Acceptable Use Policy
Last updated: 1 October 2026
Overview
1. About this policy
At EmailOctopus we are passionate about making email marketing easier. We are also dedicated to preventing abuse and making sure the platform is used responsibly. Everyone knows the frustration of receiving unwanted spam or scam emails, so we do all we can to make sure EmailOctopus does not enable that sort of activity. Keeping the platform free from unethical practices protects our reputation and our deliverability, which protects you.
This Acceptable Use Policy (AUP) tells you what you can and cannot use EmailOctopus for. It forms part of, and should be read with, our Terms of Use and our Privacy and Cookie Policy. Capitalised terms have the meaning given in the Terms of Use, and in this AUP we, us and our mean Three Hearts Digital Ltd (company number 09897211) trading as EmailOctopus, and you means anyone with an EmailOctopus account, whether paid or free.
Breach of this AUP is a material breach of the Terms of Use. Section 16 explains what we may do about it.
2. Our core rules
Do not use EmailOctopus to send or promote anything that is illegal, harmful, offensive or that constitutes harassment. We also do not allow content that is, in our reasonable opinion, false, inaccurate or misleading in a way that could cause confusion or harm around important events and topics, including health, elections and financial matters.
The content you send must be wanted by the people who receive it, and you must have permission to contact them.
Permission and the law
3. Permission and consent
You must only send Content to Contacts who have given you permission to receive it, or whom you are otherwise lawfully entitled to email. In particular:
- you must, if we ask, be able to tell us for any Contact how and when they gave you their address and what they agreed to receive;
- you must not use purchased, rented, scraped, harvested, appended or otherwise third-party sourced lists of email addresses;
- you must not add Contacts who have not asked to hear from you, including but not limited to addresses collected from directories, social media, business cards at events, or website scraping;
- you must not email addresses that have hard bounced, unsubscribed or marked your messages as spam;
- you must honour unsubscribe requests promptly and in any event within 2 days, and must not re-add, re-subscribe or otherwise resume sending to a Contact who has unsubscribed unless they ask you to; and
- where a set of Contacts has been dormant for a long period, you must re-confirm their permission before you begin sending to them through EmailOctopus.
We vet accounts before and during use. We look at the types of email you send, your industry, the age of your list and whether any spam traps appear in it. We may ask you to provide evidence of permission for any list, and may suspend sending until you do. We may ask you to confirm your industry at sign up.
4. Complying with the law that applies to you
You are responsible for complying with all laws that apply to you, to your business and to each Contact you email. Those laws differ from country to country, and they are not the same as ours. We cannot advise you on them, and the fact that we allow something on the platform is not a statement that it is lawful for you to send it.
Where a product or service is lawful in the sender’s country and in the recipient’s country, and the sender holds any licence or authorisation required there, we will not object simply because the same activity is restricted somewhere else. A Canadian customer emailing Canadian Contacts about a licensed cannabis dispensary is acceptable; the same campaign sent to Contacts in a country where it is unlawful is not.
Some categories are prohibited outright wherever you are, because they are unlawful in most places, cause serious harm, or attract abuse that damages the platform for everyone. Those are listed in section 5 and no local-law argument will change our position on them.
The laws you are most likely to need to think about include, but are not limited to: the direct marketing and data protection rules in the United Kingdom; the equivalent rules in the EU and EEA; the CAN-SPAM Act in the United States; Canada’s Anti-Spam Legislation (CASL); and the Spam Act 2003 in Australia. In broad terms these require you to have a lawful basis or consent for your emails, to identify yourself accurately, to give a valid postal or contact address, and to offer and honour an easy unsubscribe. Penalties for non-compliance are significant.
What you can send
5. Prohibited content, products and activities
You must not use EmailOctopus to send, promote, link to or host any of the following.
- Illegal goods, services or activity of any kind, or content that facilitates it.
- Controlled drugs and related substances — illegal or recreational drugs, novel psychoactive substances and “legal highs”, drug paraphernalia, unlicensed or “grey market” pharmaceuticals, prescription-only medicines offered without a prescription, unlicensed online pharmacies, and research chemicals or peptides offered for human therapeutic, weight-loss or performance use (including GLP-1 and similar peptide products) other than by a licensed pharmacy or authorised healthcare provider.
