Trust & safety
Report abuse
Oveyon operates email sending infrastructure. If you received spam, phishing or any improper message originating from our network, this is the right channel to notify us. Mailbox providers, security researchers and authorities will find here how to reach us and how reports are handled.
Reporting phishing, malware or a compromise in progress? Write to abuse@oveyon.com with the subject starting with [URGENT] and attach the message with full headers. The [URGENT] prefix helps our triage prioritize the case.
01How to report
Forward the offending message — with full headers preserved — to:
Every message sent through our infrastructure carries an X-Report-Abuse header and a Feedback-ID — they let us correlate the report to the exact message and sender.
02What to include
So we can act quickly and accurately, include as much as possible:
- The complete message, with all headers (not just the body or a screenshot);
- The affected recipient's address;
- Date, time and timezone of receipt;
- The
Feedback-ID, theMessage-IDor the return-path (bounce+…@bounce.oveyon.com), if available; - A brief description of the problem (spam, phishing, malware, missing unsubscribe, etc.).
03Automated channels
For mailbox providers and network operators, we maintain the industry-standard channels — processed automatically:
| Channel | Standard | What we do |
|---|---|---|
| Feedback Loop (FBL) / complaint | ARF · RFC 5965 | We parse the report and correlate the complaint to the sender; automatic suppression and scoring. |
| Aggregate DMARC (RUA) | RFC 7489 | We ingest and parse the reports; classify legitimate IPs vs. spoofing. |
| TLS-RPT | RFC 8460 | We ingest the TLS transport-failure reports on delivery. |
| Bounce / DSN | VERP | We correlate the DSN to the exact message via the return-path and act on suppression. |
If you operate an FBL and want to include us, write to abuse@oveyon.com.
04How we handle a report
Every valid report becomes an abuse event correlated to the sender, domain and IP. From there, proportionally:
- We confirm and correlate — we identify the message, the sender and the pattern;
- We aggregate — an isolated complaint is different from a rate that crosses the risk threshold;
- We contain the damage — throttle, freeze (sandbox), recipient suppression, sender suspension or account termination, depending on severity;
- We record everything in an audit trail;
- We get back to the reporter, where a reply address is available, as soon as reasonably possible.
The sanctions applicable to the sender are described in the Acceptable Use Policy.
05Authenticated reports
A complaint is only treated as trusted when it passes DKIM and comes from a recognized FBL provider. This closes the "forged self-suspension" vector, where a third party would try to take down a legitimate sender by sending fake complaints in their name. Human reports by email are always reviewed, but do not trigger automatic actions on their own.
06Authorities and court orders
Requests from authorities, court orders and data-preservation requests should be sent to legal@oveyon.com. We respond to legally valid requests in accordance with applicable law and our Privacy Policy. We do not log message content (the body); we retain sending metadata and the archived object according to the retention policies described in the Privacy Policy.
07Vulnerability disclosure
Found a security flaw in the platform? Disclose it responsibly to abuse@oveyon.com with the subject [SECURITY]. We ask that you not exploit the flaw beyond what is necessary to demonstrate it, that you not access third-party data, and that you give us reasonable time to fix it before any public disclosure.
This page describes how our abuse channel works for informational purposes. Handling actions are discretionary and proportionate to each case; nothing here creates a warranty, binding response time or contractual obligation beyond what is set out in the Terms of Service and the AUP.
Abuse: abuse@oveyon.com · Privacy: privacy@oveyon.com · Legal: legal@oveyon.com
Oveyon is a service of Akamind Inc., a Delaware C-corporation.