Sending compliance

Acceptable Use Policy (AUP)

Oveyon exists so that transactional and operational email reaches the inbox — not the spam folder. That is only possible if everyone who sends through the platform follows the same rules of consent, authentication and hygiene. This policy defines those rules and what we do when they are broken.

Last updated · August 26, 2026 Version · 1.1 Effective · immediately

01Scope and acceptance

This Acceptable Use Policy ("AUP") applies to all use of the Oveyon platform ("Service"), provided by Akamind Inc., a Delaware C-corporation ("Oveyon", "we"). It forms part of the Terms of Service and applies to every customer, delegated sub-account and end user who sends messages or configures sending domains through the platform. By using the Service, you agree to this AUP and are responsible for ensuring that anyone sending under your account also complies with it.

This AUP is intentionally strict. Sending reputation is a shared asset: one abusive sender harms the deliverability of everyone who shares the same infrastructure. We would rather turn away volume than risk the inbox of legitimate senders.

This page is informational: it describes platform practices and capabilities in effect on the publication date, which may evolve, and it does not by itself create any warranty, service level or contractual obligation beyond what is set out in the Terms of Service.

You may only send messages to recipients who have given verifiable consent to receive them — through explicit opt-in, an active contractual relationship or a direct request from the recipient (transactional email resulting from an action of theirs).

It is strictly prohibited to:

You must be able to prove the origin of consent for each recipient if requested by us, by a mailbox provider or by a competent authority.

03Prohibited content and practices

Regardless of consent, it is prohibited to use the Service for:

Sensitive categories (credit, health, gambling, crypto, "affiliates") are not prohibited in themselves, but are subject to greater reputation scrutiny and may require additional verification before volume is released.

04Mandatory email authentication

Every sending domain must be authenticated before operating at volume. Oveyon provides and verifies this end to end:

SPFEnvelope alignmentSPF record verified and envelope alignment with the From via a delegated sending domain.RFC 7208
DKIMRSA-2048 signatureKey pair per domain (the private key never leaves the vault), derived selector, with double DKIM (tenant + ESP).RFC 6376
DMARCPublication + RUA reportsWe guide the publication of _dmarc and ingest/parse the aggregate reports to detect spoofing.RFC 7489
MTA-STS / TLS-RPTTLS on deliveryMTA-STS policy published and consumed on egress; ingestion of TLS-RPT transport-failure reports.RFC 8461 · 8460

Sending from a domain whose authentication you have disabled, tampered with or not published correctly is a violation of this AUP. We do not allow sending "in the dark": without the correct signing key, the message is rejected, not signed blindly.

05Unsubscribe and suppression

Every recipient has the right to stop receiving. Oveyon enforces this technically, not just by promise:

Disabling, hiding or hindering unsubscribe — or reintroducing suppressed addresses — is a serious violation and may result in immediate suspension.

06Reputation limits

Reputation is measured, not assumed. We monitor continuously and may throttle or pause sending when the signals leave the safe range:

SignalReferenceTypical action
Complaint (spam) ratealert from 0.3% (Gmail threshold)throttle, review, possible suspension
Hard bounce rateelevated / risingsuppression + review of the list source
Blocklist / DNSBL presenceIP or domain listedalert the operator, route diversion, pause
Warmuprising daily cap per domainautomatic pause if health worsens

New domains and IPs go through a mandatory warmup ramp. Abrupt volume spikes without history are treated as a risk signal.

07Oveyon's technical controls

We do not rely on policy alone. The platform systematically applies hygiene controls to the traffic it processes:

Transparency

We describe here the controls that are actually implemented. Some transport mechanisms (MTA-STS, DANE) operate in observation/opportunistic mode and do not block delivery if the destination fails — the decision is always to deliver authenticated when possible, and to record when it is not.

08Enforcement and sanctions

Faced with a violation — proven or strongly indicated — we may, proportionally and at any time:

  1. Throttle the sending rate of the account or domain;
  2. Freeze (sandbox) messages pending review;
  3. Suppress specific recipients or lists;
  4. Suspend the account's sending;
  5. Terminate the account in case of serious, repeated or illegal abuse.

Every relevant action is recorded in an audit trail. Whenever possible, we notify and give an opportunity to remedy; in cases of imminent risk to the reputation of the platform or of third parties, we act first and explain afterwards. Automatic self-suspension by complaint rate, when enabled, never affects operator accounts and is reversible.

09How to report abuse

Received an improper message sent through our infrastructure? We want to know, and we act. Every outbound message carries an X-Report-Abuse header and a Feedback-ID. Forward the message with full headers to abuse@oveyon.com or see the full process at oveyon.com/abuse.

10Changes to this policy

We may update this AUP to reflect legal, technical or mailbox-provider requirement changes. The version in force is always the one published on this page, with the update date at the top. Material changes will be communicated to active customers.

Version history — 1.1 (August 26, 2026): the provider of the Service on oveyon.com became Akamind Inc. 1.0 (July 31, 2026): first publication.

Contact

Abuse: abuse@oveyon.com · Privacy: privacy@oveyon.com · Legal: legal@oveyon.com