Acceptable Use Policy
Effective 1 August 2026
Every account on YourMail sends through infrastructure whose reputation is shared. One sender who abuses it can get mail from every other customer filtered or blocked. This policy is what that shared risk buys you: a clear line, applied consistently.
Draft — not yet in force
This document is awaiting legal review and does not yet name a contracting entity. It is published so you can see the terms we intend to offer; it is not a contract, and nothing on this page should be relied on until this notice is gone.
What YourMail is for
Transactional email — messages a person receives because of something they did. Password resets, sign-in links, receipts, order updates, alerts, one-time codes, notifications they asked for.
You can send other kinds of mail if the recipient genuinely consented to it, but you must mark it as bulk when you do, which attaches a one-click unsubscribe header. Sending marketing without that flag is a breach of this policy, not a technicality.
Consent
- Send only to people who gave you their address for the purpose you are using it. Consent to receive a receipt is not consent to receive a newsletter.
- Do not send to purchased, rented, scraped, appended or otherwise harvested lists. This is the single most common cause of an account being suspended here.
- Honour unsubscribes. We enforce this for you — an address that unsubscribes is suppressed automatically for bulk sends — but working around that suppression is a breach.
What you must not send
- Anything unlawful, or that infringes someone else's rights.
- Phishing, spoofing, or any message designed to make the recipient believe it came from someone it did not. Impersonating a bank, a government body, a delivery firm, or any brand you do not represent.
- Malware, ransomware, or links to it.
- Content that is harassing, threatening, or that sexualises children.
- Fraud in any form — advance-fee schemes, fake invoices, cryptocurrency giveaways, romance scams, counterfeit goods.
- Deceptive headers: forged sender addresses, misleading subject lines, or a From address chosen to mislead the recipient about who is writing.
How you must behave technically
- Send only from domains you have verified. Do not attempt to verify a domain you do not control.
- Keep your bounce and complaint rates low. Persistent hard bounces mean your list is stale; complaints mean your recipients did not want the mail. Both damage every other customer.
- Do not create multiple accounts to get around a limit, a suspension, or the free tier's allowance.
- Do not attempt to probe, overload or circumvent the API's rate limits, quotas or authentication.
- Do not resell raw access to the API as your own email-sending service without agreeing that with us first.
What happens if you break this policy
These are the actual mechanisms, in the order we reach for them.
- Automatic throttling. If your bounce or complaint rate crosses a threshold, sending is refused until it recovers. This is automated, applies to everyone equally, and reverses itself when your numbers improve. Your live rate is on the
/metricspage at all times. - A new-account ceiling. Every account's daily sending limit starts below its plan's and rises to it over the first week of sending. This is not a judgement about you — it applies to every new account equally, including ours — and the figures are published in full at Limits & account review. We lift it on request.
- An automatic slow-down. Separately from the rate above, an account in its first period of sending may have its daily ceiling cut further for 24 hours if something about its traffic looks like a campaign. It is a slow-down, not a stop, it lifts by itself, and the dashboard says it is in force. We do not publish the signals, for the reason no one publishes them: they would be designed around.
- An automatic pause. Where the signal is stronger — including a payment card previously used by an account we suspended for abuse — sending is paused rather than slowed. Unlike the slow-down above this does not lift by itself: a person reviews it. Your data and dashboard stay accessible throughout, and we would rather reverse a wrong pause quickly than let a real campaign run while a timer expires.
- Suspension. For a clear breach of this policy we pause sending on the account. Your data and your dashboard remain accessible. Where a person made the decision we will tell you what triggered it; where sending was stopped automatically you will see that it has been, and you can ask us why.
- Termination. For severe or repeated breaches — a phishing or fraud campaign, malware, impersonation, a purchased list, evading a previous suspension — we close the account. No fees are refunded: you lose the remainder of the period you have paid for and no credit is issued. See Terms of Service sections 3 and 6.
We act without warning only when the harm is immediate and ongoing: a live phishing run, or activity putting every other customer's delivery at risk. Otherwise you hear from us first.
If you think a suspension was wrong, reply to the message we sent or email support@yourmail.dev. We would rather reinstate a misjudged account than lose a legitimate one.
Reporting abuse
If you received mail sent through YourMail that breaches this policy, tell us at support@yourmail.dev. Include the full message headers if you can — they identify the sending account, and without them we often cannot act.
This policy forms part of the Terms of Service.