Permitted purpose
The infrastructure may be used by authorized administrators for configuration, service validation, protocol study, security review, documentation, monitoring, backup, recovery testing, and other legitimate laboratory activity.
Core commitments
- Do not operate an open relay.
- Do not sell, rent, or share server access with unauthorized parties.
- Do not send spam, phishing messages, malware, or deceptive content.
- Do not harvest credentials, personal data, or recipient lists.
- Do not evade provider controls, blocklists, rate limits, or abuse investigations.
- Maintain working postmaster, abuse, and security contact channels.
- Investigate credible complaints and preserve relevant operational evidence.
- Apply changes only within the documented scope of the lab.
Recipient protection
Where controlled message tests are necessary, they should use authorized recipients, clearly identified test accounts, limited volume, and appropriate suppression or stop conditions. Testing must not create unwanted traffic for unrelated third parties.
Provider cooperation
The lab is expected to comply with the hosting provider’s policies and legitimate technical requests. Abuse reports, security notices, and infrastructure-verification requests should be reviewed promptly and answered with accurate information.