Rules designed to protect customers, recipients, and the MailMama service.
Acceptable Use Policy
Effective Date: September 5, 2026
Company: MailMama Software LLC
Company Address: 75 E 3rd St, Sheridan, WY 82801, United States
Website: https://mailmama.net/
Email: info@mailmama.net
This Acceptable Use Policy sets out the rules that govern the use of MailMama services. It forms part of the Terms of Service and applies to every account, every authorized user, and every message sent, received, or stored through the Service.
1. Purpose and Scope
MailMama Software LLC (“MailMama”, “we”, “us”, or “our”) operates hosted business email and email productivity services. Email infrastructure can be misused in ways that harm recipients, damage the reputation of the platform, degrade deliverability for every customer, and expose MailMama and its customers to legal liability. This Acceptable Use Policy (the “Policy”) exists to define what is and is not permitted, and to set out how we respond when the rules are broken.
This Policy applies to all use of the Service, including webmail, mobile and desktop applications, JMAP, IMAP, POP3, and SMTP access, the application programming interface, the unified inbox, AI-assisted features, email tracking, scheduled sending, and all content stored in or transmitted through the Service.
Capitalized terms not defined in this Policy have the meaning given in the Terms of Service. In the event of a conflict between this Policy and the Terms of Service, the Terms of Service control, except that this Policy controls in relation to the specific conduct it addresses.
2. Who Is Responsible
The account owner is responsible for all activity that occurs under the account, whether carried out by the account owner, by an authorized user, by a person who has obtained credentials, or by an automated system configured by any of them. Lack of knowledge of a violation is not a defense.
If you permit others to use the Service under your account, you must ensure that they are aware of this Policy and comply with it. If you use the Service on behalf of an organization, you must ensure that the organization’s internal rules do not conflict with this Policy.
You remain responsible for compliance with all laws applicable to you, to your authorized users, and to your recipients, including the laws of the jurisdictions in which your recipients are located. Compliance with this Policy does not establish compliance with any law, and MailMama does not advise on the lawfulness of your activity.
3. General Standard of Use
The Service is provided for lawful business and professional communication. Use must be consistent with the ordinary operation of a business mailbox: correspondence with people who expect to hear from you, with a clearly identified sender, on a domain you control, at volumes consistent with normal business communication.
The Service is not a bulk email platform, a marketing automation platform, a cold outreach tool, a transactional email relay, a mailing list service, or an anonymity service. Conduct that fits those descriptions is prohibited under this Policy even where it is lawful.
4. Prohibited Content
You must not use the Service to create, send, store, host, link to, or distribute content that:
is unlawful under any law applicable to you, to MailMama, or to the recipient;
sexually exploits or abuses a minor, or depicts a minor in a sexualized manner, in any form;
promotes, incites, or facilitates terrorism, violent extremism, human trafficking, violence against any person or group, or the commission of a serious crime;
harasses, threatens, stalks, defames, or is intended to intimidate or degrade a person or group, including on the basis of race, ethnicity, national origin, religion, sex, gender identity, sexual orientation, disability, or any other protected characteristic;
infringes or misappropriates copyright, trademark, patent, trade secret, publicity, privacy, or any other right of a third party;
contains malware, ransomware, spyware, keyloggers, rootkits, exploit code, malicious scripts, or any code designed to disrupt, damage, gain unauthorized access to, or exfiltrate data from a system;
constitutes phishing, credential harvesting, business email compromise, invoice fraud, impersonation of a person or organization, or any other attempt to deceive a recipient into disclosing information or transferring value;
promotes fraudulent, deceptive, or misleading schemes, including advance-fee fraud, fake invoices, pyramid and multi-level schemes, unregistered or fraudulent investment offerings, fraudulent cryptocurrency promotions, counterfeit goods, illegal pharmaceuticals, forged documents, stolen data, or stolen credentials;
discloses personal information about a third party without a lawful basis, or is used to dox, expose, or endanger a person;
violates export control, sanctions, or trade restriction law.
Where we become aware of apparent child sexual abuse material, we are required by United States law to report it to the National Center for Missing and Exploited Children, to preserve the associated material and records, and to take action on the account. We will do so without prior notice to the account holder.
5. Anti-Spam Requirements
5.1 Prohibition on Unsolicited Email
You must not use the Service to send unsolicited bulk email or unsolicited commercial email, in any volume. A message is unsolicited where the recipient has not given consent to receive it and no applicable legal exemption for existing business relationships applies.
This prohibition applies regardless of the content of the message, regardless of whether the message is commercial, and regardless of whether it complies with the CAN-SPAM Act or any other statute. Compliance with a statutory minimum standard does not make sending permitted under this Policy.
