Legal

Acceptable Use Policy

· BounceIntel · Bulevardul Republicii 363, Vaslui 730121, Romania

This document is published in English only. It is the authoritative version and applies regardless of the language you are browsing the rest of the site in.

A verification service can be used to keep a legitimate mailing list clean, or it can be used to work out which addresses at a company exist. The mechanism is the same; the intent is not. This policy is where we draw that line.

It forms part of the Terms of Service. Breaching it is a breach of those Terms.

01The one rule underneath all the others

Only submit addresses you already hold and have a lawful basis to process. Verification is for confirming that a mailbox you legitimately have is still live. It is not a method of acquiring addresses, discovering them, or testing whether guesses are right.

If you could not explain to the person behind an address how you came to have it, do not verify it.

02Prohibited sources of data

  • Addresses scraped from websites, social networks, directories or public records.
  • Purchased, rented, appended or otherwise brokered lists, however they are described by the seller.
  • Addresses generated by permutation: combining names with a domain to see which combinations exist.
  • Addresses obtained from a breach, leak or credential dump.
  • Addresses taken from a former employer, client or partner without a lawful basis to continue using them.
  • Addresses collected under a notice that did not contemplate this kind of processing.

03Prohibited uses

  • Supporting unsolicited bulk email, whether or not you call it marketing.
  • Phishing, fraud, impersonation, or any attempt to obtain credentials or payment details by deception.
  • Enumerating or harvesting valid addresses at a domain you have no relationship with.
  • Testing whether a set of addresses appears in a breach corpus, or otherwise using the Service as part of a credential-stuffing workflow.
  • Reselling raw verification capacity, or reverse-engineering our scoring to build a competing service.
  • Circumventing rate limits or credit metering, including by distributing traffic across multiple accounts.
  • Any use that is unlawful where you are established, where we are established, or where the recipient is.

04Technical limits

The API is rate limited per key, and a single bulk job is bounded by the size of the request the service will accept rather than by an address count. Limits exist to protect the receiving mail servers we interrogate as much as to protect us; a verification service that hammers a third party's mail infrastructure is a nuisance to everyone, including its own customers.

Do not attempt to work around a limit. If your legitimate volume exceeds it, contact us and we will raise it.

Do not probe, scan or attempt to gain unauthorised access to our systems. Genuine security research is welcome; see the section below.

05Content of what you upload

Upload only .csv, .tsv or .txt files. Our uploader extracts email addresses and ignores every other column, so there is no reason to include names, phone numbers, customer identifiers or anything else, and doing so is contrary to data minimisation.

Do not upload special category data, payment card data, health information, or anything covered by a confidentiality obligation you cannot extend to a processor.

06Reporting abuse

If you believe the Service is being used in breach of this policy, write to [email protected] with whatever evidence you have: headers, timestamps, the addresses involved. We investigate every report.

If you are a mail operator and our verification traffic is causing you a problem, write to the same address. We will work with you on volume, timing or exclusion.

07Security research

Report vulnerabilities to [email protected]. Test only against your own account, do not access or modify anyone else's data, do not run denial-of-service or spam tests, and give us reasonable time to fix an issue before disclosing it.

Research conducted on those terms is welcome, and we will not pursue action over it.

08Enforcement

Where we reasonably believe this policy is being breached we may throttle an account, suspend a key, suspend the account, or terminate it. We choose the least disruptive measure that actually stops the harm.

Urgent cases (active phishing, enumeration at scale, a complaint from a mail operator) are acted on immediately and explained afterwards. Everything else starts with a message to you and an opportunity to put it right.

Credits consumed before a suspension are not refunded. Credits unused at the point of a termination for breach are forfeited.

09Changes

We update this policy as new patterns of abuse appear. The revision date at the top reflects the current version, and material changes are notified to account holders by email.