Merdot Mail · Acceptable Use & Anti-Spam Policy

Last updated 17 July 2026

This Acceptable Use & Anti-Spam Policy (the "Policy") sets out what you may and may not do when using Merdot Mail, the business email service operated by MERDOT ("Merdot", "we", "us"). It forms part of, and must be read together with, your Merdot Mail Terms of Service and Privacy Policy; capitalised terms not defined here have the meaning given there.

1. Scope and who this Policy binds

This Policy applies to every account, domain, mailbox, and user under your subscription, and to anyone you allow to send or receive mail through your account (employees, contractors, agents, and automated systems such as application or website mailers).

You are responsible for all activity that happens through your account, whether or not you personally carried it out. If you are an organisation, your administrators are responsible for the conduct of every mailbox they provision.

By using Merdot Mail you agree to this Policy. If you do not agree, do not use the service.

Note for the reader: this document is a template. MERDOT should have it reviewed by a qualified Indian lawyer before publishing or relying on it. Placeholders such as the effective date and version number must be completed before it goes live.

2. Why these rules matter · shared sending reputation

Merdot Mail is a shared platform. Outbound mail is delivered through shared infrastructure and shared sending IP addresses hosted with Amazon Web Services in India (Mumbai, ap-south-1) and delivered via Amazon Simple Email Service (Amazon SES).

Because many businesses send through the same reputation pool, the behaviour of one sender directly affects everyone else. When a single account sends spam, triggers spam-trap hits, or attracts a high complaint rate, mailbox providers such as Gmail, Outlook, and Yahoo can throttle, junk, or block mail from the shared IPs. That harms the deliverability of unrelated, well-behaved customers.

For this reason our anti-abuse rules are strict and we enforce them quickly. Protecting the sending reputation is protecting your ability, and every other customer's ability, to have legitimate business mail reach the inbox.

3. Prohibited uses · spam and unsolicited commercial email

You must not use Merdot Mail to send spam, meaning unsolicited bulk or unsolicited commercial email (UCE), or any message to recipients who have not given you a lawful basis to contact them.

Specifically, you must not:

  • Send bulk or commercial messages to recipients who have not consented to receive them or with whom you have no genuine, pre-existing business relationship.
  • Send to purchased, rented, scraped, harvested, or otherwise third-party-sourced address lists.
  • Mail addresses collected without the recipient's knowledge, or continue mailing addresses that have unsubscribed, bounced repeatedly, or complained.
  • Use Merdot Mail as the outbound relay for a bulk marketing or mass-mailing operation. A business mailbox is for genuine business correspondence and reasonable, consented transactional or relationship mail; it is not a mass-marketing platform. High-volume marketing should be sent through a dedicated email-marketing provider designed for it.
  • Disguise, forge, or obscure the origin of a message, the sending domain, or the routing headers, or use misleading subject lines or 'from' names.

4. Consent, unsubscribe, and list hygiene

Where you send any commercial, promotional, or bulk mail that is permitted, you must:

  • Have a clear lawful basis to contact each recipient (for example, opt-in consent, or a genuine existing business relationship), and be able to produce evidence of it on request.
  • Identify yourself accurately. Every commercial message must clearly say who it is from and include a valid physical or business contact address and a working reply path.
  • Offer a clear, working, no-cost way to unsubscribe or opt out, and honour every opt-out promptly (and in any case within a reasonable period, which we recommend treating as no more than a few working days).
  • Keep your lists clean: remove hard bounces, complaints, and unsubscribes, and do not attempt to re-add or re-mail those addresses.

If you send to recipients outside India, you are also responsible for complying with the laws that apply to them, which may include CAN-SPAM (United States), CASL (Canada), and the GDPR and ePrivacy rules (European Union and United Kingdom). These can impose stricter consent and disclosure requirements than Indian law.

5. Prohibited uses · phishing, fraud, and impersonation

You must not use Merdot Mail to deceive recipients or to commit fraud. This includes:

  • Phishing, or any attempt to trick recipients into revealing passwords, one-time codes, banking or card details, or other sensitive information.
  • Spoofing or forging sender identities, or impersonating any person, business, brand, bank, government body, or Merdot itself.
  • Business email compromise, invoice fraud, payment-diversion scams, advance-fee ('419') fraud, fake lotteries or prizes, and similar deception.
  • Pump-and-dump, fake investment, cryptocurrency, or other financial scams.
  • Creating or operating look-alike domains or display names intended to mislead recipients about who is contacting them.

