Legal

Acceptable Use Policy

What you may and may not send through the service. Sending mail nobody asked for is the fastest way to lose your account.

Last updated 2026-08-10

What this says, in short

  • Only mail people who actually asked to hear from you.
  • No forged headers, impersonation or phishing — ever.
  • Honour unsubscribes, bounces and spam complaints.
  • Deliberate abuse means immediate suspension, without notice.

This summary is for orientation only — the numbered sections below are the terms that apply.

01

Why this policy exists

Email reputation is shared. Mail sent from our infrastructure is judged by receiving providers partly on the behaviour of everyone else sending through it, so one customer sending mail nobody asked for can push another customer's legitimate mail into spam folders. That is why this policy is enforced strictly and quickly.

In plain terms: One spammer can wreck deliverability for every other customer, so we do not tolerate it.

03

Be honest about who you are

  • Do not forge headers, disguise the origin of a message, or impersonate another person, company or brand.
  • Do not send phishing, credential harvesting, or any message designed to trick someone into handing over money or secrets.
  • Use a From address on a domain you actually control and have verified with us.
  • Give commercial recipients a working way to unsubscribe, and honour it promptly.

04

Prohibited content and activity

  • Anything unlawful where you or your recipients are.
  • Malware, ransomware, or links to it.
  • Child sexual abuse material — reported to the authorities, always, without notice.
  • Content that harasses, threatens, or incites violence against someone.
  • Fraud, pyramid or Ponzi schemes, fake invoices, and advance-fee scams.
  • Infringing someone else's copyright or trademark.

05

Technical abuse

  • Do not attempt to breach, probe or disrupt the service or another customer's account.
  • Do not evade rate limits, plan quotas, or a suspension — including by opening additional accounts.
  • Do not point webhook endpoints at internal or private network addresses to make our servers reach systems they should not.
  • Do not resell raw access to the service in a way that hides who the real sender is.

06

Rate limits and quotas

The public API is rate limited per account, and entry-level plans carry a daily ceiling on sends alongside the monthly allotment — bursts, rather than steady volume, are what abuse usually looks like. These limits protect the platform; treat them as part of this policy rather than as an obstacle to route around.

07

How we enforce it

Depending on what we find, we may throttle sending, suspend the ability to send while keeping receiving live, suspend the account entirely, or terminate it. Where the harm is ongoing — an active phishing campaign, for example — we act first and explain afterwards.

For a first, apparently honest mistake we will normally contact you and give you a chance to fix it. Deliberate abuse gets no such notice.

In plain terms: Honest mistake: we will talk to you first. Deliberate spam or phishing: the account goes off immediately.

08

Reporting abuse

If you have received mail sent through our infrastructure that breaks this policy, report it to abuse@inboundr.net. Include the full message headers if you can — they let us identify the sending account. We investigate every report.

09

Appeals

If you believe we suspended you in error, write to support@inboundr.net with the details. We will review it and, where we got it wrong, restore the account.