5.2 Consent and Recipient Lists
You must not send messages to addresses that were purchased, rented, leased, exchanged, harvested, scraped from websites or directories, generated by automated guessing, derived from a data breach, or otherwise obtained without the individual’s knowledge. You must be able to demonstrate, on request, how each recipient came to be on your list and when and how consent was obtained.
Where you send to recipients in the European Union, the United Kingdom, Canada, or another jurisdiction with a consent-based regime, you are responsible for meeting the consent, identification, record-keeping, and withdrawal requirements of that regime.
5.3 Cold Outreach and Prospecting
Systematic cold outreach, prospecting campaigns, recruitment campaigns, and sequenced or automated follow-up messaging to recipients with whom you have no prior relationship are not permitted on the Service, whether sent manually, through SMTP, or through the API, and whether sent in one batch or distributed over time to avoid detection.
5.4 Unsubscribe and Complaint Handling
Where you send any message of a commercial or promotional nature, you must include an accurate sender identity, a valid physical postal address where required by law, and a functioning method of opting out. You must honor opt-out requests promptly and in any event within the period required by applicable law, and you must not transfer an address that has opted out to another list or another sender.
You must monitor and act on bounces, complaints, and unsubscribe requests. Continued sending to addresses that hard bounce, that generate complaints, or that have opted out is a violation of this Policy.
5.5 Sender Identity and Authentication
You must send only from domains you own or are authorized to use, and must configure and maintain DKIM, SPF, and DMARC records as required for those domains. You must not falsify, forge, or obscure header information, sender addresses, return paths, message identifiers, originating IP information, or routing data, and must not use a display name, domain, or address intended to cause a recipient to believe the message originates from a person or organization other than you.
5.6 Reputation and Filtering Evasion
You must not take steps designed to evade spam filters, blocklists, rate limits, authentication requirements, complaint feedback loops, or the anti-abuse controls of MailMama or of any receiving network. Prohibited techniques include, without limitation, distributing a campaign across multiple accounts, domains, or mailboxes to stay below limits; rotating domains or sending identities to escape reputation systems; obfuscating text, links, or images to defeat content analysis; using link shorteners or redirect chains to disguise a destination; warming up domains or mailboxes through artificial traffic; and creating multiple accounts after a suspension.
6. Sending Limits and Fair Use
We apply limits to protect the stability, security, and deliverability of the platform. These limits may include limits on outbound messages per hour and per day, limits on recipients per message, limits on message and attachment size, limits on connection and authentication rates, limits on API request rates, limits on concurrent sessions, and limits on the rate at which mailboxes, aliases, and domains may be created. The limits applicable to your plan are published in our Documentation.
We may apply additional or individualized limits to an account where usage patterns indicate elevated risk, where an account is new or unverified, where complaints or bounces exceed acceptable thresholds, or where usage affects other customers. We may also adjust limits generally where necessary for security, capacity, or deliverability, or where required by a receiving network or an upstream provider.
Where a plan describes mailboxes, aliases, or domains as unlimited, that means no fixed numerical cap and no per-user or per-seat fee. It does not mean unrestricted use. All use remains subject to the storage allocation, the limits described above, and this Policy. Creating mailboxes, aliases, or domains for the purpose of expanding sending capacity, distributing a campaign, or evading limits is prohibited.
Use that materially exceeds the typical usage of comparable customers on the same plan, or that adversely affects the operation of the Service or the deliverability of other customers, may result in throttling, feature restriction, a requirement to upgrade, suspension, or termination.
7. SMTP, API, and Automated Sending
SMTP and API access are provided so that customers can use standard email clients and integrate ordinary mailbox functions into their own systems. They are not provided as a message relay for third parties or as a sending channel for campaigns.
You must not use SMTP or API access to operate a mail relay or open relay for parties other than yourself; to send on behalf of third parties or resell sending capacity; to send bulk, campaign, list-based, or sequenced email; to send high volumes of automated transactional email such as platform notifications, receipts, alerts, or one-time passcodes at scale without our prior written agreement; to distribute sending across accounts or identities; or to automate account creation, credential testing, or any activity prohibited by this Policy.
You must protect SMTP credentials, application passwords, and API keys, must not embed them in client-side code or public repositories, and must rotate them promptly if exposure is suspected.
8. Domains and Account Integrity
You must own or be lawfully authorized to use every domain you connect to the Service, and must be authorized to make the DNS changes required to operate email on it. You must not connect a domain that infringes a trademark, that is registered or used to impersonate another organization, that is a typosquat or lookalike of another domain, or over which your control is disputed.
You must provide accurate registration, contact, and billing information and keep it current. You must not create an account using false identity information, a false business identity, or the identity of another person. You must not create a new account, or use an existing account, to circumvent a suspension or termination.
You must not resell, sublicense, or provide the Service to third parties as a standalone hosted email service without a prior written agreement with MailMama.