6. Prohibited uses · malware and malicious content

You must not use Merdot Mail to create, host, distribute, or link to anything designed to harm systems or data, including:

  • Viruses, worms, trojans, ransomware, spyware, keyloggers, or any other malicious code.
  • Attachments or links intended to install unwanted software or to gain unauthorised access to any device or account.
  • Content used to probe, scan, or test the vulnerability of any network or system without authorisation, or to breach or circumvent security or authentication measures.
  • Denial-of-service traffic, mail-bombing, or any activity intended to overload or disrupt any system, whether ours, a recipient's, or a third party's.

7. Prohibited uses · illegal, harmful, and infringing content

You must not use Merdot Mail in connection with any illegal activity or to send, store, or link to unlawful or seriously harmful content, including:

  • Content that is unlawful under Indian law, including the Information Technology Act, 2000 and rules made under it, or under any other law that applies to you or your recipients.
  • Child sexual abuse material, or any content that sexually exploits or endangers minors. We report such material to the authorities without notice.
  • Content promoting terrorism, violent extremism, or the incitement of violence or hatred against any group or individual.
  • Harassment, stalking, threats, intimidation, defamation, or abuse directed at any person.
  • Intellectual property infringement, including sending or distributing material that infringes another party's copyright, trademark, patent, trade secret, or other rights, and unlicensed or pirated software, media, or content.
  • Sale or promotion of goods or services whose sale is illegal or restricted, including illegal drugs, weapons, counterfeit goods, and unlawful gambling.
  • Any breach of another person's privacy or unlawful processing of personal data, including personal data protected under the Digital Personal Data Protection Act, 2023 (DPDP Act).

8. Prohibited uses · system, network, and account abuse

You must not:

  • Use the service to operate an open relay or open proxy, or to relay mail on behalf of unrelated third parties.
  • Forge, alter, or remove message headers or authentication results, or take any step to defeat spam filtering or reputation systems.
  • Attempt to access mailboxes, data, or accounts that are not yours, or to interfere with any other customer's use of the service.
  • Share, resell, or sub-license mailboxes to third parties outside your organisation, or create mailboxes for the purpose of evading sending limits or a prior suspension.
  • Use scripts, bots, or automation in a way that places an unreasonable or disproportionate load on the platform, or that is designed to exceed applicable limits.
  • Attempt to reverse engineer, probe, or disrupt the underlying mail infrastructure.

9. Sending limits, warm-up, and throttling

To protect the shared sending reputation, Merdot Mail applies sending limits and progressive warm-up:

  • Rate and volume limits. Each mailbox and domain is subject to limits on the number of messages and recipients it may send per minute, hour, and day. Limits vary by plan (Lite, Standard, Pro) and by the age and reputation of your domain. Current limits are published in your account and may change from time to time.
  • Warm-up for new senders. New domains and mailboxes start with conservative daily caps that increase gradually as a healthy sending history is established. A sudden spike in volume from a new or dormant sender is a classic spam signal and will be throttled automatically.
  • Automatic throttling. We may slow, queue, pause, or hold outbound mail when we detect unusual volume, high bounce rates, high complaint rates, spam-trap hits, or other risk signals. This can happen without prior notice where the reputation of the shared pool is at risk.
  • No guarantee of unlimited sending. Limits exist to keep deliverability high for everyone. If your legitimate needs exceed what a business mailbox is designed for, contact us to discuss the right solution; do not attempt to work around the limits.

10. Authentication and configuration requirements

To send reliably and to keep the platform trustworthy, you must correctly configure and maintain the email authentication we require for your domains, including SPF, DKIM, and, where we ask for it, DMARC.

You must not publish records or configurations that authorise unauthorised third parties to send as your domain, and you must keep your DNS and domain settings accurate. We may refuse to send, or may throttle, mail from domains that are not properly authenticated.

11. Monitoring, enforcement, and consequences of abuse

We continuously monitor the health of the platform using automated signals such as sending volumes, bounce and complaint rates, spam-trap hits, feedback-loop reports from mailbox providers, and abuse reports from third parties. Consistent with our privacy commitments (see section 13), this monitoring relies on delivery metadata and sending patterns, not on our staff reading the contents of your mail.

Where we identify a breach of this Policy, or a threat to the platform, other customers, or third parties, we may take any of the following steps, in our reasonable discretion and in proportion to the issue:

  • Rate-limit, throttle, queue, or hold outbound mail.
  • Require you to fix the problem within a stated time (for example, cleaning a list, correcting authentication, or removing offending content).
  • Suspend one or more mailboxes, a domain, or the entire account.
  • Terminate the affected mailbox(es) or the whole account.
  • Remove or disable access to specific content where we are permitted or required to do so.

