Acceptable Use Policy
Last updated: August 2026
Important Notice
LexLab provides software tools, templates, sending infrastructure, hosting, and domains for legitimate business purposes only. We have a zero-tolerance policy for any illegal, fraudulent, or malicious use of our products and services. Violations will result in suspension or termination, and may be reported to law enforcement authorities.
1. Scope
This Acceptable Use Policy ("AUP") sets out what you may and may not do with LexLab products and services. It applies to every service we sell, including:
- LexLabMTA and LexLab Relay SMTP — managed SMTP relay and outbound sending infrastructure
- VPS and RDP hosting — resold from Contabo
- Domain registration — resold from Namecheap
- Mailbox and email hosting
- Tools, website templates, and other digital products sold through the marketplace
It applies to you as the account holder and to anyone acting through your account — staff, contractors, agencies, resellers, and your own end users. If someone sends, hosts, or publishes through your account, you are responsible for what they do. If you resell LexLab services, you are responsible for your downstream customers and for holding them to terms at least as strict as these.
This policy sits alongside our Terms of Service. Where a service is resold from an upstream provider, that provider's terms apply in addition to this one — see Section 7.
2. Intended Use of Products and Services
LexLab products and services are intended for:
- Legitimate businesses building web applications and platforms
- Web developers and agencies creating client projects
- Entrepreneurs launching legal online businesses
- Companies requiring hosting, domains, and digital infrastructure
- Transactional and permission-based email sent to recipients who asked for it
- Educational and learning purposes
- Portfolio demonstrations and personal projects
3. Strictly Prohibited Activities
You are strictly prohibited from using LexLab products or services for any of the following:
Financial Crimes & Fraud
- Phishing websites or pages designed to steal credentials or financial information
- Impersonating banks, financial institutions, or legitimate businesses
- Operating Ponzi schemes, pyramid schemes, or investment fraud
- Money laundering or facilitating illegal financial transactions
- Credit card fraud, identity theft, or unauthorized data collection
- Operating unlicensed financial services where licensing is required
- Fake cryptocurrency exchanges or trading platforms designed to defraud users
Deceptive Practices
- Creating fake or counterfeit websites to deceive users
- Misleading consumers about product authenticity or business legitimacy
- Operating scam websites of any kind
- Social engineering attacks or pretexting
- Fake online stores that do not deliver products
- Romance scams, lottery scams, or advance-fee fraud
Illegal Content & Activities
- Distribution of malware, viruses, ransomware, or spyware
- Hacking, unauthorized access, or cyberattacks
- Drug trafficking or sale of controlled substances
- Human trafficking or exploitation
- Terrorism financing or support
- Child exploitation material (CSAM) - reported to authorities immediately
- Sale of weapons, explosives, or dangerous materials
- Harassment, stalking, or threats
Spam & Abuse
- Mass unsolicited emails (spam) or SMS campaigns
- Harvesting personal data without consent
- Creating fake accounts or automated bot networks
- DDoS attacks or network disruption
- Scraping or data mining without authorization
4. Sending Infrastructure — Prohibited Use
This section covers LexLabMTA, LexLab Relay SMTP, and any mailbox or email hosting we provide. It applies to every message that leaves our infrastructure under your account, whatever generated it.
You may not use LexLab sending infrastructure for:
- Unsolicited bulk email. Any message sent at volume to recipients who did not ask to hear from you. It does not matter how the campaign is described internally — cold outreach, prospecting, re-engagement, or a "warm list" from a previous business. If the recipient did not opt in, it is spam.
- Purchased, rented, scraped, or appended recipient lists. This includes lists bought from data brokers, lists harvested from websites, LinkedIn, or public directories, lists obtained through email-appending services, and lists acquired with a company or domain you did not run at the time consent was given.
- Phishing and credential harvesting. Messages that direct recipients to fake login pages, payment forms, MFA prompts, or anything else designed to capture credentials, session tokens, or financial details.
- Brand impersonation. Sending as, or on behalf of, a company, institution, or individual you have no authorization to represent. This includes lookalike domains, homoglyph domains, and display names chosen to imply a relationship that does not exist.
- Spoofed or forged headers and sender identities. Forging
From,Return-Path,Reply-To,Message-ID, orReceivedheaders; falsifying originating IP or hostname information; injecting headers to disguise the true source of a message. - Malware and malicious links. Attaching or linking to malware, ransomware, droppers, credential stealers, exploit kits, or any URL that redirects to them — including through shorteners, open redirects, or compromised third-party sites.
- Evading unsubscribe requests. Continuing to mail a recipient who opted out; moving an opted-out address to a different list, sending domain, subaccount, or provider to keep mailing them; making unsubscribe deliberately hard to find, slow to take effect, or dependent on logging in.
Sending infrastructure is also covered by everything in Section 3. The list above is the part specific to email.
