Acceptable Use Policy
Applies to: the Pombus service operated at pombus.com (the "Service"), provided by Willian Clayton de Almeida, an individual domiciled in Brazil, CPF 277.866.058-51, with correspondence address provided upon request to [email protected], operating under the trade name Pombus ("Pombus", "we", "us").
This Acceptable Use Policy (the "AUP") governs your use of the Service. It is incorporated by reference into, and forms part of, the Pombus Terms of Service. Capitalized terms not defined here have the meaning given in the Terms of Service. By creating an account, provisioning a mailbox, generating an API key, signing in to the Pombus web application, or sending or receiving mail through the Service, you (the "Customer") agree to this AUP and are responsible for ensuring that every person, application, automated agent, integration, and end user acting under your account complies with it.
1. What Pombus Is — and Is Not
1.1. Pombus is a mailbox provider for people and for the AI agents that work for them, in the same mailbox. Each Customer, whether a business or an individual using the Service for personal purposes, operates one or more real, individually addressed mailboxes (for example, contact@, billing@, and orders@). A person uses a mailbox through the Pombus web application; an AI agent uses the same mailbox through the API and webhooks, under an API key with a defined scope (Section 6). Each mailbox is provisioned in one of two ways:
- as a Pombus Address on the shared domain pombus.com (for example, [email protected]). Pombus owns, operates, and authenticates the pombus.com domain, and the Customer is the holder of the mailbox; or
- on a Customer Domain: a domain that the Customer owns and has verified in DNS under Section 4. This option is available but not required.
Applications and AI agents use these mailboxes the way a person uses email: they receive messages, reply within existing conversations, and compose individual messages to individual recipients.
1.2. Pombus is not a bulk-email, mass-marketing, newsletter, or campaign-delivery platform. The Service does not support, and you may not use it for, list uploads, broadcast campaigns, or one-to-many blast sending.
1.3. This distinction is not cosmetic. It defines the permitted use of the Service and reflects the sending profile Pombus maintains with its upstream email infrastructure provider (Amazon Simple Email Service) and, for Pombus Addresses, the reputation of a domain that every Customer shares. Use that departs from a conversational, one-to-one sending pattern is a material breach of this AUP.
1.4. Permitted and prohibited automated sending. The line between the two does not depend on whether a person or an agent writes the message; it depends on the pattern.
- Permitted: one-to-one messages composed by a person, or by an AI agent acting within the scope of its API key, to an individual recipient: replies, follow-ups, individual requests, and individual first contacts, each addressed to a specific recipient for a specific reason.
- Not permitted: automated mass sending of any kind, including batch system notifications, verification or one-time codes sent at scale, alerts broadcast to many recipients, newsletters, marketing campaigns, and any other flow in which the same or templated content is sent to a list of recipients. Such traffic belongs on a dedicated transactional or marketing email service, not on a mailbox.
2. Prohibited Content and Conduct
You may not use the Service to send, transmit, store, solicit, or facilitate any of the following. This list is illustrative, not exhaustive.
2.1. Spam and Unsolicited Mail
- Spam of any kind.
- Unsolicited bulk email or unsolicited commercial email ("UCE").
- Unsolicited first contact at scale: mass prospecting, cold outreach sequences, or any pattern of sending unsolicited first messages to many recipients, whether composed by a person or generated by an agent (see Section 3).
- Mail sent to addresses obtained from purchased, rented, scraped, harvested, or otherwise non-consented lists. Importing or sending to any such list is strictly prohibited, regardless of volume.
2.2. Deceptive, Fraudulent, and Malicious Mail
- Phishing, spear-phishing, credential harvesting, or social-engineering attacks.
- Malware, ransomware, viruses, worms, or any code intended to damage, disrupt, or gain unauthorized access to systems or data.
- Fraud, scams, deceptive commercial practices, pyramid or Ponzi schemes, or chain messages.
- Forged, spoofed, or misleading headers, sender identities, subject lines, or routing information.
2.3. Illegal and Harmful Content
- Content that is illegal under applicable Brazilian, U.S., European Union, or other applicable law.
- Content that infringes intellectual property, publicity, or privacy rights.
