Legal
Acceptable Use Policy
The rules for mail sent through Chebu, so your mail and everyone else's keeps reaching the inbox.
Last updated
Why this policy exists
Mail providers decide whether to trust mail from Chebu based on how all of it behaves. One sender's spam can hurt delivery for everyone. This policy applies to all mail sent through Chebu: from the web app, from mail apps, through the API, and through the SMTP relay. It is part of our Terms of Service.
Sending rules
- Do not send unsolicited bulk email or unsolicited marketing.
- Do not use purchased, rented, shared, scraped, or harvested address lists.
- Everyone who receives automated mail from your apps must have asked for it, or must expect it because of an account or purchase they have with you.
- Only send from addresses and domains you control. Sending domains must be verified in Chebu and signed with DKIM. Mail from a mailbox must come from an address assigned to you.
- Make it easy to opt out of any mail that is not essential, and honour unsubscribe requests and complaints promptly.
- Never add a suppressed address back, or switch workspaces or domains, to get around a suppression.
- Keep headers, sender names, and subject lines accurate. Do not hide who you are.
What you must not send or do
- Phishing, or anything that tries to collect passwords or payment details under false pretences.
- Malware, or links to it.
- Fraud, scams, or deceptive offers.
- Mail that impersonates another person, company, or organization.
- Illegal content, child sexual abuse material, threats, or harassment.
- Content that infringes other people's rights, including copyright and trademarks.
- Attempts to get around limits, for example by opening extra accounts or workspaces.
- Attempts to probe, overload, or break into Chebu or anyone else's systems.
Limits and allowances
- Each message can have at most 50 recipients across To, Cc, and Bcc.
- Each Business plan includes a monthly allowance of transactional emails, with a hard cap above it. See the pricing page.
- We limit how fast a workspace can send and how often an API key can make requests. When we ask you to slow down, wait and retry.
Bounces and complaints
We suppress an address for a workspace, so it gets no more mail from that workspace, when:
- a message to it bounces permanently
- its owner marks a message as spam
- messages to it bounce temporarily three times in seven days
- you add it to your suppression list yourself
We also watch each workspace's rates over the last seven days, once it has sent to at least 200 recipients in that time. If 10% or more of recipients hard bounce, or 0.5% or more complain, we pause the workspace's sending automatically. It stays paused until we have reviewed it. Lower rates can trigger a review by our team.
Reporting abuse
If you received spam, phishing, or other abuse sent through Chebu, email abuse@chebu.io. Include the full message with its headers if you can. We review every report.
Enforcement
Depending on how serious a problem is, we may:
- suppress addresses
- slow down or limit sending
- pause a workspace's sending
- suspend an account or workspace
- close an account or workspace
We may act without notice when we need to protect recipients, other users, or the services. Where we can, we will tell you what happened and how to fix it. To ask for a review of a decision, email abuse@chebu.io.