Acceptable Use Policy

What you may send through Avelto, what you may not, and the sending limits we enforce automatically. This policy forms part of the terms of service.

Last updated 24 September 2026

1. Why this policy exists

Every customer sends through sending infrastructure whose reputation is shared. One sender mailing people who did not ask for it lowers delivery for everyone else on the platform.

This policy applies to every account, on every plan, including test mode and the sandbox domain. It forms part of our terms of service.

2. What you must not send

  • Unsolicited bulk email. If the recipient did not ask to hear from you, do not send to them.
  • Mail to purchased, rented, harvested or scraped lists, however the list was described when you obtained it.
  • Phishing, credential harvesting, spoofing, or any message that impersonates another person, business or brand.
  • Malware, ransomware, links to malicious downloads, or attachments and links designed to compromise a recipient.
  • Adult or sexually explicit content.
  • Anything unlawful in the United Kingdom, including fraud, harassment, threats, content that incites violence, and unlawful discrimination.
  • Mail that hides who the sender is, uses a false return path, or uses a domain you do not control.
  • Mail advertising services intended to break this policy, such as list brokers or bulk-mail evasion tools.

You must also not attempt to bypass our controls. That includes spreading one sending programme over several accounts, evading a suspension, or probing the API for ways around plan limits and rate limits.

3. Consent and lawful basis

You are the controller of the recipient data you send to us. Before you send to a person, you must have a lawful basis under the UK GDPR for contacting them, and you must be able to show it if we ask.

  • Keep a record of how and when each recipient gave consent, or of the other lawful basis you rely on.
  • When marketing to individuals by email, comply with the Privacy and Electronic Communications Regulations, including the rules on consent and on the soft opt-in for existing customers.
  • Give a working unsubscribe route in marketing mail and honour it promptly.
  • Send from an address that accepts replies, and act on complaints sent to it.
  • Stop sending to a recipient who objects, including one who objects to us rather than to you.

Transactional mail that a recipient has asked for, such as a receipt or a password reset, is what this service is built for. It still has to be mail the recipient expects from you.

4. Sending thresholds we enforce

Two rates are measured per account, per day, and are enforced by the platform rather than by a person. Sending is paused automatically for that account when either is crossed, and the account is flagged for review.

  • A daily bounce rate over 5% pauses sending.
  • A daily complaint rate over 0.1% pauses sending.
  • A rate is only judged once at least 20 emails have reached a final state that day, so a small test run cannot trip the pause.

A paused account keeps its data and its dashboard. New sends are refused until the pause is lifted. We tell you which rate tripped, and we lift the pause once the cause is fixed.

New accounts are also capped for their first 7 days at 100 emails a day and 5 domains, whatever the plan. Addresses that hard bounce or complain are added to your suppression list automatically, and further sends to them are refused.

5. What we look at when we investigate

To investigate abuse we inspect message metadata: the sending address, the recipient domain, timestamps, tags, delivery status, and bounce and complaint rates. That is what our abuse tooling is built on.

We do not read the content of your messages. The exception is where we are legally required to produce or examine content, for example under a court order or a binding request from a public authority.

Message bodies are stored so that you can see what was sent, are visible to your own signed-in users, and are deleted when your plan's retention window ends. Our logs redact body fields, API keys and session cookies.

6. What happens if you break this policy

  • We may pause sending on the account immediately, with no prior notice, and tell you afterwards.
  • We may suspend the account, with the reason shown at the top of your dashboard and a way to write to us, until the matter is resolved.
  • We may require evidence of consent for a list before sending resumes.
  • We may remove a domain, revoke keys, or refuse to verify a domain.
  • We may terminate the account for a serious or repeated breach, and report unlawful activity to the relevant authority.

We aim to be proportionate. A first mistake by a customer who fixes it quickly is treated differently from a deliberate spam run.

7. Reporting abuse

If you received mail sent through our platform that breaks this policy, write to [email protected]. Include the full message headers where you can, because they let us identify the sending account.

We read every report. We do not share your report with the sender unless you ask us to. Security vulnerabilities go to [email protected] instead.

8. Changes to this policy

We may update this policy as new kinds of abuse appear. Material changes are announced by email to account holders. The date at the top of this page always shows when it last changed.