- Child sexual abuse material ("CSAM") or any content that sexualizes minors.
- Content promoting terrorism, violent extremism, human trafficking, or the illegal sale of weapons or controlled substances.
- Harassment, threats, defamation, or hate speech.
2.4. Technical Abuse
- Attempts to circumvent account sending limits, per-message recipient caps, rate limits, suppression lists, automated pauses, or any other technical control.
- Using multiple accounts, mailboxes, API keys, or domains to spread sending, to evade limits, pauses, or suspensions, or to resume conduct for which an account, mailbox, or key was restricted.
- Harvesting, verifying, or probing email addresses (namespace mining), including sending test messages to discover whether addresses exist.
- Any activity that degrades, overloads, or interferes with the Service, the underlying infrastructure, or other Customers.
- Unauthorized access to any account, mailbox, API key, or data that is not yours.
2.5. AI Agents and Automation
- Using the Service to send prompt injection, jailbreak attempts, or other content designed to manipulate, hijack, or subvert AI agents or automated systems operated by third parties.
- Automating inauthentic activity, including creating fake personas, simulating independent senders, or generating deceptive engagement.
This AUP applies to conduct carried out through the Service by AI agents that make decisions or take actions autonomously or with any level of human intervention, in the same way as it applies to conduct by a person.
3. Recipient Consent and Customer Responsibility
3.1. You are solely responsible for the lawful basis to contact every recipient you send to and for the content of every message sent under your account, whether composed by a human, an application, or an AI agent.
3.2. An individual, one-to-one first contact with a recipient, sent for a specific and legitimate reason, is permitted. What is prohibited is unsolicited first contact at scale: mass prospecting, cold outreach to many recipients, and any sending to purchased, rented, scraped, or harvested lists (Section 2.1). You represent and warrant, for each message, that it is individually addressed and conversational or individually relevant to its recipient, and that you have a lawful basis to send it under the law that applies to you and to the recipient.
3.3. You are fully responsible for the behavior of your own applications and AI agents. Automated or AI-generated sending does not reduce your obligations. An agent acting under your API key, and a person acting under your account credentials in the web application, act as you, and you bear responsibility for their output, their recipients, and their sending patterns as if you had composed each message yourself.
3.4. You must honor opt-out and unsubscribe requests within 48 hours and must not attempt to re-contact a recipient who has objected, complained, or bounced, except where a distinct and lawful basis clearly applies.
3.5. Sender obligations on the shared domain. Because the major mailbox providers evaluate pombus.com as a single sender, you must, when sending from a Pombus Address: (a) include one-click unsubscribe (List-Unsubscribe and List-Unsubscribe-Post headers, RFC 8058) and a visible unsubscribe link in any message that is not an individual one-to-one message, such as the same content sent to several recipients outside an existing conversation or a recurring update sent to people who asked to receive it; (b) process every opt-out within 48 hours; and (c) keep the spam complaint rate of your sending below 0.1%. These obligations also apply to Customer Domains as good practice and wherever the receiving provider requires them.
4. Domain Authentication and Sender Identity
4.1. Every mailbox on the Service sends from an authenticated domain. How authentication is achieved depends on the kind of mailbox:
- Pombus Addresses ([email protected]). Pombus owns the pombus.com domain and configures and maintains its DKIM, SPF (including the MAIL FROM domain), and DMARC records. Pombus also publishes an MTA-STS policy for pombus.com at https://mta-sts.pombus.com/.well-known/mta-sts.txt, currently in testing mode, with TLS reporting (TLS-RPT) enabled; Pombus intends to move it to enforce mode once the reports show clean delivery. You do not need to own a domain or make any DNS change to use a Pombus Address.
- Customer Domains. Before any mail may be sent from a domain of your own, you must verify that domain in DNS, and you must configure and maintain:
- DKIM (DomainKeys Identified Mail) signing;
- SPF (Sender Policy Framework), including a custom MAIL FROM domain; and
- DMARC (Domain-based Message Authentication, Reporting and Conformance).
4.2. Pombus is designed to block sending from a Customer Domain until domain authentication is complete. Pombus may refuse to send, or may suspend sending, if authentication records are missing, misconfigured, or removed. Sending from a Pombus Address requires only that the mailbox is active and in good standing under Sections 4.5, 5, and 7.
