---
title: "Acceptable Use"
description: "What OpenEmail may and may not be used to send, how to report abuse, and what happens when someone breaks these rules."
url: "https://openemail.uk/acceptable-use"
---

Legal

# What this service is for, and what it is not.

OpenEmail carries ordinary correspondence between people. These rules exist so that the mail our users send keeps arriving. One account sending things nobody asked for makes every other account less deliverable. Last updated September 3, 2026.

## Reporting abuse

Write to [abuse@openemail.uk](mailto:abuse@openemail.uk). Include the full message with its headers if you have them. The headers are what let us identify which account sent it.

Reports are read by a person. You do not need an account to send one, and you do not need to have been the recipient.

## What this service is for

Mail written by a person to people they are corresponding with: replies, conversations, messages to addresses they already have. Accounts also send transactional mail from their own applications through our API: receipts, confirmations, password resets, notifications that a person asked to receive.

## What may not be sent

Unsolicited bulk mail, in any volume and by any name. This includes mail to addresses that were bought, rented, scraped, harvested, guessed, or collected for a different purpose than the one you are mailing them about.

Mail that misrepresents who sent it. Forged or misleading headers, a From address on a domain you do not control, or a reply path that hides the sender.

Phishing, credential harvesting, and messages that imitate another organisation. This applies to simulated phishing and security-awareness campaigns too. Send those through a service built for them.

Malware, and links to it. Content that is illegal where the sender or recipient is.

Mail to addresses that have already bounced permanently or complained. We suppress those for you; deliberately working around that suppression is a breach of these rules.

## Sending as a domain

You can only send from a domain after proving you administer it, by publishing a record we give you at a name only its administrator can write to. Publishing the signing records we then show you is what lets mail be signed as that domain.

Removing a domain from a workspace withdraws that permission. Domains belonging to this service cannot be claimed by an account.

## Bounces and complaints

Every permanent bounce and every complaint on a message you sent is recorded against your workspace, and that address is not written to again. This is automatic and you do not have to do anything for it to happen.

Sustained bounce or complaint rates are the clearest signal that mail is going to people who did not ask for it, and we act on them.

## What happens when these rules are broken

Depending on what we find: we contact the account, we withdraw a domain's ability to send, we suspend sending for the workspace, or we close the account. Serious cases such as a live phishing campaign or malware are acted on immediately and asked about afterwards.

We keep enough of a record to answer a complaint about what was sent and to tell a reporter what came of their report.
