Acceptable Use Policy
Effective: June 12, 2026
By using VayloMail hosted mail services or any associated infrastructure ("the Service") you ("the Customer") agree to this policy. If you do not agree, do not use the Service. We may update this policy; continued use after an update constitutes acceptance.
1. You are responsible for your own use
The Service provides unmanaged-content mail infrastructure. We do not monitor the content of your mail or pre-screen how you use the Service. You are solely responsible for ensuring your use complies with all laws and third-party terms that apply to you, in every jurisdiction you operate in or send to. You represent that you have the legal right to use any domain, mailbox, or data you process through the Service. We are an infrastructure provider, not a party to your business.
2. Prohibited use
You must not use the Service to send, host, facilitate, or assist any of the following. This list is not exhaustive — the spirit is "nothing illegal, and nothing that endangers the Service or other customers."
- Fraud and deception — phishing, spoofing a third party's identity to deceive, business email compromise, fake invoices, or any scheme to obtain money, credentials, or data by deception.
- Malware and intrusion — distributing malware or exploit code; unauthorised access to systems or accounts you do not own or have permission to access; credential-stuffing against third parties.
- Unsolicited bulk mail to recipients who have not opted in or with whom you have no prior relationship, in violation of applicable anti-spam law (e.g. UK PECR, EU ePrivacy, US CAN-SPAM).
- Illegal content — child sexual abuse material (zero tolerance, reported immediately), content inciting violence or terrorism, or any content whose possession or distribution is a criminal offence.
- Harassment and threats — targeted harassment, stalking, doxxing, or threats of violence against any person.
- Sanctions breaches — use by, for, or on behalf of any person or entity subject to UK, EU, or US sanctions, or in a sanctioned jurisdiction.
- Infrastructure abuse — open relays, deliberate IP-reputation poisoning, resource exhaustion, or attempts to access other customers' data or servers.
3. Domains and identity
You must only use domains you own or are authorised to administer. Spoofing, typosquatting, or configuring mail for a domain you do not control is prohibited and is grounds for immediate suspension.
4. Logging and lawful requests
For the security and integrity of the Service, we retain connection and transport metadata (authentication events, sending IPs, SMTP transaction logs, DKIM/SPF/DMARC results). We do not routinely read message content. We will respond to lawful requests from competent authorities and act on credible abuse reports. Where legally permitted and operationally reasonable we will notify an affected customer.
5. Abuse reports and takedown
Abuse reports may be sent to abuse@vaylomail.com. We aim to acknowledge credible reports within one business day and act — warn, suspend, or remove — in proportion to severity. Serious matters (CSAM, active fraud, threats to life) are actioned immediately.
6. Suspension and termination
We may suspend or terminate the Service, with or without notice, where we reasonably believe you have breached this policy, where the Service is being abused, where required by law, or where continued operation endangers the Service or other customers. No refund is owed for a suspension or termination caused by your breach.
7. No warranty for your use; indemnity
The Service is provided "as is." We are not liable for your use of it or any consequence of that use. You agree to indemnify and hold us harmless against any claim, loss, fine, or legal cost arising from your use of the Service or your breach of this policy, to the maximum extent permitted by law.
8. Contact
General: support@vaylomail.com
Abuse / legal: abuse@vaylomail.com