This Acceptable Use Policy ("AUP") describes what you may and may not send through toSend. It forms part of our Terms of Service, and breaking it is a breach of those Terms.
It applies to every message sent through toSend, however you send it — our API, our SMTP service, or any plugin, integration, or tool that connects to us on your behalf.
Deliverability is shared. Mailbox providers judge senders partly on the company they keep, so one customer mailing a bought list makes the inbox harder to reach for everyone else sending through us. That is the reason for most of the rules below, and the reason we enforce them quickly.
toSend is for transactional email and for marketing email that recipients asked to receive. It is not a cold outreach platform. If your use case depends on contacting people who have not asked to hear from you, toSend is not the right service for you.
1. The core rule: permission
Send only to people who have explicitly asked to receive that mail from you.
"Explicitly" means the recipient took a deliberate action — they filled in a signup form, ticked a box themselves, made a purchase, created an account, or otherwise asked you for the mail you are now sending. The following are not permission:
- A pre-ticked or default-on consent box.
- Consent buried in terms the recipient did not read or agree to separately.
- An existing business relationship, on its own, as a basis for marketing.
- Someone else adding an address on the recipient's behalf.
- An address you believe would be interested.
You must be able to show, for any recipient, when and how they opted in — the date, the source, and what they were told they would receive. We may ask you for this, and we expect an answer. We recommend confirmed (double) opt-in for all marketing lists, because it is the only record that survives a dispute.
2. Send the type of mail they asked for
Permission is specific, not general. A recipient who signed up for one kind of message has not signed up for every kind of message. Sending the wrong type is treated the same as sending without permission at all.
- Someone who placed an order agreed to receive information about that order. They did not agree to a promotional series.
- Someone who downloaded a guide, entered a quiz, or requested a quote asked for that one thing. They did not ask for an ongoing newsletter.
- Someone who created an account agreed to service and security notices. They did not agree to product marketing.
If you want to send marketing to these people, ask them separately, and keep the record of them saying yes.
3. Prohibited: cold outreach
You may not use toSend to contact people who have not asked to hear from you. This applies no matter how the address was obtained, how relevant you believe the message is, or how personalised it looks. In particular, you may not send to:
- Purchased, rented, shared, swapped, or otherwise acquired lists.
- Addresses scraped or harvested from websites, directories, social networks, domain registration records, conference or attendee lists, or data brokers.
-
Addresses guessed or generated from a pattern — for example
info@,sales@, orfirstname@company.com. - Lists that came with a company, product, domain, or mailing tool you acquired, unless each recipient opted in to hear from you.
- Prospecting sequences, "I found your website" outreach, and link-building or guest-post pitches.
Running a cold outreach or sales-sequencing tool through toSend is a violation of this policy even if the tool itself is legitimate.
4. Frequency
Contacting someone far more often than they would reasonably expect makes your mail unsolicited, even where the first message was requested.
- Match your frequency to what the recipient was told they would receive when they signed up.
- As a working limit: do not send the same person more than 5 marketing messages in any 24 hours. Above that we may pause your sending. More than 3 in a day is already unusual, and worth a second look at the sequence that produced it.
- This limit covers marketing and promotional mail. Genuine transactional messages — order and delivery updates, password resets, security alerts, receipts — do not count towards it.
- Automated sequences count. A drip that sends several messages to one person within a day, triggered by a single signup or a single purchase, is a violation — including where each individual message is well written and carries an unsubscribe link.
- Stop sending to recipients who have not opened or clicked in a long time. Unengaged addresses decay into spam traps, and mailing them damages you and everyone else who sends through us.
5. Unsubscribing
-
Every marketing message must contain a visible, working
unsubscribe link in the body of the message. A
List-Unsubscribeheader alone is not sufficient. - Unsubscribing must take one click. Do not require a login, a password, a reason, a survey, or the recipient to retype their address.
- Honour unsubscribes immediately, and in no case later than 72 hours. Do not send a confirmation message to someone who has just unsubscribed or reported your mail as spam.
- Never re-add someone who unsubscribed, complained, or hard bounced, including as part of a later list import or re-engagement campaign.
6. Identify yourself honestly
- Use an accurate From name and From address on a domain you own and have verified with us. Do not use a free mailbox provider's domain as your sending identity.
- Use a Reply-To address that reaches a real person. Avoid no-reply addresses.
- Subject lines must reflect what is in the message. Do not write bulk mail to look like personal one-to-one correspondence in order to get it opened, and do not imply a prior relationship, conversation, or reply that did not happen.
- Every marketing message must include your legal or trading name and a valid physical postal address.
- Say why the recipient is hearing from you. Every bulk message must state, in the message itself, how the recipient came to be on your list — for example "you are receiving this because you signed up for our newsletter at example.com". A recipient who cannot remember agreeing to your mail will report it as spam.
- Do not send on behalf of, or promote, an unrelated third-party business from your domain.
