You must not
- Add or claim a domain without authority.
- Direct report traffic for unrelated domains at an assigned address.
- Generate artificial mail or reports intended to flood or stress the service.
- Upload or send malware, exploit payloads or intentionally malformed archives.
- Probe, bypass or interfere with access controls and rate limits.
- Use results to facilitate spam, phishing, impersonation or unlawful surveillance.
Responsible testing
Security research requires prior written agreement on scope. Contact us with a concise description before sending payloads or testing production infrastructure.
Enforcement
Assigned addresses, domains or accounts may be limited or disabled when activity threatens the service or other users. DNS authorisation may also be withdrawn so compliant reporters stop sending to the destination.
Further readingContact the security team