Skip to content
MailGuardHQ
Legal

Acceptable Use Policy

What you may and may not do with the service. This applies to the free domain check as much as to a paid account.

Draft - not yet reviewed by counsel

This document is a working draft written to be reviewed, not a binding agreement. It has not been through legal review and it does not yet govern any customer relationship. Do not rely on it. It is published here so the shape and the commitments can be checked before launch.

Last updated 9 August 2026 · Uniworld Technologies · MailGuardHQ

1. Check domains you are entitled to check

The public domain check reads DNS records that are already published to the whole internet, so running it against a domain is not an attack. Even so:

  • Do not use the check to build a bulk list of misconfigured domains for cold outreach, resale, or targeting.
  • Do not use it as reconnaissance for an attack on a third party.
  • Only add a domain to monitoring if you own it or administer it with authorisation.

2. Do not overload the service

  • Do not exceed the published rate limits, or attempt to work around them by rotating IP addresses, accounts or API keys.
  • Do not create multiple free accounts to obtain more free allowance than one account provides.
  • Do not point an unreasonable volume of report traffic at us without telling us first. If you are onboarding hundreds of domains, contact us and we will plan the capacity with you.

3. Do not attack or probe the service

  • No attempts to gain unauthorised access to another tenant's data, to escalate token scopes, or to bypass authentication.
  • No malformed or hostile payloads intended to break parsing, including compression bombs sent to our report intake.
  • No scraping of the application beyond your own tenant's data through the published API.

Security research is welcome, but coordinate with us first. A responsible disclosure contact will be published before launch. Do not test against another customer's tenant under any circumstances.

4. Do not misuse what the service tells you

Findings about a domain's email authentication can be used to improve it or to exploit it. Using output from this service to impersonate a domain, to craft phishing, or to help anyone else do so, is a serious breach and will result in immediate termination.

5. Automation, API and MCP

  • Automated clients must identify themselves and honour rate limit responses.
  • Keep API keys secret. Do not embed them in client-side code or public repositories.
  • You remain responsible for anything done with your credentials, including by an AI assistant you have connected to the MCP server.

6. Consequences

Depending on severity, we may rate limit you, suspend a key, suspend the account, or terminate it. Where a breach is accidental and low impact we will normally contact you first. Where it endangers other customers or a third party, we will act immediately.

7. Reporting abuse

If you believe the service is being used against you or against someone else, tell us. An abuse contact address will be published before launch.