Sending compliance
Acceptable Use Policy (AUP)
Oveyon exists so that transactional and operational email reaches the inbox — not the spam folder. That is only possible if everyone who sends through the platform follows the same rules of consent, authentication and hygiene. This policy defines those rules and what we do when they are broken.
01Scope and acceptance
This Acceptable Use Policy ("AUP") applies to all use of the Oveyon platform ("Service"), provided by Akamind Inc., a Delaware C-corporation ("Oveyon", "we"). It forms part of the Terms of Service and applies to every customer, delegated sub-account and end user who sends messages or configures sending domains through the platform. By using the Service, you agree to this AUP and are responsible for ensuring that anyone sending under your account also complies with it.
This AUP is intentionally strict. Sending reputation is a shared asset: one abusive sender harms the deliverability of everyone who shares the same infrastructure. We would rather turn away volume than risk the inbox of legitimate senders.
This page is informational: it describes platform practices and capabilities in effect on the publication date, which may evolve, and it does not by itself create any warranty, service level or contractual obligation beyond what is set out in the Terms of Service.
02Consent is mandatory
You may only send messages to recipients who have given verifiable consent to receive them — through explicit opt-in, an active contractual relationship or a direct request from the recipient (transactional email resulting from an action of theirs).
It is strictly prohibited to:
- Send to purchased, rented, scraped or harvested lists;
- Send to addresses obtained from third parties without the recipient's direct consent;
- Continue sending to those who requested unsubscribe, marked messages as spam or whose address returned a hard bounce;
- Use consent obtained for one purpose to send content of a different, unrelated purpose.
You must be able to prove the origin of consent for each recipient if requested by us, by a mailbox provider or by a competent authority.
03Prohibited content and practices
Regardless of consent, it is prohibited to use the Service for:
- Phishing, spoofing or identity forgery — including forging headers, sender, domain or the
Fromof a third party you do not control; - Distributing malware, ransomware, spyware or links to malicious content;
- Financial scams, pyramid schemes, advance-fee fraud, fake lotteries and the like;
- Content that is illegal in the jurisdiction of the sender or recipient, child exploitation material, incitement to violence or hate speech;
- Violating third-party rights (intellectual property, trademark, privacy);
- Circumventing unsubscribe, suppression, authentication or platform-limit mechanisms;
- Testing, probing or exploiting vulnerabilities in the infrastructure without our written authorization.
Sensitive categories (credit, health, gambling, crypto, "affiliates") are not prohibited in themselves, but are subject to greater reputation scrutiny and may require additional verification before volume is released.
04Mandatory email authentication
Every sending domain must be authenticated before operating at volume. Oveyon provides and verifies this end to end:
From via a delegated sending domain.RFC 7208_dmarc and ingest/parse the aggregate reports to detect spoofing.RFC 7489Sending from a domain whose authentication you have disabled, tampered with or not published correctly is a violation of this AUP. We do not allow sending "in the dark": without the correct signing key, the message is rejected, not signed blindly.
05Unsubscribe and suppression
Every recipient has the right to stop receiving. Oveyon enforces this technically, not just by promise:
- One-click unsubscribe — we insert the
List-UnsubscribeandList-Unsubscribe-Post: List-Unsubscribe=One-Clickheaders, covered by the DKIM signature, as required by Gmail and Yahoo since 2024; - The unsubscribe
POSTtakes effect immediately; the request is recorded as a suppression and event, and the customer's webhook is notified; - Automatic suppression list — hard bounces and complaints go into suppression. A non-existent mailbox becomes a global suppression; other causes remain scoped to the sender;
- Every send may carry an unsubscribe footer (HTML and text) and the
X-Report-Abuseheader.
Disabling, hiding or hindering unsubscribe — or reintroducing suppressed addresses — is a serious violation and may result in immediate suspension.
06Reputation limits
Reputation is measured, not assumed. We monitor continuously and may throttle or pause sending when the signals leave the safe range:
| Signal | Reference | Typical action |
|---|---|---|
| Complaint (spam) rate | alert from 0.3% (Gmail threshold) | throttle, review, possible suspension |
| Hard bounce rate | elevated / rising | suppression + review of the list source |
| Blocklist / DNSBL presence | IP or domain listed | alert the operator, route diversion, pause |
| Warmup | rising daily cap per domain | automatic pause if health worsens |
New domains and IPs go through a mandatory warmup ramp. Abrupt volume spikes without history are treated as a risk signal.
07Oveyon's technical controls
We do not rely on policy alone. The platform systematically applies hygiene controls to the traffic it processes:
- Compromised-account detection — scoring by telemetry (volume spikes, bounces, FBL complaints, domain spray) with vigilance, suspicion and compromise levels;
- IP reputation checking — cross-referencing with AbuseIPDB and DNSBL checks;
- Content and URL scanning — explainable spam score, URL blocklist (Spamhaus DBL / SURBL / URIBL) and verification via Google Web Risk / Safe Browsing;
- Sandbox (frozen) — messages from a suspected source are accepted, signed and stored, but not delivered until controlled release;
- Rate limiting and authentication throttle — protection against compromised credentials and brute force;
- Egress hygiene — removal of internal control headers before external delivery, preserving what DKIM signed;
- Circuit breaker and relay valves to contain route failures without contaminating reputation.
We describe here the controls that are actually implemented. Some transport mechanisms (MTA-STS, DANE) operate in observation/opportunistic mode and do not block delivery if the destination fails — the decision is always to deliver authenticated when possible, and to record when it is not.
08Enforcement and sanctions
Faced with a violation — proven or strongly indicated — we may, proportionally and at any time:
- Throttle the sending rate of the account or domain;
- Freeze (sandbox) messages pending review;
- Suppress specific recipients or lists;
- Suspend the account's sending;
- Terminate the account in case of serious, repeated or illegal abuse.
Every relevant action is recorded in an audit trail. Whenever possible, we notify and give an opportunity to remedy; in cases of imminent risk to the reputation of the platform or of third parties, we act first and explain afterwards. Automatic self-suspension by complaint rate, when enabled, never affects operator accounts and is reversible.
09How to report abuse
Received an improper message sent through our infrastructure? We want to know, and we act. Every outbound message carries an X-Report-Abuse header and a Feedback-ID. Forward the message with full headers to abuse@oveyon.com or see the full process at oveyon.com/abuse.
10Changes to this policy
We may update this AUP to reflect legal, technical or mailbox-provider requirement changes. The version in force is always the one published on this page, with the update date at the top. Material changes will be communicated to active customers.
Version history — 1.1 (August 26, 2026): the provider of the Service on oveyon.com became Akamind Inc. 1.0 (July 31, 2026): first publication.
Abuse: abuse@oveyon.com · Privacy: privacy@oveyon.com · Legal: legal@oveyon.com