5. Sender Requirements
If you send through LexLab, these are not suggestions. They are conditions of keeping the service.
- Consent. Every recipient must have given you permission to email them, and you must be able to show where and when. Keep the record: signup timestamp, source IP or form URL, and what the recipient agreed to. We may ask for it during an abuse investigation.
- Working unsubscribe. Every commercial message needs a clear, one-click way out that works without a login. Honour opt-outs across all of your lists and sending domains, not just the one the recipient happened to receive. Process them within [PLACEHOLDER — maximum time to process an unsubscribe, e.g. 24 hours / 10 business days]. Include
List-UnsubscribeandList-Unsubscribe-Postheaders on bulk mail. - Accurate sender identity. The
Fromname and address must identify who is actually sending.Reply-Tomust reach a monitored mailbox that a human reads. Subject lines must describe the message honestly. No misleading pretexts. - Authentication alignment. Your sending domains need valid SPF, DKIM, and DMARC records, and they need to align with the domain in the visible
Fromheader. We will give you the records to publish at provisioning. If alignment breaks — a DNS change, an expired key, a third-party sender added to your SPF record — fix it. Sending on a domain that fails alignment gets throttled. - Physical address and identification. Include a valid postal address and a clear indication of who you are in commercial mail, as CAN-SPAM, CASL, GDPR, and equivalent laws in your recipients' jurisdictions require.
- List hygiene. Remove hard bounces immediately. Stop mailing addresses that have not engaged in [PLACEHOLDER — inactivity window before an address must be suppressed, e.g. 6 / 12 months]. Do not re-import addresses you previously removed.
6. Rate Limits and Sending Volume
Every client gets a sending cap set at provisioning, based on the plan purchased, the reputation of the assigned IPs, and the warm-up state of your domains. Your cap is stated in your service details. It is a technical limit and a contractual one.
- You may not circumvent your cap. That includes splitting a campaign across multiple accounts, subaccounts, API keys, IPs, or sending domains to stay under per-object limits while exceeding your total.
- You may not open additional accounts to obtain additional capacity, or have a third party open them on your behalf.
- New IPs and new domains go through a warm-up ramp. Ramp schedules are set per client at provisioning and may not be skipped.
- Increases are available. Request one through your dashboard or support with [PLACEHOLDER — required lead time for a cap increase request, e.g. 48 hours] notice. Increases are granted based on delivery history, not on how much you need to send.
- Traffic above your cap is queued or rejected at the relay. Repeated attempts to push past it are treated as a policy violation under Section 9, not as a capacity problem.
7. Hosting and Domains — Prohibited Use
This section covers VPS and RDP hosting resold from Contabo, and domains registered through Namecheap.
You may not use LexLab hosting or domains to:
- Host, stage, or distribute malware, ransomware, exploit kits, credential stealers, or command-and-control infrastructure
- Host phishing pages, phishing kits, fake login portals, or reverse-proxy credential capture
- Run open relays, open proxies, or open resolvers
- Launch port scans, brute-force attempts, DDoS traffic, or any unauthorized access attempt against systems you do not own
- Register or use domains that impersonate another organization, including typosquats and homoglyph variants of established brands
- Host content that violates the terms of the upstream provider carrying it
Upstream terms apply on top of this policy. Contabo's terms of service and acceptable use policy govern all VPS and RDP hosting. Namecheap's registration agreement and acceptable use policy, and ICANN's requirements, govern all domains. Read them — they bind you directly.
Contabo and Namecheap can suspend a service or a domain on their own initiative, without consulting us and without prior notice to you. When that happens we will pass on whatever information we receive, but we cannot reverse an upstream suspension and we cannot compel reinstatement.
8. Monitoring
We monitor sending infrastructure per client. This is operational — shared IPs mean one sender's behaviour lands on everyone else on that range.
What we track:
- Blacklist status of sending IPs and domains across the major public and commercial blocklists, plus reputation signals from the large mailbox providers
- Bounce rates, hard and soft, broken out per campaign and per sending domain
- Deferral rates and rejection reasons returned by receiving servers
- Send volume against your provisioned cap, including short spikes
- Complaint rates from feedback loops where the receiving provider offers one
- Abuse reports received at support@lexlabtools.com or forwarded to us by an upstream provider
What triggers a review:
- A sending IP or domain appearing on a major blocklist
- Hard bounce rate above [PLACEHOLDER — hard bounce threshold, e.g. 3% / 5%] over [PLACEHOLDER — measurement window]
- Complaint rate above [PLACEHOLDER — complaint threshold, e.g. 0.1% / 0.3%]
- Sustained deferrals or rejections from a major mailbox provider
- Volume exceeding your provisioned cap, or a sudden spike inconsistent with your normal pattern
- Any credible abuse report naming your account
Monitoring is based on delivery telemetry and headers rather than routine inspection of message bodies. When we are investigating a specific abuse report, a blocklisting, or an upstream complaint, we may examine full message content, including bodies and attachments, to establish what was sent.
