Draft — pending legal review. This document has not yet been reviewed by counsel and may change before Irisend is generally available.
Acceptable Use & Anti-Spam Policy
Effective date: 2026-09-25
This Acceptable Use Policy ("AUP") is part of the Irisend Terms of Service. It exists to protect deliverability, IP/domain reputation, and legal compliance for every Irisend customer. Violating this AUP may result in message filtering, sending throttles, suspension, or termination, at our discretion, with or without notice depending on severity.
1. Scope
This AUP applies to all email and other messages sent through the Service ("Messages"), including transactional and marketing/bulk mail, and to all recipient lists, sending domains, and content used with the Service.
2. You Must Have Permission to Email Each Recipient
You may only send Messages to recipients who have given you a valid legal basis to be emailed. Acceptable bases include, depending on jurisdiction and message type:
- Express opt-in / consent — the recipient affirmatively agreed to receive the specific type of message (required for marketing email under GDPR/ePrivacy, CASL, the Dutch Telecommunicatiewet, and most jurisdictions outside the U.S./Canada soft opt-in exceptions).
- Existing customer relationship ("soft opt-in") — for your own similar products/services, to a customer who bought from you and was given a clear opt-out at collection and in every email (recognized under CASL, the Dutch Telecommunicatiewet Art. 11.7, and similar EU implementations).
- Transactional necessity — receipts, password resets, shipping notices, account/security alerts, and other messages the recipient reasonably expects as part of a service or transaction they initiated with you, generally exempt from prior-consent rules (CAN-SPAM, CASL, GDPR) but still subject to identification/opt-out rules below where they contain any promotional content.
You may never: purchase, rent, scrape, harvest, or otherwise acquire email addresses without the addressee's knowledge and agreement; email addresses obtained via a third-party list, co-registration, or partner "opt-in" you did not directly control; use email addresses you do not have a documented lawful basis to contact; or add addresses to a marketing list because someone signed up for a different purpose (e.g., a support ticket).
You are responsible for maintaining proof of consent/basis (timestamp, source, IP address where applicable) and producing it to us on request.
3. Mandatory Message Requirements
Every Message sent through the Service, and particularly every bulk/marketing Message, must:
- Accurately identify the sender — a real "From" name/address and, in the body, the legal name and contact details (physical address, per CAN-SPAM/CASL) of the entity on whose behalf the Message is sent.
- Have a truthful subject line and header information — no deceptive "From," "Reply-To," or routing information (CAN-SPAM, CASL, EU/AU spam law).
- Include a working unsubscribe/opt-out mechanism for any promotional or bulk Message, that:
- requires no login, payment, or information beyond an email address;
- is honored within legally required timeframes (see table below), and in all cases within 10 days, and as close to immediately as technically possible via automated suppression;
- stays functional for at least 30/60 days after send, per applicable law.
- Support one-click unsubscribe (RFC 8058) for bulk/marketing mail sent at volume: include
List-Unsubscribe(HTTPS URL) andList-Unsubscribe-Post: List-Unsubscribe=One-Clickheaders so Gmail, Yahoo, and other mailbox providers can process opt-outs natively. This is required by Irisend for any sender we classify as a "bulk sender" (broadly: ~5,000+ messages/day to consumer mailboxes, mirroring Google/Yahoo's 2024 bulk-sender rules) and strongly recommended for all marketing mail regardless of volume. - Mark advertisements as such where required (CAN-SPAM requires clear disclosure that the Message is an ad, unless the recipient gave prior affirmative consent for the specific content).
| Regime | Consent standard | Unsubscribe honor window | Unsubscribe must stay live |
|---|---|---|---|
| GDPR / ePrivacy (EU/EEA) | Opt-in (consent or narrow legitimate-interest cases) | Without undue delay, generally ≤ 1 month | Ongoing |
| Dutch Telecommunicatiewet Art. 11.7 | Opt-in, or soft opt-in for existing customers | Immediately, ongoing right to object | Ongoing |
| UK GDPR / PECR | Opt-in (soft opt-in for existing customers) | Without undue delay | Ongoing |
| CAN-SPAM (US) | Opt-out (no prior consent required, but must honor opt-out) | ≤ 10 business days | ≥ 30 days |
| CASL (Canada) | Express or narrow implied consent | ≤ 10 business days | ≥ 60 days |
| Australia Spam Act 2003 | Express or inferred consent | ≤ 5 business days | ≥ 30 days |
| CCPA/CPRA (California) | N/A (privacy, not anti-spam) — opt-out of sale/share | Per CCPA request timelines | Ongoing |
This table is a compliance aid, not a substitute for legal review of your specific sending programs and audiences.
