Acceptable use policy
Effective date: July 25, 2026
This policy governs everything sent through EmailPal. It is part of the terms of service, and violating it is a material breach of that agreement. It exists for a practical reason as much as a legal one: our customers share sending infrastructure, and a single abusive sender damages the deliverability of everyone else. So the rules below are enforced by software before they are enforced by people, and enforcement errs toward protecting the infrastructure.
The one-sentence version: send relevant business email, to businesspeople you have a genuine reason to contact, from lists you built yourself, identifying yourself honestly, and honour every opt-out. Everything below is detail on that sentence.
1. Cold email is permitted. Spam is not.
EmailPal is built for cold outreach: unsolicited, targeted, business-to-business email sent in compliance with applicable law. Cold email done properly is legal in most jurisdictions. What separates it from spam is targeting, honesty, volume discipline and opt-out handling — and each of those is a requirement here, not a suggestion.
2. Prohibited content and businesses
You may not use the Service to send, link to, or promote:
- anything unlawful in the sender’s or recipient’s jurisdiction, including fraud, money laundering, or the sale of illegal goods or services;
- phishing, credential harvesting, impersonation of any person or brand, or messages with forged or misleading headers, sender identities or reply paths;
- malware, spyware, or links whose destination is disguised from the recipient;
- get-rich-quick schemes, pyramid or multi-level marketing recruitment, unregistered securities offerings, or “guaranteed” investment returns of any kind, including cryptocurrency promotions of that character;
- payday or advance-fee loans, debt relief and credit repair services, or lead generation for any of these;
- counterfeit goods, or academic fraud services;
- sexually explicit content or escort services;
- unlicensed gambling, or unlicensed sale of pharmaceuticals, controlled substances or weapons; and
- content that harasses, threatens or incites violence against any person or group.
We also decline whole categories of business at verification, at our discretion, where the category’s typical sending behaviour is incompatible with shared infrastructure — regardless of any individual sender’s intentions. If we are not the right fit, we will tell you at onboarding rather than after you have built on us.
3. Recipient lists
List quality is the single biggest determinant of deliverability, so it is where this policy is most specific. Every list you send through the Service must be one you or your client collected deliberately, from identifiable sources, targeting people with a plausible business reason to hear from you. The following are prohibited:
- Purchased or rented lists.No list bought from a broker, however “verified” the broker claims it is.
- Scraped or harvested lists — addresses collected from websites, directories, social networks or leaked databases.
- Generated lists — addresses assembled by guessing patterns (first.last@company) rather than collected. Receiving providers classify this as directory harvesting and penalise it severely.
- Consumer lists presented as business lists. B2B outreach sent predominantly to personal addresses at free providers indicates a list that was not collected from businesses.
Every list is verified before its first send, automatically. The gate is published so you can plan around it rather than discover it:
- a list whose projected bounce rate is 8% or higher is blocked from sending;
- a list in which 40% or more of addresses are role accounts, disposable addresses or generated-looking addresses is blocked regardless of bounce projection;
- lists above 3% projected bounce rate are flagged and may be subject to reduced sending speed while early results come in; and
- addresses on the platform suppression list are removed from every list, always, and cannot be reinstated.
Passing verification is not a certification that your list is lawful — that responsibility stays with you — and repeatedly submitting lists that fail the gate is itself grounds for review of the account.
4. Message requirements
Every message sent through the Service must:
- identify the real sender — a real person or company, with a valid physical postal address where the law requires one (CAN-SPAM requires it for US recipients);
- use a truthful subject line and accurate header information;
- be answerable: the from and reply-to addresses must reach a monitored mailbox, not a void;
- carry a working opt-out. The platform adds RFC 8058 one-click unsubscribe headers to every relayed message; you must not strip, alter or interfere with them, and any additional unsubscribe mechanism you include must also work; and
- respect prior opt-outs: a recipient who has opted out stays opted out, everywhere.
5. Prohibited sending techniques
The following techniques are banned regardless of content or list quality:
- circumventing or attempting to circumvent platform controls — suppression, throttles, list verification, warming schedules or send ceilings — by any means, including distributing the same campaign across accounts to evade limits;
- hash-busting, content randomisation designed to evade spam filtering, or deliberately malformed messages;
- open redirects, cloaked links, or landing pages that differ from what the message describes;
- SMTP callout verification, RCPT-TO probing or any other directory-harvesting behaviour against third-party mail servers;
- relaying mail for third parties who are not party to your agreement with us; and
- using warming infrastructure to send anything other than warming traffic, or misrepresenting campaign mail as warming mail.
6. Performance thresholds
Sustained sending performance outside these bounds triggers automatic intervention, starting with throttling and escalating as evidence accumulates:
- Bounce rate: sustained hard-bounce rates above roughly 4% indicate an unverified or stale list and will slow, then stop, sending.
- Complaint rate: Gmail and Yahoo enforce a 0.3% spam-complaint threshold; we intervene below it, because by the time a provider acts the damage is done.
- Volume: per-mailbox daily send ceilings exist to keep sending patterns inside what providers treat as normal, and are not negotiable upward beyond plan limits.
These interventions are automatic, recorded, and visible to you with their reasons, as described in section 7 of the terms of service.
7. Enforcement
Enforcement is graduated where the evidence allows it and immediate where it does not:
- Automatic throttling and pausing for threshold breaches — routine, often temporary, and resolved by fixing the underlying list or content.
- List blocks at the verification gate, with a breakdown of what to fix.
- Account suspension, without prior notice, where we reasonably suspect fraud, phishing, purchased lists or other serious violations. Investigation follows suspension because reputation damage is immediate and cannot be repaired afterwards.
- Termination for serious or repeated violations, with forfeiture of prepaid fees for the current period as set out in the terms of service. We may also report unlawful activity to registrars, hosting providers, blocklist operators and law enforcement, and preserve related records for that purpose.
If you believe an enforcement action was wrong, write to support@emailpal.io. Every automatic action has a recorded reason, and a person will review it.
8. Reporting abuse
If you received unwanted or abusive mail sent through our infrastructure, forward it with full headers to abuse@emailpal.io. Reports are read by a person and acted on against the sending account. Recipients can also opt out permanently with the one-click unsubscribe link carried by every message; that opt-out is enforced platform-wide against all of our customers, not just the one who mailed you.
9. Changes
We update this policy as sending standards and provider requirements evolve — they do, and a policy that lags them would protect nobody. Material changes are announced by email with at least 14 days’ notice; changes required by a receiving provider or by law may take effect sooner. The effective date above always reflects the current version.