Acceptable Use Policy
Effective 5 August 2026
What you may and may not send through Prospexly. Sending happens from your own mailbox, so the first cost of getting this wrong is your domain — but a tool with a spam reputation drags down everyone using it, which is why this policy is enforced rather than decorative.
1. Why this policy is strict
Prospexly sends from your mailbox, not ours, so the first cost of sending badly is yours — your domain, your reputation, your deliverability. But it is not only yours. Mailbox providers judge the tools people use as well as the domains they send from, and a product with a reputation for enabling spam becomes a product that lands in spam for everyone using it.
This policy forms part of the Terms of Service. Breaching it is grounds for suspension.
2. You need a reason to be in someone's inbox
Before you send, you must have a lawful basis to contact that person under the rules that apply where they are, not where you are. What that means varies:
- In much of the EU and the UK, business-to-business cold email can rest on legitimate interest, provided the message is genuinely relevant to the recipient’s professional role and opting out is easy.
- In the United States, CAN-SPAM permits cold email but requires honest headers, a valid physical postal address, and a working opt-out honoured promptly.
- In Canada, CASL requires consent or a defined existing business relationship. Assuming otherwise is how people get fined.
Deciding which applies is your responsibility as the sender. We do not check it for you and cannot.
3. Sending practices that are never permitted
- Purchased, scraped or rented lists. Uploading a list you bought is the single fastest way to lose a domain, and it is not permitted here.
- Forged or misleading headers. The From address must be a mailbox you control. Subject lines must describe the message honestly — no fake replies, no fabricated prior conversation, no invented shared connection.
- Impersonation. Of a person, a company, a brand or a government body.
- Ignoring an opt-out. Every message carries one-click unsubscribe headers and every send is checked against your suppression list. Removing someone from suppression so you can email them again, or moving them to a second mailbox to escape it, is a serious breach.
- Continuing to contact someone who has said no. A reply asking you to stop is an opt-out however it is phrased.
- Sending to addresses you know are invalid. Verification is unlimited on every plan, including Free. Repeatedly sending to a list you have not verified damages everyone.
- Evading limits. Multiple accounts to multiply an allowance, rotating mailboxes to dodge warmup ramps, or working around randomised pacing.
4. Content that is never permitted
Do not use Prospexly to send, store or promote:
- Malware, phishing, credential harvesting, or anything designed to defraud.
- Investment schemes promising guaranteed returns, cryptocurrency solicitations, and anything else with the shape of a pump.
- Content that is unlawful, defamatory, harassing, or that promotes violence or hatred against people on the basis of who they are.
- Sexually explicit material, and anything involving minors.
- Goods or services whose sale requires a licence you do not hold, including prescription medicines and controlled substances.
- Material you have no right to distribute.
5. Using the platform itself
Do not:
- Probe, scan or test the security of the service except under a disclosure we have agreed in advance — see the security page, which sets out how to report a vulnerability safely.
- Attempt to access another customer’s data, or any account that is not yours.
- Automate the interface to extract data at volume, or resell access to the AI discovery features as if they were your own product.
- Use the free plan or trials repeatedly through new accounts to avoid paying for the usage you are actually making.
- Share one login between several people rather than buying seats.
6. Open and click tracking
Tracking is optional and off unless you enable it. Where you do enable it, you are the one doing the tracking, and where the recipient’s local law requires disclosure or consent for it, meeting that requirement is yours to meet.
Do not use tracking data to infer anything about a person beyond their interest in your message, and do not present a tracked open as a reply, a meeting or consent.
7. How we enforce this
We monitor aggregate signals — bounce rates, complaint rates, suppression-list collisions — because those are what tell us a list is bad before a mailbox provider does. We do not read the content of your messages as a matter of course.
Where something looks wrong, our response is proportionate:
- A warning, with what we saw, for a first problem that looks like a mistake — a high bounce rate on one campaign, for instance.
- Rate limiting or a paused campaign where sending is actively causing damage.
- Immediate suspension without notice for phishing, malware, impersonation, purchased lists, or deliberate evasion of unsubscribes. These put other customers at risk, and a notice period is a window to do more of it.
Suspension does not delete your data. Your CRM stays exportable, because a sending problem is not a reason to hold your records hostage.
If you think we have got it wrong, reply to the notice or write to support@prospexly.com. We would rather reverse a wrong call than defend it.
8. Reporting abuse
If you received mail sent through Prospexly that breaches this policy, tell us at support@prospexly.com. Include the full message headers if you can — they identify the sending account, and without them we are often guessing.
To ask the sender to stop, use the unsubscribe link in the message; it is honoured automatically and immediately. Reporting it to us as well helps us find senders who are making a habit of it.