- Sexually explicit material — content that is obscene or unlawful in the sender’s or the recipient’s country.
- Child sexual abuse material, and any content that sexualises, grooms or endangers children.
- Terrorist content, violent extremism and incitement to violence, and content promoting self-harm or suicide.
- Hate speech and content that harasses, bullies, threatens or discriminates against a person or group.
- Weapons — the unlicensed sale or solicitation of firearms, ammunition, explosives or other weapons, the sale of any weapon to a recipient who cannot lawfully receive it, and instructions for manufacturing weapons or explosives. Lawful, licensed sales of firearms, ammunition and bladed articles are treated as a restricted industry under section 6.
- Fraud and deception — phishing, spoofing, malware, ransomware, spyware, cryptojacking, advance fee fraud, pyramid and Ponzi schemes, chain letters, “get rich quick”, “make money online” and work-from-home schemes, fake invoices and fake delivery or account notices.
- Counterfeit and infringing goods, pirated content, and material that infringes another person’s intellectual property or confidentiality.
- Deceptive synthetic media — deepfakes and other artificially generated or manipulated audio, image or video content presented as genuine, and impersonation of any person or organisation.
- Health misinformation and unlawful health claims — content making claims about the prevention, treatment or cure of disease that are unlicensed, unevidenced or unlawful in the recipient’s country.
- Selling or sharing personal data — email lists, phone numbers, list brokering, data appending services, and the sale of followers, likes or engagement.
- Circumventing platform controls — content or activity intended to evade filtering, moderation, billing limits or suspensions.
6. Restricted industries and content
The following categories are not prohibited, but they attract higher complaint rates or sector-specific regulation. Accounts sending this content are subject to additional scrutiny, may be asked to provide evidence of permission, licensing or authorisation before or during sending, may be subject to volume limits, and may be refused or suspended at our reasonable discretion. If you are in any of these categories, tell us when you sign up.
- Cannabis and CBD products, where lawful in both your and your Contacts’ jurisdictions and where you hold any licence required;
- Alcohol, tobacco, vaping and nicotine products;
- Nutritional, herbal and vitamin supplements, nutraceuticals and weight-loss products;
- Gambling, betting, lotteries and casino products and services, where you are licensed in each jurisdiction you send to;
- Financial products and services, including investment, insurance, mortgages, refinancing, consumer credit, high-cost short-term credit, debt advice, debt management and credit repair, where you hold any regulatory authorisation required;
- Cryptocurrency, digital assets, blockchain products and trading education — educational content is permitted, but promises or implications of wealth, guaranteed returns or specific investment outcomes are not;
- Multi-level marketing and direct sales — you may promote products, but you may not use EmailOctopus to recruit distributors or promote an income opportunity;
- Affiliate marketing and lead generation, where you send only to your own permission-based list and clearly identify yourself as the sender;
- Political campaigning and advocacy, where you comply with applicable electoral and data protection law;
- Online courses, coaching and “information products”;
- Travel, timeshare and holiday club offers;
- Licensed sales of firearms, ammunition and bladed articles, where lawful in both your and your Contacts’ jurisdictions and where you hold any licence required; and
- Dating, escort, sexual encounter and marriage brokering services, where lawful in both your and your Contacts’ jurisdictions.
We may update these lists at any time by publishing a revised AUP. These lists are not exhaustive, and we may refuse, suspend or close an account for any other reason we reasonably consider necessary to protect the platform, our other customers or our sending reputation, provided we do not do so for a reason that would be unlawful discrimination.
We allocate sending IP addresses and sending domains at our discretion, and we may move, throttle or warm up your sending in order to protect deliverability for you and for other customers.
