Acceptable Use Policy (Anti-Spam Policy)

DRAFT — pending operator legal sign-off. Thresholds and mechanisms below mirror what the platform actually enforces in code (audited 2026-07-24). If the code changes, this document must change with it — and vice versa.

Last updated: [DATE]

This policy applies to every customer of InboxTempo and is incorporated into the Terms of Service. We run shared sending infrastructure: one customer's spam damages every customer's deliverability. These rules are therefore enforced automatically and strictly.

You may only send to recipients for whom you can document a lawful basis to email:

  • Express consent — the recipient explicitly opted in (signup form, double opt-in).
  • Implied consent through an existing business relationship — e.g. current customers, within the limits of the laws that apply to you (notably CASL's time-limited implied consent categories for Canadian recipients).
  • Anything else must be declared as "other" at import time and will be held for manual review before the list can be mailed.

Every list import requires a consent attestation: you must state where the list came from and its consent basis before the platform will process the file. Attestations are recorded (with the attesting user and IP) and retained as compliance evidence. False attestations are grounds for immediate termination.

2. Prohibited lists

You must not upload or send to:

  • Purchased, rented, or traded lists — no exceptions, including "opt-in" lists sold by third parties.
  • Scraped or harvested addresses (from websites, directories, social networks, WHOIS, or anywhere else).
  • Appended or "enriched" lists (email addresses matched to other data you hold by a third-party service).
  • Lists obtained from a co-registration or sweepstakes path the recipient would not recognize.
  • Addresses whose consent is stale — if you cannot show recent consent or an active business relationship, do not import it.
  • Role accounts and distribution lists (info@, sales@, support@) except where you have a direct relationship with that mailbox. The importer flags these for review.

The platform's importer independently refuses to resurrect addresses that previously unsubscribed, bounced, or complained — re-importing them does not re-enable sending, and suppressed addresses import as unsubscribed. Do not attempt to work around this.

3. Prohibited content and behavior

You must not send: illegal content; phishing or credential-harvesting; malware or links to it; deceptive subject lines, headers, or sender identities; sexually explicit material without appropriate labeling and consent; or mail on behalf of a business other than the one that was vetted, unless approved.

The following restricted verticals may not be promoted through the platform (shared-IP reputation risk — these categories draw disproportionate complaints and blocklistings):

  • pharmaceutical products, online pharmacies, or nutraceutical/supplement offers;
  • payday loans, cash advances, debt collection, debt relief, or credit repair;
  • gambling, betting, or sweepstakes/prize promotions;
  • cryptocurrency, NFT, or day-trading/forex promotions and trading signals;
  • get-rich-quick, work-from-home, or multi-level/network-marketing offers;
  • affiliate marketing where the affiliate offer is the primary content of the mail;
  • lead generation, list brokerage, or mailing on behalf of third parties;
  • escort services or adult-entertainment promotion.

You must not: forge or obscure message origin; tamper with or suppress the unsubscribe mechanisms the platform inserts; use the tracking domain for anything other than platform-generated links; or attempt to bypass sending limits, warm-up schedules, or any guardrail.

4. Technical compliance (enforced by the platform)

These are not requests — the platform enforces them and you must not defeat them:

  • Identification & postal address. Your verified physical mailing address is required before any send, and every campaign must contain it (CAN-SPAM/CASL). The pre-send check blocks campaigns without it.
  • Working unsubscribe. Every message carries RFC 8058 one-click unsubscribe headers (mailto + HTTPS) and a link to a hosted unsubscribe/preference page. Opt-outs apply immediately and are checked both when a campaign's audience is built and again immediately before each message is submitted.
  • Verified sending domains only. You may only send from domains you have proven you control (DNS ownership token, DKIM, SPF, DMARC, bounce-handling records all verified). Sending stops automatically if your DNS verification lapses.
  • Account vetting. New accounts complete a vetting questionnaire (company, website, list provenance, opt-in method, expected volume) and must be approved before sending.

5. Enforcement thresholds

The platform monitors bounce and complaint rates continuously. The following automated actions fire at the thresholds currently enforced in code:

SignalThresholdAutomated action
Campaign hard-bounce rate> 3% (after ≥ 200 delivered)Campaign auto-paused
Campaign complaint rate> 0.15% (after ≥ 200 delivered)Campaign auto-paused
New-list probe (first 500 engagement-ranked recipients, evaluated after a 2-hour soak)hard bounce > 1.5%, complaints > 0.05%, or deferrals > 20%Probe fails; rest of the campaign never sends
Account, 7-day windowbounce rate > 5% or complaint rate > 0.3% (after ≥ 200 delivered)Account automatically suspended — all sending stops
Soft bounces to one address3 within 30 daysAddress suppressed for your account
Hard bounceanyAddress suppressed platform-wide
Complaints from one address3+ across the platformAddress suppressed platform-wide
Platform-wide block rate> 1%/hour, or a blocklist (DNSBL) listing of the shared IPGlobal sending halt for all customers until cleared

Automated suspensions are reviewed by a human; reinstatement requires you to demonstrate the cause (usually list quality) has been fixed. Repeated trips, evidence of prohibited lists, or a false consent attestation result in termination.

New accounts additionally start under warm-up limits (daily caps that grow with demonstrated good performance, starting at 200/day) and, during a trial, a 500-message total cap. These limits protect deliverability for everyone and are not negotiable through support tickets.

6. Reporting abuse

To report spam or abuse originating from our platform, email [email protected] with the full message headers. Every message we send carries a deterministic message identifier that lets us trace it to the exact sender and campaign, and we act on verified reports, including suspension and law-enforcement cooperation where warranted.