9. Network, System, and Security Conduct
You must not:
attempt to gain unauthorized access to any part of the Service, to any account other than your own, or to any system or network connected to the Service;
probe, scan, or test the vulnerability of the Service or conduct penetration testing, load testing, or vulnerability scanning without our prior written consent;
circumvent, disable, or interfere with authentication, rate limiting, filtering, monitoring, logging, or other security or abuse-prevention measures;
interfere with or disrupt the Service, its infrastructure, or the use of the Service by others, including through denial-of-service activity, resource exhaustion, mail bombing, or subscription bombing;
use the Service as a command and control channel, an exfiltration channel, or a distribution point for malicious infrastructure;
conduct automated credential stuffing, brute-force authentication attempts, or address enumeration against the Service or any other system;
reverse engineer, decompile, or disassemble any part of the Service except to the extent that applicable law prohibits that restriction;
use automated means to extract data from the Service beyond the data of your own account, or to replicate the functionality of the Service.
If you discover a security vulnerability in the Service, report it to info@mailmama.net with the subject line “Security Report” and do not disclose or exploit it. We will acknowledge reports and will not pursue action against good-faith researchers who report promptly, avoid accessing data belonging to others, and do not degrade the Service.
10. Email Tracking
Where you enable email tracking, you are the party responsible for that processing in relation to your recipients. You must ensure that your use of tracking complies with all laws applicable to you and to your recipients, including data protection and electronic communications laws that may require transparency, a lawful basis, or the prior consent of the recipient. In the European Union and the United Kingdom, tracking technologies in email are regulated and will in most cases require recipient consent.
You must not use tracking to monitor individuals covertly for purposes unrelated to your business correspondence, to surveil a person without a lawful basis, to determine the location of a person for harassment or stalking purposes, or in combination with prohibited outreach. We may restrict or disable tracking for particular accounts, jurisdictions, or use cases for legal, regulatory, deliverability, or abuse-prevention reasons.
11. AI-Assisted Features
You must not use AI-assisted summaries, reply drafting, or any other AI-assisted feature to generate or refine content that violates this Policy, including deceptive, fraudulent, impersonating, harassing, or unlawful content, or content intended to evade filtering or reputation systems.
You must not submit to AI-assisted features any content that you are not permitted to disclose to a third-party processor, and you are responsible for informing your authorized users that these features process message content. Output is generated automatically, may be inaccurate, and must be reviewed before it is relied on or sent.
12. Restricted and Regulated Information
The Service is a general-purpose business email product. It is not designed, marketed, certified, or audited for information subject to sector-specific regulatory regimes. You must not use the Service to transmit or store protected health information subject to United States health privacy law, cardholder data subject to the Payment Card Industry Data Security Standard, classified or export-controlled government information, or information subject to regulated retention, supervision, or archiving obligations, unless you have entered into a separate written agreement with MailMama that expressly permits it.
13. Sanctions, Export Control, and Geographic Restrictions
You must not use the Service in violation of United States export control or economic sanctions law, or the equivalent law of any other applicable jurisdiction. You must not use the Service if you are located in, ordinarily resident in, or organized under the laws of a country or territory subject to comprehensive United States sanctions, or if you are identified on an applicable restricted party or sanctions list or are owned or controlled by such a person.
Availability of the Service in a given country is additionally subject to our infrastructure, local legal requirements, abuse and fraud risk, and the policies of third-party services on which we depend. We may decline, restrict, or withdraw service in any jurisdiction.
14. Intellectual Property and Copyright Complaints
You must hold all rights necessary for the content you transmit and store through the Service. MailMama responds to properly submitted notices of claimed copyright infringement in accordance with the Digital Millennium Copyright Act and applicable law. Notices should be sent to info@mailmama.net with the subject line “Copyright Notice” and must contain the elements required by law, including identification of the work, identification of the material, your contact details, a statement of good-faith belief, a statement of accuracy made under penalty of perjury, and your signature.
We may remove or disable access to material in response to a valid notice and may terminate the accounts of repeat infringers. Submitting a notice that contains a material misrepresentation may expose the sender to liability.
15. Monitoring and Detection
We do not routinely review the content of customer messages and we do not read customer mail for commercial purposes. We do operate automated systems that analyze messages and traffic for spam, malware, phishing, fraud, abnormal volume, authentication failures, and other abuse signals, and we maintain logs of connections, authentication events, and delivery outcomes. This processing is described in our Privacy Policy.
Where an automated signal, a complaint, a blocklist listing, a report from a receiving network, or a legal request indicates a possible violation, we may investigate. Investigation may include reviewing metadata, sending patterns, account records, and, where strictly necessary and permitted by law, message content. Access to content in the course of an investigation is limited to authorized personnel, is logged, and is restricted to what is necessary.
