Acceptable Use and Anti-Spam Policy
Effective September 20, 2026 · Astra Innovations LLC, Sanford, Florida, USA
Version 2026-09-20. This Acceptable Use and Anti-Spam Policy (the “Policy”) governs all use of the InBuzzed platform operated by Astra Innovations LLC, including the transactional email API, the SMTP relay, broadcasts, funnels and automations, forms, tracking domains and hosted business mailboxes. It is incorporated into the Terms of Service, and a breach of it is a material breach of those Terms.
InBuzzed operates shared sending infrastructure. One sender abusing it damages deliverability for every other customer. We enforce this Policy strictly and at our discretion.
Contents
- 1. Permission standards
- 2. Prohibited content
- 3. Prohibited practices
- 4. Technical and message requirements
- 5. Deliverability thresholds and consequences
- 6. Review of new and free workspaces
- 7. Hosted mailboxes and inbound mail
- 8. Reporting abuse
- 9. Enforcement
1. Permission standards
1.1 Express consent. You may send marketing or commercial messages only to recipients who gave clear, affirmative, express permission to receive that kind of message from the sender named in the message. Permission must be specific to the sender and to the content; permission given to one brand does not transfer to an affiliate, a parent company, an acquired list or a partner.
1.2 Not consent. Pre-ticked boxes, consent bundled into unrelated terms, an entry in a directory, a business card collected without a stated mailing purpose, a website visit, a LinkedIn connection, and a past purchase without a marketing opt-in are not permission for marketing email where express consent is required.
1.3 Documentation. For every contact, you must be able to produce on request: the source of the address; the date, time and, where collected online, the IP address of the opt-in; the exact wording and page or form presented at the point of consent; and, for double opt-in, the confirmation record. We may require this evidence before enabling or resuming sending.
1.4 Age of consent. Permission older than twenty-four (24) months without any subsequent engagement (open, click, reply, purchase or login) is treated as stale. Before mailing stale contacts you must either run a documented re-permission campaign or remove them. Repeated mailing of stale lists is a breach of this Policy.
1.5 Re-permission. A re-permission campaign must be a single message, must state clearly when and how the address was obtained, must require an affirmative action to remain subscribed, and must not be repeated to non-responders.
1.6 Transactional messages.Transactional and relationship messages — receipts, password resets, delivery notices, account alerts — may be sent without marketing consent, but their primary purpose must genuinely be transactional. A receipt that is mostly promotional is a marketing message and must meet the standards above.
2. Prohibited content
You may not use InBuzzed to send, host, link to or promote:
- content that is illegal in the sender’s or recipient’s jurisdiction, or that facilitates illegal activity;
- pornographic or sexually explicit material, escort or adult dating services, other than to an age-verified, expressly opted-in audience where lawful and never in preview text, subject lines or images that display without action;
- gambling, betting, lotteries, sweepstakes or casino promotions where unlawful or unlicensed for the recipient’s jurisdiction;
- cryptocurrency, token, NFT, forex or binary-option promotions of a speculative, unregistered or fraudulent nature, including airdrops, pump schemes, guaranteed-return claims and wallet-seed solicitations;
- multi-level marketing, pyramid schemes, matrix programmes, chain letters, work-from-home and get-rich-quick offers, lead-generation for such programmes, and similar business-opportunity content;
- pharmaceuticals, controlled substances, nutraceuticals with medical claims, vaping or tobacco products offered without the licences and disclosures required by law;
- weapons, ammunition, explosives, or instructions for producing them;
- hate speech, content that incites or glorifies violence, or content that harasses, threatens, defames or degrades a person or group on any basis;
- malware, ransomware, spyware, exploit kits, credential-harvesting pages, or links to any of them;
- phishing and impersonation, including messages designed to appear to come from a bank, mailbox provider, government body, employer, or from InBuzzed itself;
- deceptive claims, fake invoices, fake shipping or security notices, false scarcity, fake testimonials, or false endorsements;
- content that infringes copyright, trademark, patent, trade-secret, privacy or publicity rights; and
- material relating to children that is exploitative in any respect, which we report to the authorities.
3. Prohibited practices
Regardless of content, you may not:
- upload or send to purchased, rented, leased, appended, co-registered, traded, scraped or harvested lists, or to addresses generated by a dictionary or permutation attack;
- harvest addresses from websites, directories, social networks, WHOIS records or third-party platforms;
- send affiliate-network mail, third-party lead-gen blasts, or mail on behalf of a client whose permission records you cannot produce;
- engage in snowshoeing — spreading similar sending across many domains, subdomains, workspaces, IPs or accounts to dilute reputation or evade filtering and thresholds;
- forge, falsify or obscure headers, envelope information, Message-ID, Received lines, originating IP, or routing data;
- send from, or authenticate as, a domain or subdomain you do not own or are not expressly authorised in writing to use, or configure a tracking domain you do not control;
- impersonate any person, business or brand, or use a friendly-from name or reply address designed to mislead;
- remove, hide, disable, delay or condition the unsubscribe mechanism, require a login or fee to unsubscribe, use unsubscribe links that do not work, or re-subscribe a contact who opted out;
- list-bomb — subscribe an address to a form or list without that person’s action, or operate forms without anti-automation protection;
- send en masse to role accounts such as info@, sales@, admin@, postmaster@, abuse@ or noreply@, or to addresses obtained from a public contact page;
- knowingly send to spam traps, recycled addresses, or addresses that previously hard-bounced or complained;
- use the Service to relay mail for third parties, to operate an open relay, or to resell sending capacity without our written agreement;
- circumvent quotas, rate limits, review holds, suppression lists, or an existing suspension, including by creating additional accounts;
- host, in templates or linked assets, content unrelated to the message, or use InBuzzed storage as a general file host or redirector;
- send messages whose links redirect through URL shorteners or cloaking services in a way that conceals the destination; or
- interfere with the Service or other customers, including by scanning, load-testing, or attacking the infrastructure without written authorisation.
