Legal
Acceptable Use Policy
Last updated: August 7, 2026
SendCanyon exists to make good outreach easier, not to make spam cheaper. This policy defines the line. It applies to every workspace and every message sent through the Service, is incorporated into our Terms of Service, and is enforced by both automated systems and human review. Report abuse to abuse@sendcanyon.com.
1. The standard
Every message you send through SendCanyon must be one you could defend to the recipient, to their mailbox provider, and to a regulator: sent to someone you have a lawful, articulable reason to contact, honest about who it is from and why, and trivially easy to stop. If a sending practice depends on the recipient not noticing something, it is not permitted here.
2. List and consent requirements
- You must have a consent basis or a documented legitimate-interest basis for every contact. For B2B outreach under legitimate interest, that means a specific, plausible business relevance between your offer and the recipient's professional role — not merely a harvested address.
- Purchased or rented lists are prohibited unless you can demonstrate a valid consent basis for the contacts on them. In practice, bulk-purchased lists almost never meet this bar; "the vendor said it was opted in" is not evidence.
- Scraped lists are prohibited — addresses harvested from websites, social networks, or directories without any relationship or basis.
- Role and trap hygiene: do not knowingly send to role accounts unrelated to your purpose (postmaster@, abuse@), spam-trap addresses, or addresses that previously hard-bounced or unsubscribed anywhere in your organization.
- Validation is expected. Import validation exists in the product; disabling your own judgment about a list because validation "will catch it" is not compliance.
3. Bounce and complaint thresholds
These are the numeric tripwires our automated enforcement watches, measured per workspace and per domain over rolling windows:
| Metric | Warning | Sending pause |
|---|---|---|
| Hard-bounce rate | 2% of sends (7-day) | 5% of sends (7-day) |
| Spam-complaint rate | 0.1% of sends (30-day) | 0.3% of sends (30-day) |
| Unsubscribe rate | 2% of sends (7-day) | Reviewed case by case |
| Invalid rate at import | 10% of an import | Repeated 25%+ imports |
Crossing a warning threshold triggers an in-app and email notice with the affected campaigns identified. Crossing a pause threshold suspends campaign sending for the affected domain or workspace automatically — dashboard access, warmup, and data export continue — until you have identified the cause and we have reviewed your remediation. Repeated threshold breaches after remediation are grounds for termination.
4. Prohibited content and practices
The following may not be sent through or promoted via the Service under any circumstances:
- Deceptive headers, forged sender information, or subject lines designed to misrepresent the message's origin or content (including fake "Re:" / "Fwd:" threading).
- Phishing, credential harvesting, malware, or links to either.
- Content that is illegal in the sender's or recipient's jurisdiction: fraud, pyramid or multi-level recruitment schemes, counterfeit goods, unlicensed pharmaceuticals or controlled substances, weapons sales, or sanctioned-party dealings.
- Adult content, escort services, or sexually explicit material; predatory financial products; fake documents or credentials.
- Harassment, threats, doxxing, or content that incites hatred or violence against any person or group.
- Messages impersonating another person or organization, or sent from domains and mailboxes you do not control.
- Deliberate evasion of this policy: rotating burner domains to outrun reputation damage, re-importing suppressed addresses under new lists, or splitting sends across workspaces to dodge thresholds.
5. Technical requirements
- Sending domains must pass SPF, DKIM, and DMARC verification (the product enforces this before launch).
- Every sequence must include a functioning unsubscribe mechanism (enforced), and unsubscribes are honored permanently via suppression.
- Warmup gating, daily limits, and pacing must not be circumvented — including by simultaneously running the same mailboxes at volume through other tools.
- Do not use the API to rebuild prohibited behavior the dashboard prevents.
6. Enforcement
Enforcement is graduated but not negotiable. Depending on severity we may: issue a warning with required remediation; pause specific campaigns; suspend sending for a domain or workspace; terminate the account for repeated or serious violations; and, where content is unlawful, preserve evidence and report to relevant authorities. Automated pauses (Section 3) are reversible on remediation; deliberate deception — forged consent records, threshold evasion, prohibited content — is grounds for immediate termination without refund, per the Terms of Service.
We investigate every report sent to abuse@sendcanyon.com, including reports from recipients, mailbox providers, and blocklist operators. If you believe an enforcement action was applied in error, reply to the enforcement notice with the facts; a human reviews every appeal.
7. Why this policy is strict
Deliverability is a commons. One workspace sending to a purchased list from a burned domain damages recipient trust and provider relationships that every legitimate sender depends on. The thresholds in this policy are not arbitrary caution — they mirror the limits Gmail, Microsoft, and Yahoo themselves enforce. Staying inside them is not just how you keep your SendCanyon account; it is how cold email keeps working at all.