Skip to main content
This page explains what happens to an email from the moment a member bans a user to the moment the entry is deleted. For the request and response details, see Check a sign-up and Report a banned user.

Terms

Hashing

An email passes through three steps before the registry stores anything. The first two run on your servers, so the email itself never leaves your platform.
  1. Normalise. Different spellings of one mailbox become one value. For example, Gmail ignores dots and +tags, so J.a.n.e.D.o.e+x@GoogleMail.com and janedoe@gmail.com reach the same inbox. Every member applies the same normalisation rules.
  2. SHA-256. You hash the normalised email and send only the hash.
  3. Keyed HMAC. The registry computes an HMAC of your hash with a secret key that only Omnifence holds, and stores that value. It discards your hash when the request ends.
Step 3 matters because a plain SHA-256 of an email is easy to reverse: anyone with a list of email addresses can hash every one and compare. Without the secret key, the stored values match nothing. See Privacy and security.

Reporting and checking

The same hash from two members leads to the same stored identifier, so Member B matches the report from Member A without either member ever seeing the other’s data.

What a check returns

A check returns one signal for each category that at least one member reported for the identifiers you sent: A check never returns an entry ID, the name of a reporting member, or a case reference. A signal is the same whether one member reported the user or five, except for reporter_count. Only live entries match. An entry that is disputed, revoked or past its retention period does not appear in any check.

The life of an entry

The diagram shows the main path. A disputed entry can also be revoked or expire, and a new report from the member reactivates a revoked or expired entry (see below). A revoked or expired entry is deleted 30 days after it stops matching. After that, nothing in the registry links to the identifier. When a member reports the same identifier and category again, the registry refreshes the existing entry: it takes the new case reference and restarts the retention period. A new report reactivates a revoked or expired entry, because a new ban is a new decision. It never ends a dispute: only Omnifence resolves a dispute.

Several members, one user

Each member’s report is a separate entry. If three members report the same user for payment fraud, the registry holds three entries, and a check returns one signal with reporter_count: 3. If one of those members revokes its report, the signal drops to reporter_count: 2. The other two reports are not affected.

Next steps

Hash an email

The normalisation rules, a reference implementation and test vectors.

Privacy and security

What the registry stores, what it never stores, and who can see what.