Acceptable Use Policy
What you may send, what you may not, and what happens if it goes wrong.
Last updated 2026-08-06
- 1. Permission to email
- 2. Where your addresses came from
- 3. What you may not send
- 4. Headers, subject lines and identity
- 5. Unsubscribes
- 6. Complaints and bounces
- 7. What we do about it
- 8. Reporting abuse
1. Permission to email
You need permission for every address you send to. Not most of them. That is the single rule this page exists to state, and everything below follows from it.
Permission means the person asked to hear from you, in a way you could describe to someone else afterwards. A signup form, a checkout box they ticked themselves, an account they created. It does not mean they gave you an address for one purpose and you started sending another kind of mail to it.
Transactional mail is different and this is worth being clear about. Password resets, one-time codes, receipts and delivery notices go to people because of something they did, and they do not need marketing permission.
2. Where your addresses came from
You may not send to addresses that were:
- bought, rented or otherwise licensed from someone else
- scraped from websites, directories or social profiles
- guessed, generated, or built by appending your domain to a list of names
- collected by a third party who cannot tell you how
- given to a different company that you later acquired, unless the original permission covered mail from you
If you are importing a list you did not build yourself, tell us before you send. We would rather have that conversation early than read the complaint reports afterwards.
3. What you may not send
- anything illegal where you are, or where your recipients are
- malware, phishing, or links to either
- content designed to deceive someone into paying, logging in, or handing over credentials
- sexually explicit material
- promotion of firearms, illegal drugs, or prescription medication sold without a prescription
- gambling where it is not permitted
- cryptocurrency or investment offers promising a return
- multi-level marketing, chain letters, and work-from-home offers of the kind that fill spam folders
- content that attacks people for who they are
4. Headers, subject lines and identity
Your mail must say who it is from. Do not forge headers, disguise the sending domain, or route mail to look as though it came from somebody else.
Subject lines must describe what is inside. A subject that promises one thing to get the message opened and delivers another is prohibited under United States law governing commercial email, and it is also the fastest way to teach a mailbox provider that your domain is worth filtering.
Every marketing message must carry a real postal address for your business and a working way to unsubscribe. Today both of those are yours to put there. The unsubscribe link and its headers are something we add to marketing sends, and marketing sends are not a thing this API can produce yet: every message you pass to it is recorded as transactional, and a transactional message gets neither. So if what you are sending is promotional, the address, the link and the opt-out behind it are all yours to supply. When that changes, this section will say which of them we have taken over, and the date at the top will change with it.
5. Unsubscribes
Every marketing message you send must carry a working unsubscribe, and it has to act on the first click, without asking the person to sign in, explain themselves, or hunt for the right list to leave.
We do run an unsubscribe page, and a link that reaches it suppresses the address for your account immediately. That link is issued for marketing sends, and as section 4 says those are not something the API produces yet, so nothing you send today carries one and the opt-out route inside your mail has to be your own.
However somebody opts out, treat it as final. Do not re-import that address, do not move it to a different list, and do not ask us to clear it. Coming back is their decision to make, and not yours to make for them.
6. Complaints and bounces
Mailbox providers judge a sending domain by how often people mark its mail as spam and how often it is sent to addresses that do not exist. Sustained complaint rates above 0.1%, or hard bounce rates above 5%, are where a domain starts being filtered rather than delivered.
Those are the thresholds we act on. They are industry norms rather than numbers we invented, and we watch them because your sending reputation and ours are not fully separable.
7. What we do about it
When something on this page is breached, what happens is, in order:
- We get in touch. Most breaches are a bad import or a form somebody left unprotected, and the fix is a conversation. We will usually ask you to stop sending the campaign in question while we work it out.
- We stop your sending. Suspension stops mail leaving and stops deliveries that are already queued. You keep access to your account, your data and your billing page.
We can skip straight to the second step, and will, for phishing, malware, or anything that puts other people at immediate risk.
Suspension is not a refund event and it is not termination. Ending the agreement entirely is covered in the Terms of Service.
8. Reporting abuse
If you received mail through Wakio that breaches this policy, write to [email protected] and include the message with its full headers if you can. The headers are what let us find the account; without them we are guessing.
This policy is part of the Terms of Service. WorkersLab LLC, trading as Wakio, of 30 N Gould St STE N, Sheridan, WY 82801, whose own site is workerslab.com.