4.3. You may send only from Pombus Addresses provisioned to your account and from Customer Domains you own and have verified. Spoofing, impersonation, or use of any domain, brand, or sender identity that you do not control or are not authorized to use is strictly prohibited. A Pombus Address identifies you, not Pombus: you must not present mail from a Pombus Address as if it were sent by Pombus, and you must not use Pombus's name or marks in display names, signatures, or content except to state that the mailbox is provided by Pombus.
4.4. Shared domain, shared reputation. Every Pombus Address shares the reputation of the pombus.com domain with every other Customer's Pombus Address. Mailbox providers and spam filters evaluate that domain as a whole, so bounces, complaints, or abusive sending from one mailbox degrade deliverability for all of them. For that reason the obligations in Section 3.5, the limits and automated controls in Section 5, and the measures in Section 7 apply with particular strictness to Pombus Addresses (Section 5.5), and Pombus may act on a Pombus Address to protect the shared domain even where the conduct in question would, on a Customer Domain, affect only you. If your sending volume or pattern is not appropriate for a shared domain, you must use a Customer Domain.
4.5. Mailbox names on pombus.com. A Pombus Address is a name assigned to your account on a domain that belongs to Pombus. It is not your property, and no exclusive right in the name arises from its use. When choosing or using a name you must not:
- impersonate, or suggest an affiliation with, a third party, brand, company, public body, or well-known person (for example, [email protected] or the name of a bank, government agency, or other business), unless you are that party or are authorized by it in writing;
- use a name that is misleading about who operates the mailbox or about the nature of the messages sent from it; or
- use a name that Pombus reserves for its own operation, including abuse@, postmaster@, admin@, support@, security@, noreply@, and any other role, system, or brand name that Pombus designates.
Pombus may refuse a name at provisioning and may rename, reclaim, or migrate a Pombus Address, with notice where practicable, if the name breaches this Section, is the subject of a well-founded third-party complaint, or is used in breach of this AUP.
Inactivity. Pombus may reclaim a Pombus Address for inactivity only if it belongs to a free account or to an account without an active paid subscription, and only after the mailbox has been inactive (no messages sent or received) for more than 180 days. Before reclaiming, Pombus will notify the account owner's email address 30 days and again 7 days in advance; any activity in the mailbox before the reclaim date cancels it. A Pombus Address on an account with an active paid subscription is never reclaimed for inactivity.
Quarantine and reassignment. A reclaimed or released name is held in quarantine for 12 months before it may be reassigned to another Customer. Pombus does not forward mail sent to a reclaimed name and does not guarantee that any particular name is or will remain available. A Pombus Address is licensed to you, not assigned (Terms of Service, Section 9.7), and reverts to Pombus when your account is closed or the mailbox is reclaimed (Terms of Service, Section 13.7). If a name previously used by another Customer is assigned to you, you must not read, use, or reply to messages evidently intended for its former holder, and must report them to [email protected].
5. Sending Limits, Suppression, and Automated Controls
5.1. Suppression. Pombus automatically suppresses recipients that generate hard bounces or spam complaints. Suppressed addresses will not receive further mail from your account. You must not attempt to bypass, clear, or circumvent the suppression list.
5.2. Limits. Pombus applies, or may apply, sending limits per account according to your plan. Each message may be addressed to at most 10 recipients when sent through the API with an API key, and to at most 100 recipients when sent through the Pombus web application. These limits protect the Service's reputation and the deliverability of all Customers. Attempting to evade them, including by the means described in Section 2.4, is a breach of this AUP.
5.3. Automated review and pausing. Pombus monitors bounce and complaint rates for each mailbox and account. A mailbox or account whose hard-bounce rate reaches 3% or whose complaint rate reaches 0.08%, measured over a representative volume of recent sending, is placed under review and its sending may be paused automatically without prior notice. These thresholds are set below the levels at which Amazon SES places a sender under review (5% bounces; 0.1% complaints), so that Pombus acts before the shared infrastructure is put at risk. Pombus also applies, or may apply, an operator kill-switch that halts sending from a mailbox, API key, or account immediately.