We have no obligation to monitor content, and the absence of action in relation to particular conduct does not constitute approval of it or a waiver of our rights.
16. Complaints and Abuse Reports
Reports of abuse originating from the Service should be sent to info@mailmama.net with the subject line “Abuse Report”. A report should include the full message headers where available, the date and time, the addresses involved, and a description of the issue. We review reports and take action where a violation is established.
We may forward the substance of an abuse report to the account holder concerned, redacting the reporter’s identity where appropriate, so that the account holder may respond. We may decline to act on reports that are vexatious, that concern content protected by law, or that are outside the scope of this Policy, and we may decline to disclose the outcome of an investigation to a reporter.
Where an account is the subject of a blocklist listing, a feedback-loop complaint, or a complaint from a receiving network, we may act immediately to protect platform deliverability for all customers.
17. Enforcement
17.1 Actions We May Take
Where we determine that a violation has occurred or is likely to occur, we may take one or more of the following actions, in any order, proportionate to the severity and persistence of the conduct:
issue a warning and request corrective action within a stated period;
require additional verification of identity, business status, domain control, or consent records;
apply rate limits, reduce sending capacity, or restrict specific features including SMTP, API, tracking, or AI-assisted features;
quarantine, block, or refuse to deliver specific messages;
disable a specific mailbox, alias, or domain;
suspend the account in whole or in part, with or without prior notice depending on the urgency;
terminate the account and the subscription;
report the matter to law enforcement, to a regulator, to a receiving network, to a blocklist operator, or to an affected third party, where appropriate or required.
17.2 Immediate Action
We may act immediately and without prior notice where the conduct involves child sexual abuse material, active phishing or malware distribution, a security incident, a compromised account, fraud, a legal or regulatory requirement, a serious threat to platform deliverability, or a risk of harm to any person.
17.3 Consequences
Suspension or termination for a violation of this Policy does not entitle you to a refund of fees paid, and any refund eligibility under the Refund and Cancellation Policy is forfeited. You remain liable for amounts due. We may decline to provide the Service to you or to any related person or entity in the future.
Where termination results from abuse, unlawful use, or fraud, the thirty-day data export period described in the Terms of Service may be shortened or withheld, and data may be preserved rather than deleted where preservation is required by law or by legal process.
17.4 Recovery of Costs
You are responsible for the costs we reasonably incur as a result of your violation, including costs of investigation, remediation, delisting from blocklists, third-party claims, and legal fees, to the extent permitted by applicable law.
18. Appeals
If your account has been restricted, suspended, or terminated and you believe the decision was mistaken, you may appeal by writing to info@mailmama.net with the subject line “Enforcement Appeal”, identifying the account and explaining why the decision should be reconsidered. Appeals are reviewed by a person who was not solely responsible for the automated detection, and we will respond with a decision and, to the extent that doing so does not compromise security or abuse prevention, an explanation of the basis for it.
We may require corrective measures, evidence of consent, or additional verification as a condition of reinstatement. We are not obliged to reinstate an account where the violation was serious, repeated, or unlawful.
19. Cooperation with Authorities and Third Parties
We may preserve and disclose account records, metadata, and content where required by valid legal process or where we believe in good faith that disclosure is necessary to comply with law, to investigate suspected abuse or fraud, to protect the rights, property, or safety of MailMama, our customers, or the public, or to respond to an emergency involving a risk of death or serious physical injury. Our approach to notice and to legal process is described in the Privacy Policy.
20. Relationship to Law
This Policy states the rules of the Service. It does not state the law and does not constitute legal advice. Conduct may be prohibited under this Policy even where it is lawful, and conduct may be unlawful even where this Policy does not expressly address it. You are responsible for identifying and complying with the laws that apply to you, including the CAN-SPAM Act in the United States, Canada’s Anti-Spam Legislation, the ePrivacy rules and the General Data Protection Regulation in the European Union, the Privacy and Electronic Communications Regulations and the UK General Data Protection Regulation in the United Kingdom, and the equivalent laws of any other jurisdiction in which your recipients are located.
21. Changes to This Policy
We may update this Policy to address new forms of abuse, changes to the Service, changes to the requirements of receiving networks and upstream providers, or changes in law. The current version is always published at https://mailmama.net/ with the Effective Date shown at the top. Where a change is material, we will notify customers by email or by a prominent notice within the Service before it takes effect, except where an immediate change is necessary for security, legal, or abuse-prevention reasons. Continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.
22. Contact Information
Abuse reports, security reports, copyright notices, enforcement appeals, and questions about this Policy should be directed to the contact details below, using the subject line indicated in the relevant section.
Company: MailMama Software LLC
Company Address: 75 E 3rd St, Sheridan, WY 82801, United States
Website: https://mailmama.net/
Email: info@mailmama.net