Sending and content standards
7. Technical and deliverability requirements
Mailbox providers now enforce minimum standards on anyone sending in volume. If you do not meet them your email will be filtered or rejected, and your sending affects every other customer on our shared infrastructure. You must:
- authenticate your sending domain, where we ask you to — publish SPF and DKIM records, and a DMARC record with a policy of at least p=none, with the domain in your From header aligned to your SPF or DKIM domain;
- keep an unsubscribe link in every message — every marketing or subscribed message must carry a clearly visible unsubscribe link in the body of the message. We add the one-click unsubscribe headers that mailbox providers expect, and unsubscribes must be honoured;
- not disguise your identity — your From name, From address, subject line and headers must be accurate and must not mislead recipients about who is sending the message or what it is about;
- include a valid contact address — your messages must include a physical postal address or other valid contact address at which you can be reached. If you use our address privacy feature you must keep a current postal address in your Account so that we can forward correspondence to you; and
- keep your audience engaged — stop sending to Contacts who have not engaged for a long period. We remove Contacts who hard bounce, or repeatedly soft bounce, automatically. Adding a known hard-bounced or non-opted-in address is already a breach of this AUP.
Mailbox providers publish their own bulk sender requirements, which apply mainly where you send from your own validated domain, and they change them from time to time. It is your responsibility to keep up with those that apply to your sending.
8. Your sending statistics
We monitor the sending statistics of all accounts to understand the quality of your lists and content. As a guide, across a rolling period we expect:
Measure | Expected |
|---|---|
Spam complaint rate | Below 0.10%, and never at or above 0.30% |
Hard bounce rate | Below 5% |
Open rate | Above 3% |
Unsubscribe rate | Below 1% |
These are guidelines, not entitlements. We may limit, throttle, suspend or terminate an account whose statistics fall outside them, or whose sending is harming deliverability for other customers, even if no other part of this AUP has been breached.
9. AI-generated content
You may use artificial intelligence tools, including any AI features we make available, to help you create Content. If you do:
- the Content must comply with this AUP and all applicable law in exactly the same way as content you write yourself;
- you are responsible for reviewing the output and for its accuracy, and you must not send AI-generated claims you have not verified;
- you must not create or send content that impersonates a real person or organisation, or that presents artificially generated or manipulated audio, images or video as genuine; and
- you must make any disclosure that the law requires about the artificial generation or manipulation of content. If you are established in the EU, or the output of your campaigns is used there, Article 50 of the EU AI Act has applied to you as a deployer since 2 August 2026. It requires you to disclose deepfake images, audio or video as artificially generated or manipulated, and to disclose AI-generated text published to inform the public about matters of public interest.
We screen Content sent through the platform using automated tools, including an AI model, to detect phishing and other abuse. When we release a feature that generates content for you, we will label what it produces, where the law requires us to as provider of that feature, so that it can be detected as artificially generated — that is our responsibility, not yours. Our Privacy and Cookie Policy explains how we handle personal data in the process.
Using EmailOctopus
10. Using the platform itself
As an EmailOctopus user, you must not:
- use, or try to use, someone else’s account without their permission;
- create a false identity on EmailOctopus, or identify or misrepresent yourself in an incorrect or misleading manner;
- create a user profile for anyone other than yourself, either as a business or as an individual, or use an image of anyone other than yourself in your profile;
- claim to be associated with, or endorsed by, EmailOctopus unless you have a written agreement with us (this does not stop you displaying the EmailOctopus branding we require on Free Services content);
- perform any action intended to avoid free plan or billing thresholds, including deleting and re-adding Contacts, or unsubscribing and re-subscribing Contacts, to work around your plan’s Contact limit;
- “white label” or otherwise present yourself as the original provider of the EmailOctopus platform or any EmailOctopus material or process;
- tamper with, disable or override any security component or process of EmailOctopus, or attempt to do so;
- “mirror”, “scrape”, “crawl” or “spider” any page or service on the platform, or make excessive or abusive use of our API; or
- include in your campaigns any virus, Trojan horse, worm, time bomb, keystroke logger, spyware, adware or other harmful code.
11. Multiple accounts
If your account is suspended for activity in breach of this AUP, creating new accounts to avoid the suspension is strictly forbidden, and we may suspend or terminate any account we reasonably believe is connected to you.
12. EmailOctopus Connect
EmailOctopus Connect links to your own account with Amazon SES or another email service provider. That provider is your processor, not our sub-processor, and your account with them is governed by your agreement with them. If you use Connect you must also comply with that provider’s own acceptable use and sending requirements, in addition to this AUP. Please make yourself familiar with them.
13. Landing pages, forms and hosted content
Where you use EmailOctopus to publish landing pages, signup forms or other hosted content, everything in this AUP applies to that content as well as to your emails. Your signup forms must make clear who is collecting the data, what the person is signing up to receive, and where your privacy notice can be found.