9. Enforcement
Most problems are mistakes — a bad import, a misconfigured DNS record, a client who was less careful than you were. The response is graduated to match.
- Warning. We contact you with what we found and what needs to change. You have [PLACEHOLDER — remediation window after a warning, e.g. 24 / 72 hours] to fix it and tell us what you did.
- Throttle. If the problem continues, or the metrics are damaging shared infrastructure, we reduce your sending rate below your provisioned cap while you work through it. Throttles lift when the underlying numbers recover.
- Suspension. Sending, hosting, or both are stopped. Your data stays in place during suspension for [PLACEHOLDER — data retention window during suspension, e.g. 14 / 30 days]. Reinstatement requires a written explanation of the cause and the fix.
- Termination. The account is closed and access to all services is revoked.
Phishing and malware skip the ladder. Confirmed phishing, credential harvesting, or malware distribution results in immediate suspension without prior notice, followed by investigation. So does CSAM, which is reported to NCMEC and law enforcement the same day. There is no warning step for these.
We may also act immediately, without working through the stages, where a violation is causing active harm to recipients, to shared infrastructure, or to our standing with an upstream provider.
Other consequences of enforcement action:
- No refunds. Accounts terminated for policy violations are not eligible for refunds of any kind, including unused prepaid balance or the remainder of a billing period.
- Product revocation. Access to purchased products, licences, and services is revoked on termination.
- Data retention. We may retain account records, delivery logs, and evidence for legal purposes and law enforcement cooperation after termination.
If you think an enforcement decision is wrong, reply to the notice you received. We will look at it again. Appeals do not lift a suspension while they are pending.
10. Your Responsibilities
As a LexLab client, you are solely responsible for:
- Ensuring your use complies with all applicable local, national, and international laws
- Obtaining necessary licenses, permits, and regulatory approvals for your business
- Implementing proper legal disclaimers and terms on your deployed applications
- Verifying the legality of your business model in your jurisdiction
- Protecting end-user data in accordance with privacy regulations (GDPR, CCPA, and equivalents)
- Keeping your account credentials, API keys, and SMTP credentials secure — compromised credentials used to send spam are still your account's traffic
- All content created, sent, hosted, or distributed using our products
11. Law Enforcement Cooperation
LexLab takes violations of this policy seriously:
- We will cooperate fully with law enforcement agencies investigating illegal activities
- We may report suspected criminal activity to appropriate authorities
- We will comply with valid legal requests, subpoenas, and court orders
- We maintain logs and records that may be provided to investigators
- Child exploitation material is reported immediately to NCMEC and law enforcement
12. Disclaimer of Liability
LexLab provides software tools, sending infrastructure, hosting, and domains for legitimate purposes. We are not responsible for:
- How clients choose to deploy or use our products and services
- Illegal activities conducted by clients using our products and services
- Third-party actions or content created, sent, or hosted using our tools
- Compliance failures by clients in their respective jurisdictions
- Suspensions or terminations applied directly by an upstream provider
Clients bear full legal responsibility for their actions and any consequences arising from misuse of our products and services.
13. Reporting Abuse
If you have received spam, a phishing message, or malware from LexLab infrastructure, or you have found abusive content hosted on it, report it to support@lexlabtools.com.
Include as much of the following as you have — it decides how fast we can act:
- Full message source with complete headers, not a forwarded copy or a screenshot
- The date and time you received it, with timezone
- The sending IP address, envelope sender, and any URLs in the message
- For hosted content: the URL, the IP, and what is wrong with it
We acknowledge abuse reports within [PLACEHOLDER — acknowledgement window, e.g. 24 hours / 1 business day] and aim to resolve or escalate within [PLACEHOLDER — resolution target, e.g. 72 hours / 5 business days]. Reports involving active phishing or malware are handled ahead of everything else.
You can also use the contact form, though emailing the abuse address directly is faster.
14. Changes to This Policy
We update this policy as services change and as upstream requirements change. The current version always lives at this URL, with the revision date at the top of the page.
- Material changes — new restrictions, tighter thresholds, or anything that affects how you can use a service you already pay for — are notified by email to the address on your account, and by a notice in your dashboard, at least [PLACEHOLDER — notice period before material changes take effect, e.g. 14 / 30 days] before they take effect.
- Clarifications, corrections, and new examples that do not change what is permitted take effect when posted.
- Changes required by law, by an upstream provider, or to stop active abuse take effect immediately. We will tell you as soon as we can afterwards.
Continuing to use LexLab services after a change takes effect means you accept the updated policy. If you do not accept a material change, tell us before the effective date and we will discuss options for winding down your service.