7. Keep marketing and transactional mail apart
Sending reputation is tracked per domain. When marketing and transactional mail share one domain, a single poorly received campaign can stop your password resets and receipts from being delivered.
We strongly recommend separate subdomains — for example
news.yourdomain.com for marketing and
mail.yourdomain.com for receipts, password resets, and
account notices. Both can be verified on your toSend account.
8. List hygiene
- We automatically suppress addresses that hard bounce or generate a complaint. You must also remove them at your end, and must not attempt to send to them again.
- Validate addresses when you collect them. Check that they are well formed and that the domain can actually receive mail.
- Do not mail a list you have not contacted in a long time without a careful, small-volume re-permission process. Old lists produce bounces and spam-trap hits at a rate that will get your account paused.
-
Do not send marketing to role addresses such as
abuse@,postmaster@, ornoc@. These are rarely genuine signups and are often monitored by anti-spam organisations.
9. Prohibited content and activity
Regardless of permission, you may not use toSend to send:
- Anything unlawful, fraudulent, deceptive, or misleading.
- Phishing, credential harvesting, or any message that imitates another company, brand, or person. This includes simulated phishing and security-awareness testing.
- Malware, viruses, or links to malicious software.
- Content that threatens, incites, promotes, or encourages violence, terrorism, harassment, or other serious harm.
- Content that sexually exploits or abuses children.
- Sexually explicit or adult content.
- Pirated material, counterfeit goods, illegal substances, or unlicensed regulated products.
- Chain letters, pyramid or multi-level marketing schemes, get-rich-quick offers, or unsubstantiated financial, investment, cryptocurrency, or medical claims.
- Gambling and betting services, escort or adult dating services, pharmaceutical products, credit repair and debt relief offers, short-term or payday lending, and the sale of social media followers, likes, or engagement.
- List brokerage, list rental, or the sale of contact data in any form.
- Any message designed to evade spam filters — hidden text, misleading headers, deliberately obscured links, or forged routing information.
We also reserve the right to decline or stop any sending connected to a business or activity that we consider, at our sole discretion, to be deceptive, exploitative, or otherwise a serious risk to our reputation, to our other customers' deliverability, or to recipients — whether or not it appears in the list above.
You must also comply with the acceptable use policies of the infrastructure providers listed on our Subprocessors page, and with the anti-spam and data protection laws that apply to you and to your recipients — including CAN-SPAM, CASL, GDPR, UK GDPR, and their equivalents.
10. Accounts
- You may not create or use multiple accounts, teams, or sending domains in order to work around a limit, a quota, a free allowance, or a suspension. Where we find accounts operated by the same person or business for that purpose, we may close all of them.
- You may not resell or provide access to your toSend account to a third party whose sending you do not control and cannot answer for. If you send on behalf of clients, use a team per client, so that one client's list problem does not reach the others.
- Account and billing details must be accurate. Sending from an account registered with false details is grounds for immediate termination.
11. Sending limits
These are our limits. They are measured per team, over your recent sending, and they apply whatever your plan. We set them below the level at which mailbox providers start filtering, so that meeting them keeps you comfortably inside what the wider email ecosystem will tolerate.
- Hard bounces. Your rate must stay below 4%. Aim for under 2% — that is where a well-maintained list sits.
- Spam complaints. Your rate must stay below 0.08%. Aim for under 0.05%.
- Spam traps. Even a small number of hits will trigger a review. Trap addresses are never disclosed, by us or by anyone else, so the only defence is a clean, permission-based, actively engaged list.
If you go above either limit we may pause your sending without warning. We would rather stop one campaign than let it damage your domain, and everyone else's.
New accounts, and accounts that have not sent for a while, may be subject to lower limits, a slower ramp, and a review of the first significant campaign before it goes out.
12. How we enforce this policy
We monitor bounce rates, complaint rates, sending patterns, and recipient feedback across the platform, and we sample message content. Each team's sending reputation is isolated from every other team's, but abuse still puts the whole service at risk, so we act quickly.
Depending on what we find, we may:
- Contact you and ask how a list was collected.
- Rate-limit your account, or hold a campaign pending review.
- Pause sending for one domain, or for the whole team.
- Suspend or terminate the account and withhold unused credits.
For serious violations — cold outreach, purchased or scraped lists, phishing, or anything in section 9 — we suspend immediately and without prior warning.
If you believe we have acted in error, write to support@tosend.com. Tell us what happened, how the affected list was collected, and what you have changed. We reinstate accounts where the underlying problem has genuinely been fixed.
13. Reporting abuse
If you received mail sent through toSend that you did not ask for, report it to abuse@tosend.com. Please include the full message headers if you can — they let us identify the sender precisely. We investigate every report, and we do not pass your details to the sender.
14. Changes to this policy
We may update this policy as sending standards change. We will post the revised version here and update the effective date. Where a change materially restricts what you may send, we will give you reasonable notice before it takes effect.
15. Contact
Questions about this policy:
FluentCart Inc.131 Continental Dr, Suite 305
Newark, DE 19713, USA
support@tosend.com