DomainsMesh
Legal

Cookie Policy

Last updated: August 28, 2026

1. What Cookies Are

Cookies are small text files placed on your device by a website. Similar technologies — localStorage, sessionStorage, pixels and device identifiers — do comparable things. This policy covers all of them and explains what DomainsMesh sets, why, and how you can control it.

2. Categories We Use

2.1 Strictly necessary

Required for the site to function and for basic security and abuse prevention (for example, rate limiting). These cannot be switched off.

The cookies below are set only once you sign in to an account. Analytics cookies are covered separately in 2.3:

  • authjs.session-token — keeps you signed in as you move between pages. HttpOnly (unreadable by JavaScript), SameSite=Lax, and served with the __Secure- name prefix over HTTPS. Expires about 30 days after it is issued, or when you sign out.
  • authjs.csrf-token — a per-session token used to verify that sign-in and sign-out requests genuinely came from our own pages, protecting against cross-site request forgery. HttpOnly; cleared when the browser session ends.
  • authjs.callback-url — remembers which page to return you to after a successful sign-in. HttpOnly; cleared when the browser session ends.

These are set by Auth.js, the authentication library this site runs on, and are first-party — they are readable only by domainsmesh.com and are never used for analytics, profiling or advertising.

2.2 Preferences

We store one value in your browser's localStorage. It is not a cookie, is never sent to our servers, and is not used to identify you:

  • dm-theme — remembers your light/dark mode choice.

You can remove it at any time by clearing your browser's site data for domainsmesh.com.

2.3 Analytics

We run two analytics systems, and they behave differently.

Google Analytics 4 measures audience and traffic patterns. It sets its own cookies in your browser, typically:

  • _ga — distinguishes one browser from another. Expires about 2 years after it is set.
  • _ga_<container-id> — keeps session state for this specific property. Expires about 2 years after it is set.

These are set by Google, not by us, and are governed by Google's privacy policy. You can opt out of Google Analytics across all sites with Google's opt-out browser add-on, or by blocking these cookies in your browser — the tools work exactly the same either way.

Our own first-party analytics sets no cookies. When you run a tool, your browser sends one usage event to our own server recording which tool was used, the query, how many results came back, whether it succeeded and how long it took, along with your browser's user-agent, the referring URL and a country code. If you click one of the results, we record which one and its position in the list. Your IP address is hashed with a secret salt before storage and the raw address is not kept. Full detail is in section 2.3 of our Privacy Policy.

2.4 Advertising

We do not currently serve advertising on this site. No advertising, ad-targeting or ad-measurement code is loaded on any page, and no advertising cookies are set.

If we introduce advertising in future, we will update this policy and our Privacy Policy to name the ad provider and its cookies, and will put any consent mechanism required in your region in place, before any ad code is deployed.

2.5 Affiliate tracking

Outbound registrar links are routed through /go/[registrar] on our own domain. When you follow one, the destination provider may set its own cookie to attribute the referral. That cookie is set by the provider, on their domain, under their privacy policy — not by us. See our Affiliate Disclosure.

3. Your Choices

3.1 Consent (EEA, UK and Switzerland)

Google Analytics sets cookies that are not strictly necessary, so if you are in the EEA, the UK or Switzerland you have the right to refuse them. You can do that today by blocking third-party cookies for this site, or by installing Google's opt-out browser add-on. Nothing on this site stops working if you do.

We are candid about the current state: this site does not yet present a consent banner that blocks those cookies until you accept. If you are subject to those rules and require prior consent, treat the opt-out above as the mechanism available today. The sign-in cookies in section 2.1 are exempt from consent requirements because they are required to deliver a service you explicitly asked for, and our own first-party analytics sets no cookies at all.

3.2 Browser controls

Every major browser lets you block or delete cookies through its settings. Blocking all cookies may break parts of this or other websites. Most browsers also offer a "Do Not Track" signal; because there is still no agreed industry standard for honouring it, we do not respond to DNT headers, but we do honour Global Privacy Control (GPC) signals where legally required.

3.3 US state privacy rights

If you are a resident of California or another US state with comparable law, you may opt out of the "sale" or "sharing" of personal information for cross-context behavioural advertising. We do not sell or share personal information for that purpose — we run no advertising and no third-party analytics. You can still exercise your access and deletion rights by emailing [email protected].

4. Children

DomainsMesh is not directed at children under 13 and we do not knowingly serve personalised advertising to children. Ad requests from this site are not tagged as child-directed content under COPPA because the site is a general-audience business tool.

5. Changes

We will update this page whenever our cookie or advertising practices change, and will revise the "Last updated" date accordingly.

6. Contact

Questions about cookies or advertising on DomainsMesh? Email [email protected]. See also our Privacy Policy.