14. Reporting abuse and illegal content
If you think anyone is breaching this AUP, or that content sent or hosted through EmailOctopus is illegal, please tell us at abuse@emailoctopus.com. If you received spam you think came from an EmailOctopus user, we want to hear about it. If you think material infringes your copyright or other rights, you may notify us at the same address.
To help us act quickly, please tell us why you think the content is illegal or in breach of this AUP, give us the exact location of the content (for example the full URL, or a copy of the email including its headers), and give us your name and email address. We will acknowledge your report without undue delay, handle it in a timely, diligent, non-arbitrary and objective way, and tell you the outcome, whether we used automated means in handling the notice or reaching the decision, and how you can challenge it. This is our notice and action mechanism for the purposes of Article 16 of the EU Digital Services Act, and it applies in place of the equivalent provision in our Terms of Use.
15. Your obligations to your Contacts
You must have, and comply with, a privacy notice and cookie notice which you actively bring to the attention of your Contacts at or before the time you collect their details. It must say that you use EmailOctopus, that we and our sub-processors will process personal data on your behalf, and, where the laws that apply to your Contacts require it, that emails you send may track opens and clicks (a setting you control). You are responsible for obtaining any consent your Contacts’ local law requires, including for tracking.
You must not use EmailOctopus to send or collect special category personal data (such as data about health, religion, politics, sex life or sexual orientation) or data about criminal convictions or offences.
Enforcement and contact
16. How we deal with breaches of this policy
We reserve the right to limit any account on EmailOctopus where we reasonably consider it necessary. Failure to comply with this AUP is a material breach of the EmailOctopus Terms of Use, on which you are permitted to use the service. In the event of a breach, we may do any or all of the following:
- issue you a warning, or ask you for evidence of permission, licensing or authorisation;
- throttle or limit your sending, or suspend your account or a campaign, temporarily or permanently;
- withdraw your right to use the service, temporarily or permanently;
- remove your content and Contacts from the platform, temporarily or permanently;
- where you are a business customer, start legal proceedings against you for the reimbursement of any costs on an indemnity basis (including reasonable administrative and legal costs) resulting from the breach;
- take further legal action against you; and
- disclose relevant information to law enforcement authorities, mailbox providers, internet service providers or anti-spam organisations where we reasonably consider it necessary or where the law requires it.
We will aim to act proportionately and, where it is practical and appropriate to do so, to tell you what the problem is and give you an opportunity to fix it before we suspend or terminate your account. Where a breach is serious, is incapable of being remedied, or where the law requires immediate action, we may act without notice. Where we restrict your account or a campaign because we consider it illegal or in breach of this AUP, we will give you a statement of our reasons, the facts we relied on, whether automated means were used, and how you can challenge the decision, and we will do so at the latest when the restriction takes effect. We may withhold detail where giving it would help others evade our abuse controls or would disclose confidential information. This paragraph describes how we intend to act and does not limit our rights under the Terms of Use.
If we reinstate your account after a suspension caused by your breach, we may charge a reinstatement fee in accordance with clause 15.3 of the Terms of Use.
Any liability we may have for action taken under this section is subject to clause 13 of the Terms of Use. The actions we may take are not limited to those described above, and we may take any other action we reasonably consider appropriate.
17. Changes to this policy
We may update this AUP from time to time to reflect changes in the law, in mailbox provider requirements, or in the abuse we see on the platform. We will publish the updated version on our website and, where the change is significant, we will tell you by email. The date at the top of this policy tells you when it was last updated.
18. Contact us
Three Hearts Digital Ltd (trading as EmailOctopus), 86-90 Paul Street, Shoreditch, London EC2A 4NE, United Kingdom. This policy is published at https://emailoctopus.com/legal/acceptable-use-policy.
General enquiries: contact@emailoctopus.com. Abuse and illegal content reports: abuse@emailoctopus.com. Privacy and data protection: privacy@emailoctopus.com. These addresses are also our single point of contact for recipients of the service for the purposes of Article 12 of the EU Digital Services Act, and they are monitored by our team and not only by automated tools. We deal with correspondence in English.
Thank you for helping us keep EmailOctopus a safe, clean and efficient system for everyone.