Skip to content
Abuse Handling

How abuse reports are investigated.

Full root access means real responsibility, and open Port 25 means we take mail abuse seriously rather than treating it as someone else's problem. Here is where to send a report, what to put in it, and what happens next.

Send reports to

[email protected]

  • The offending IP address
  • Date and time, with timezone
  • Raw headers, logs or the exact URL

The Process, End to End

Four steps. No stage of it involves ignoring a report and hoping it stops.

  1. 1

    Report received

    Send it to [email protected]. Include the IP address, timestamps with a timezone, and raw evidence — full mail headers, log excerpts or URLs. A report without an IP and a time cannot be matched to an account.

  2. 2

    Matched to an account

    The address is traced to the service it belongs to and the report is checked against that account's activity and against our Acceptable Use Policy.

  3. 3

    Action taken

    A confirmed violation results in a warning, suspension or termination depending on severity. Active attacks and ongoing spam campaigns are treated as urgent rather than queued.

  4. 4

    Reporter updated

    We confirm that the report was actioned. We do not disclose customer details to a reporter — that requires a valid legal request, not an email.

What Falls Outside the Policy

Privacy at the point of ordering is not the same as permission afterwards, and we would rather that were unambiguous.

Spam and unsolicited bulk email

Port 25 is open by default here, which makes this the category we take most seriously. Sending to purchased or scraped lists, operating an open relay, or forging headers are all outside the policy — regardless of what the sender calls it.

Network attacks

Participating in or launching DDoS traffic, port scanning, brute-force attempts against third parties, or any traffic designed to degrade someone else's service.

Phishing and fraud

Pages impersonating banks, payment providers or login screens, and infrastructure supporting credential theft. These are actioned fastest because the damage compounds by the hour.

Malware distribution

Hosting or distributing malicious executables, or operating command-and-control infrastructure.

Illegal content

Content that is illegal in the jurisdiction where the datacenter operates. Our servers sit in real countries under real law, and privacy on the ordering side does not change that.

Valid legal requests

Handled in line with applicable law and our Terms of Service. A request from a party claiming authority is checked before anything is acted on.

Ordinary lawful use is unaffected by any of this. The full wording is in the Acceptable Use Policy section of our Terms of Service, which is the binding version if this page and the Terms ever disagree.

For Reporters and Customers

Seeing something from our network?

Email [email protected] with the IP, the timestamp and the raw evidence. Active attacks and live phishing are treated as urgent.