---|
| The lookup you submitted | The duration of the request. Not stored afterwards. |
| Rate-limit records (hashed IP plus timestamps) | A rolling window of roughly one minute; entries outside it are discarded on the next request. |
| Cached registry answers | A short period, keyed by the answer. Contains nothing about who asked. |
| Web server and error logs | As retained by our hosting provider, typically a small number of weeks. |
| Analytics data | As configured in Google Analytics; event-level data expires within 14 months. |
| Advertising data | Held by Google under its own retention policy. |
13. Security
The site is served over HTTPS only, with HTTP Strict Transport Security, a Content Security Policy, and cookies marked Secure, HttpOnly and SameSite=Lax. Lookup requests carry an anti-forgery token. Results are inserted into the page as text and never as markup, so a hostile response from a registry cannot execute in your browser.
We keep the smallest amount of personal data we can, which is itself the most effective control available to a site like this one. No system is perfectly secure, and we cannot guarantee that transmission over the internet is free from interception.
14. Your rights in the EEA, UK and Switzerland
If the UK or EU GDPR applies to you, you have the right to:
- ask what personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- have data erased;
- restrict how we use it, or object to use based on legitimate interests;
- receive data you gave us in a portable format;
- withdraw consent to analytics or advertising at any time, through the cookie banner; and
- complain to a supervisory authority.
We must be straightforward about a limitation here. Because we hold no accounts and store IP addresses only as irreversible hashes, we usually cannot identify you from the information we hold. Under Article 11 GDPR, where a controller cannot identify a data subject, the access, rectification, erasure and portability rights do not apply unless you provide additional information that makes identification possible. This is a consequence of collecting very little, not a way of avoiding the obligation, and we will always explain what we can and cannot do in response to a request.
Most of what is held about you sits with Google, through the cookies you consented to. Those rights are best exercised directly with Google, and we will help you do so if you ask.
To make a request, email privacy@dnsfetcher.com. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
You can complain to your local supervisory authority. In the UK that is the Information Commissioner's Office; in the EEA, the authority in your country of residence or workplace.
15. Your rights in US states
California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and a growing number of other states give residents rights over personal information. Depending on your state, these include the right to know what is collected and why, to obtain a copy, to correct it, to delete it, to opt out of targeted advertising and of the sale or sharing of personal information, and not to be discriminated against for exercising a right.
We do not sell personal information for money. However, under the California Consumer Privacy Act as amended, and under comparable laws in other states, allowing advertising cookies to operate can qualify as “sharing” personal information for cross-context behavioural advertising, and in some readings as a “sale”. We state that plainly rather than rely on a narrow definition.
To opt out, decline advertising cookies in the banner, or send a Global Privacy Control signal, which we honour as described in the next section. You do not need an account, and we do not require you to verify your identity to exercise an opt-out.
In the twelve months before the date of this policy, the categories of personal information involved were identifiers (IP address, cookie identifiers), internet activity (pages viewed, tools used), and coarse location inferred from IP address. We disclose these for the business purposes set out in section 6 only. We do not knowingly collect or sell the personal information of anyone under 16.
To exercise a right, or to appeal a decision we make about one, email privacy@dnsfetcher.com. An authorised agent may act for you with written permission.
16. Do Not Track and Global Privacy Control
Global Privacy Control (GPC) is a browser signal with an agreed legal meaning, and we treat it as a valid opt-out of advertising and analytics cookies where the law recognises it.
Do Not Track (DNT) is a different matter. No common standard for interpreting it was ever finished, and browsers have largely removed it. Like most sites, we do not respond to DNT, and we say so because California law requires the disclosure. Use the cookie banner or GPC instead; both work.
17. Children
This site is a technical tool intended for adults working in IT and web development. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided personal information, contact us and we will delete what we can.
18. Automated decision-making
We do not carry out profiling or automated decision-making that produces legal or similarly significant effects. The rate limiter is automated, but it does no more than briefly slow a source making too many requests, and it operates on a hash rather than on any profile of a person.
19. Links to other sites
Results may contain links or references to registrars, registries and other organisations, and the site links to the developer's own website. We do not control those sites and are not responsible for their privacy practices.
20. Changes to this policy
We will update this policy when the site changes. The revision date at the top always reflects the current version. Where a change materially affects how your information is used, we will make that clear on the site before it takes effect, and where the law requires it we will ask for your consent again.
21. Contact and complaints
Questions, requests and complaints about privacy: privacy@dnsfetcher.com.
We would rather hear from you first, but you always have the right to go straight to your data protection authority.