We will usually give you notice and an opportunity to remedy a breach. However, for serious or urgent matters, such as active phishing, malware distribution, illegal content, a live threat to the sending reputation, or where the law requires it, we may act immediately and without prior notice, and inform you afterwards.

Repeated or serious breaches may lead to permanent termination. Where we terminate for cause because of your breach of this Policy, you are not entitled to a refund of fees already paid, and any applicable Goods and Services Tax (GST) already charged is non-refundable in accordance with our Terms. You remain liable for any losses, fines, or third-party claims arising from your breach.

12. Reporting abuse

If you receive spam, phishing, malware, harassment, or any other abusive message that appears to originate from Merdot Mail, or if you believe someone is misusing our service, please report it to us at contact@merdotmail.com.

To help us act quickly, please include, where you can:

  • The full message headers of the offending email.
  • A copy of the message body and any relevant attachments or links (do not open suspicious attachments or links).
  • The date and time you received it, including the time zone.
  • Any context about why you believe it is abusive.

We investigate credible reports promptly. To protect the privacy of the parties involved, we may not always be able to tell you the outcome of a specific investigation.

13. Privacy during enforcement

Our commitment stands: we do not read your mail, we do not scan it to target advertising, and we do not sell your data. Your mailbox data belongs to you and is hosted in India.

Abuse detection is designed to respect this. It works from delivery metadata, sending patterns, authentication results, complaint and bounce signals, spam-trap hits, and reports from recipients and mailbox providers, rather than from our staff reading the content of your messages.

We will access the contents of specific messages only in narrow circumstances: where it is strictly necessary to investigate a specific, credible abuse or security incident, where you ask us to as part of resolving an issue, or where we are required to do so by law or valid legal process. Any such access is limited to what is necessary and is handled in accordance with our Privacy Policy and the DPDP Act, 2023.

14. Cooperation with law enforcement and legal process

Merdot Mail operates under Indian law. We cooperate with law enforcement agencies and respond to lawful requests, court orders, and legally valid process from competent authorities in India, and we comply with our obligations under the Information Technology Act, 2000 and the rules made under it.

Where we are legally required or permitted to do so, we may preserve, access, and disclose account information, metadata, or message content to the extent necessary to comply with a valid legal request, to investigate suspected illegal activity, or to protect the rights, safety, and property of Merdot, our customers, or the public.

We will, where the law allows, apply our normal privacy safeguards and disclose only what is required. Nothing in this Policy prevents us from meeting a binding legal obligation.

15. Infrastructure and sub-processors

Merdot Mail is delivered using a small number of infrastructure sub-processors:

  • Amazon Web Services (AWS) for hosting, in the Mumbai region (ap-south-1), India.
  • Amazon Simple Email Service (Amazon SES) for outbound mail delivery.

Because outbound mail is delivered through Amazon SES, your sending activity is also subject to the acceptable-use and anti-spam requirements of that service. Abusive sending can affect not only Merdot's reputation but our ability to use the underlying delivery infrastructure, which is a further reason we enforce this Policy strictly.

16. Your indemnity and responsibility

You are responsible for your use of Merdot Mail and for the conduct of everyone who sends through your account. You agree to indemnify and hold MERDOT harmless against any claims, losses, penalties, fines, or costs (including reasonable legal costs) arising from your breach of this Policy, including complaints from recipients, actions by mailbox or infrastructure providers, and claims by third parties. This section applies in addition to any indemnity in your Terms of Service.

17. Changes to this Policy

We may update this Policy from time to time, for example to address new abuse techniques, to reflect changes in law, or to protect the platform. We will post the current version at merdotmail.com and update the effective date. Material changes will be notified to account administrators by email or in-product notice. Your continued use of Merdot Mail after a change takes effect means you accept the updated Policy.

18. Governing law, jurisdiction, and contact

This Policy is governed by the laws of India. Subject to any mandatory consumer-protection rights you may have, the courts at Ahmedabad, Gujarat, India have exclusive jurisdiction over any dispute arising out of or relating to this Policy.

MERDOT is based in Ahmedabad, Gujarat, India.

For questions about this Policy, or to report abuse, contact us at contact@merdotmail.com.

Effective date: [insert date] · Version: [insert version]

This Policy is a template and should be reviewed by a qualified Indian lawyer before publication.