Acceptable Use Policy
Last updated: August 1, 2026
1. Scope
This Acceptable Use Policy (the "Policy") applies to everyone who uses MailFlat, through the dashboard, the API, the SDKs or the MCP server. It forms part of our Terms of Service, and breaking it is a breach of that agreement.
MailFlat exists for legitimate uses: testing software, automating sign-up and one-time-passcode flows, running CI pipelines, and keeping personal correspondence separate from a main mailbox. The rules below mark the boundary of that purpose.
2. Prohibited Content & Conduct
You may not use MailFlat to:
- Phish or impersonate. Register accounts, send messages, or configure domains that pretend to be another person, company or brand, or that are designed to trick recipients into revealing credentials, payment details or personal information.
- Commit or facilitate fraud. Including payment fraud, fake reviews, refund abuse, ticket or promotion abuse, and evading bans or identity checks on other services.
- Distribute malicious code. Storing, receiving or forwarding malware, ransomware, exploit kits or similar payloads, except in a controlled security-research context that complies with section 7.
- Handle unlawful content. Any content that is illegal where you or your recipients are located. Child sexual abuse material is reported to the relevant authorities and results in immediate, permanent termination.
- Harass or threaten. Messages intended to harass, threaten, defame or incite violence against anyone.
- Infringe rights. Content that infringes copyright, trademark, trade secret or privacy rights.
- Collect data you are not entitled to. Using inboxes to gather personal data without a lawful basis, or to receive data exfiltrated from systems you do not own.
3. Outbound Sending
Outbound sending exists so you can reply and can test real delivery. It is not a bulk email platform.
- No unsolicited commercial or bulk email, newsletters, or marketing campaigns.
- No purchased, scraped or rented recipient lists.
- No forged or misleading sender information, headers or reply-to addresses.
- No routing of another system's outbound mail through MailFlat as a relay.
- Recipients must reasonably expect to hear from you. Persistent spam complaints or high bounce rates may lead us to disable outbound sending on your account or on a connected domain.
4. Custom Domains
- Connect only domains you own or are authorised to configure.
- Do not connect domains that contain another company's trademark, that are look-alike or typo-squatted versions of an existing brand, or that were registered to deceive recipients.
- Keep your DNS records accurate. Leaving stale MX records pointed at us after you stop using a domain can misdirect mail.
- We may remove a connected domain from your account, without notice, if it is used in breach of this Policy.
5. Infrastructure & Fair Use
- Do not attempt denial of service attacks, traffic floods, or anything else that degrades the Service for others.
- Do not probe, scan or test the vulnerability of our systems outside the terms of section 7, and do not attempt to access accounts, data or infrastructure that are not yours.
- Do not circumvent rate limits, quotas or plan limits, including by creating multiple accounts, rotating IP addresses to evade limits, or scripting sign-ups.
- Do not scrape the Service or resell access to it as your own product.
- Do not use the Service to mine cryptocurrency, to run unrelated workloads, or as general-purpose storage.
6. Automation & Agents
Automated clients, CI pipelines and AI agents are first-class users of MailFlat, and this Policy applies to them exactly as it does to a person clicking in the dashboard.
- You are responsible for what your automation does, including agents acting with a degree of autonomy.
- Keep API keys secret. Do not embed them in client-side code, public repositories or shared images. Rotate a key as soon as you suspect exposure.
- Clean up test inboxes you no longer need rather than accumulating them to work around limits.
- Back off when you receive rate-limit responses instead of retrying in a tight loop.
7. Security Research
We welcome good-faith security research and will not pursue action against researchers who follow these rules:
- Test only against your own account and your own data.
- Do not run automated scanners that degrade the Service, and do not attempt denial of service.
- Do not access, modify or retain another user's data. If you encounter it, stop and tell us.
- Report what you find to security@mailflat.net and give us reasonable time to fix it before publishing.
8. Reporting Abuse
If you received a message from a MailFlat address that breaks this Policy, or you believe an account is being used for abuse, write to abuse@mailflat.net. Include the full message headers where you can, since they let us identify the account. We review reports and act on them, though we cannot always share the outcome with the reporter.
9. Enforcement
Depending on the severity and the circumstances, we may warn you, throttle or disable a feature such as outbound sending, remove a connected domain, suspend the account, or terminate it. Serious cases, in particular phishing, fraud, malware and illegal content, result in immediate termination without prior notice.
Where we terminate an account for a breach, fees already paid are not refunded, and content is deleted under section 5 of the Terms of Service. We report unlawful activity to the relevant authorities where the law requires it, and we respond to valid legal requests.
If you believe enforcement action against your account was a mistake, write to support@mailflat.net and we will review it.