5.4. Send logging. Sends are recorded in an append-only, timestamped log tied to the originating API key or web session and mailbox. These logs support abuse investigation, security, and dispute resolution.
5.5. Shared-domain enforcement. On Pombus Addresses, the controls in this Section are applied strictly and at the level of the individual mailbox, because one mailbox's bounces or complaints harm every other mailbox on pombus.com. In particular: (a) suppression under Section 5.1 applies to every Pombus Address without exception; (b) the per-message recipient caps in Section 5.2 apply to every Pombus Address; (c) the review and automated pausing in Section 5.3 may pause a single mailbox without pausing the rest of your account; and (d) the operator kill-switch in Sections 5.3 and 7.1 may be used to halt sending from a Pombus Address immediately. Where necessary to protect the shared domain, Pombus may also migrate a Pombus Address to a separate sending identity, suspend it, or close it, and may require you to move a use case to a Customer Domain as a condition of continued sending.
6. API Keys and Scoped Access
6.1. API keys are issued per agent and bound to a single mailbox, with least-privilege scopes (for example: read, read and reply, read and send). You must select the narrowest scope required for each application or agent, and you must not reuse one key across several agents or mailboxes: attribution in the send log (Section 5.4) and the ability to suspend a single agent without affecting the others (Section 7.2) depend on it.
6.2. You are responsible for the security and confidentiality of your API keys. Any activity performed with your key is attributed to you. Compromised or leaked keys must be rotated or revoked immediately, and you must notify Pombus at [email protected] without undue delay.
6.3. People and webhooks. People access mailboxes through the Pombus web application using the account's credentials; their conduct is subject to this AUP in the same way as an agent's, and you are responsible for the people you give access to. Webhook endpoints that you register receive inbound messages and events for your mailboxes; you are responsible for securing those endpoints, for verifying that requests come from Pombus, and for what your systems and agents do with the data they receive.
7. Enforcement
7.1. Pombus may take any of the following actions, with or without prior notice, where it reasonably determines that a violation has occurred, is occurring, or is imminent, or where necessary to protect the Service, its infrastructure, other Customers, or third parties:
- Throttle or rate-limit sending;
- Suspend a mailbox, API key, or account;
- Rename, migrate, or reclaim a Pombus Address (Sections 4.5 and 5.5);
- Activate an operator kill-switch to halt sending immediately;
- Add recipients to the suppression list;
- Terminate the account.
7.2. Pombus will seek to apply the least disruptive measure appropriate to the circumstances, at the narrowest level that fits (API key, then mailbox, then account), and, where practicable and lawful, will notify you and give you an opportunity to remediate. Immediate action may be taken without prior notice for serious violations (for example, phishing, malware, CSAM, complaint or bounce rates above the thresholds in Section 5.3, or legal orders) and, for Pombus Addresses, wherever delay would put the reputation of the shared pombus.com domain at risk.
7.3. Enforcement action under this AUP does not limit any other remedy available to Pombus under the Terms of Service or applicable law, and does not entitle you to a refund for suspension or termination caused by your breach.
8. Reporting Abuse
8.1. To report suspected abuse, spam, phishing, or other violations of this AUP originating from the Service, contact:
Abuse reports: [email protected]
8.2. Please include, where available: the affected recipient address, message headers, timestamps, and a description of the issue. Pombus reviews abuse reports and takes appropriate action, which may include the measures in Section 7. Pombus may share information with the reporting party, affected Customers, upstream providers, or authorities as necessary to investigate and resolve the report and as permitted by law.
9. Changes to This AUP
9.1. Pombus may update this AUP to reflect changes in the Service, applicable law, or its infrastructure providers' requirements. Material changes will be notified through the Service or by email, and the "Last updated" date above will be revised. Continued use of the Service after changes take effect constitutes acceptance.
10. Contact
Willian Clayton de Almeida, an individual, trading as Pombus
CPF 277.866.058-51 (supplier identification under Article 2, I, of Decree No. 7,962/2013)
Correspondence address: provided upon request to [email protected]
Abuse: [email protected]
Legal notices: [email protected]
General: [email protected]