4. Technical and message requirements
4.1 Unsubscribe. Every marketing message must include a clear, conspicuous, one-click or two-step unsubscribe link that works for at least thirty (30) days after sending, requires no login, payment or extra data, and is honoured promptly and in every case within ten (10) days. Bulk marketing messages must also include a functioning List-Unsubscribe header with the one-click POST variant where supported.
4.2 Physical address. Marketing messages must include a valid physical postal address for the sender: a street address, a registered post-office box, or a private mailbox registered with a commercial mail receiving agency.
4.3 Identity fields. The From, Sender, friendly-from and Reply-To fields must accurately identify the sender and be monitored where a reply is invited. Subject lines and preview text must not misrepresent the content of the message.
4.4 Authentication. Each sending domain must complete the authentication records we specify during delivery setup, including SPF and DKIM, with alignment sufficient for DMARC to pass. We recommend a DMARC policy of at least quarantine for every sending domain. We may refuse to send from a domain whose records are missing, broken or misaligned.
4.5 Tracking domains. Custom tracking domains must resolve to hosts you control and must be pointed at our endpoints as documented. You may not use a tracking domain that impersonates another brand.
4.6 Content hygiene. Messages must render a plain-text alternative where a text part is expected, must not consist solely of a single image, must not contain hidden text or invisible characters intended to defeat filtering, and must not embed scripts or active content.
4.7 List hygiene. You must remove hard bounces immediately, remove unsubscribes and complaints permanently, suppress addresses that repeatedly soft-bounce, and avoid importing lists containing obvious syntax errors, disposable domains or duplicate entries.
4.8 Volume ramping. New sending domains and new workspaces must ramp volume gradually. Sudden large increases may be throttled or held for review.
5. Deliverability thresholds and consequences
5.1 We monitor per-workspace, per-domain and per-campaign metrics. The following are thresholds, not targets:
- Hard bounce rate: must remain at or below 3% of messages sent.
- Spam-complaint rate: must remain at or below 0.1% (one complaint per thousand delivered messages).
- Unsubscribe rate: monitored; a sustained rate above 1% triggers review of your permission practices.
- Spam traps: any confirmed hit to a pristine trap, and any pattern of recycled-trap hits, triggers review.
- Authentication failures and blocklistings: monitored per domain and per IP.
5.2 Consequences. Where a threshold is exceeded or a risk signal appears, we may, in any order and with or without prior notice: throttle or queue your sending; pause an individual campaign or automation; place the workspace in review and require evidence of consent; require list cleaning, re-permission or removal of segments; disable a sending domain, API key or SMTP credential; move you to separate sending infrastructure; suspend the workspace; or terminate the account. We may also add addresses to a platform-wide suppression list.
5.3 Reinstatement. Where a suspension is remediable, we will tell you what we need. Repeat breaches, or a breach involving phishing, malware, fraud or list purchase, will normally result in permanent termination without a data-export window.
5.4 No refunds for enforcement. Fees are not refunded for periods during which sending was throttled, paused or suspended as a result of your breach of this Policy.
6. Review of new and free workspaces
6.1 New workspaces, workspaces on the Free plan, and workspaces whose sending profile changes materially may be held for manual review before sending is enabled or before a broadcast is released.
6.2 Review may include verifying your business identity and website, checking domain ownership and authentication records, inspecting sample content and destination lists, and asking how the list was built. Providing false or misleading information during review is grounds for immediate termination.
6.3 We aim to complete review promptly during business hours, but we do not commit to a review time and review outcomes are at our discretion.
7. Hosted mailboxes and inbound mail
7.1 Hosted business mailboxes are for legitimate business correspondence associated with your organisation. They may not be used for bulk sending, for anonymous or throwaway identities, for relaying third-party mail, or to store unlawful material.
7.2 A mailbox that is compromised, is sending spam, or is the subject of a credible abuse report may be suspended immediately, and credentials may be reset without notice.
7.3 You must not configure auto-responders, forwarding loops or filters that generate backscatter or amplify inbound mail.
8. Reporting abuse
8.1 To report spam, phishing or other abuse originating from InBuzzed, email abuse@inbuzzed.com or support@inbuzzed.com. Please include the full message headers, the message body or a screenshot, the receiving address, and the date and time received. Full headers greatly speed up investigation.
8.2 We investigate every credible report. We do not disclose the outcome of an investigation to the reporter, and we may share the report, including your contact details where you provide them, with the customer concerned unless you ask us not to.
8.3 If you received a message you did not ask for, the fastest remedy is usually the unsubscribe link in the message. If it does not work, that is itself a breach of this Policy and we want to know.
9. Enforcement
9.1 We may investigate suspected violations, inspect content, headers, links and destination lists as described in the Terms, and take any action we consider appropriate to protect the platform, our customers, recipients and third parties.
9.2 Enforcement is at our sole discretion. Our failure to act on a violation is not a waiver of our right to act on it or on any other violation later. This Policy sets minimum standards; compliance with it does not guarantee that a message will be accepted, delivered or inboxed, and does not relieve you of your obligation to comply with applicable law.
9.3 We may update this Policy in line with Section 27 of the Terms of Service. Changes required by law, by an upstream provider, or to address an immediate abuse risk may take effect on posting.
Questions about whether a programme is permitted should be sent to support@inbuzzed.com before you send. We would much rather answer a question than suspend an account.
Questions: support@inbuzzed.com · Terms · Privacy · Acceptable Use · DPA · Cookie Policy