4. Prohibited Content and Practices
You may not use the Service to send, host, or facilitate:
- Unsolicited bulk email ("spam") in violation of applicable law;
- Phishing, spoofing, or any Message impersonating another person or entity;
- Malware, viruses, or other malicious code, or links to them;
- Content that is fraudulent, deceptive, or violates consumer protection law (e.g., fake giveaways, pyramid/Ponzi schemes);
- Content promoting illegal goods or services in the recipient's jurisdiction (e.g., unlicensed pharmaceuticals, illegal gambling, counterfeit goods, illegal weapons);
- Adult content sent to non-consenting recipients, or any sexual content involving minors (zero tolerance — reported to authorities);
- Content that infringes intellectual property, defames, harasses, or violates the privacy of any person;
- Purchased, rented, harvested, or scraped recipient lists (see Section 2);
- High-risk sending patterns associated with spamming or account abuse, including sudden unexplained volume spikes, sending to invalid/non-existent addresses at scale, or sending to spam-trap addresses;
- Any activity that would cause our sending IPs or domains, or those of our infrastructure providers, to be blocklisted.
5. Deliverability Thresholds
To protect the shared sending reputation of the platform, we monitor per-account and per-domain:
- Hard bounce rate — sustained rates above 5% may trigger warnings; above 10% may trigger throttling or suspension.
- Spam complaint rate — sustained rates above 0.1% may trigger warnings, in line with Gmail/Yahoo bulk-sender thresholds; rates at or above 0.3% will trigger throttling or suspension.
- Unknown-user/invalid-recipient rate — high rates indicate un-validated or purchased lists and may trigger review.
We will attempt to notify you before taking action except where immediate action is necessary to protect the platform (e.g., suspected spam campaign in progress, phishing).
6. Domain Authentication
You are required to configure SPF, DKIM, and (recommended) DMARC for every sending domain before sending non-trivial volume, and to keep From domain alignment consistent with SPF/DKIM, consistent with mailbox-provider bulk-sender requirements (Google/Yahoo, effective 2024).
7. Reporting Abuse
To report suspected spam, phishing, or other abuse originating from the Service, email [to be completed: ABUSE_EMAIL] (or legal@irisend.dev) with full headers and, if available, the offending Message. We investigate all abuse reports and, where warranted, suspend the responsible account. We aim to acknowledge abuse reports within 24 hours and act on confirmed violations promptly.
8. DMCA / Copyright Complaints
To report content sent or hosted via the Service that infringes your copyright, send a notice to [to be completed: ABUSE_EMAIL] including: (a) identification of the copyrighted work; (b) identification of the infringing material and its location; (c) your contact information; (d) a statement of good-faith belief that the use is unauthorized; (e) a statement, under penalty of perjury, that the notice is accurate and you are authorized to act; and (f) your physical or electronic signature. We will respond in accordance with the DMCA (17 U.S.C. § 512) and equivalent notice-and-takedown regimes elsewhere, and may forward your notice to the account holder.
9. Enforcement
Depending on severity, we may: request corrective action with a deadline; throttle sending; require additional domain/list verification; suspend sending on affected domains only; or suspend or terminate the account. Severe violations (phishing, malware, CSAM, fraud) result in immediate suspension and, where required by law, a report to relevant authorities.
10. Changes
We may update this AUP from time to time; material changes will be notified per Section 13 of the Terms of Service.
11. Contact
Abuse reports: [to be completed: ABUSE_EMAIL]. General questions: legal@irisend.dev.
This document is a draft template and does not constitute legal advice. See research/legal.md for review recommendations before publishing.