AgentSend sends product email and opted-in marketing email from domains our customers verify. One sender's spam damages delivery for everyone else on shared infrastructure, so we enforce this policy strictly.
Legal
Acceptable Use Policy
Last updated:
01Who this applies to
This policy covers every email sent through AgentSend, whether it goes through the REST API, the MCP server, the CLI, or the dashboard, and whether a person, a script, or an AI agent makes the call. It applies to the account holder and to anyone or anything using the account's API keys. What an agent sends with your key, you sent.
This policy is part of our Terms of Service. If you're unsure whether something is allowed, ask at hello@agentsend.co before you send it.
02Permission-based email only
Every recipient must expect your email. That means one of two things:
- Transactional email the recipient triggered or needs as part of an existing relationship with you: password resets, sign-in links, receipts, invoices, account and security notices, and product notifications they turned on.
- Marketing email to people who explicitly opted in to receive it from you. A pre-checked box, a purchase, or an address found on a website is not an opt-in. We recommend confirmed (double) opt-in.
Keep a record of how, when, and where each marketing contact opted in, and give it to us if we ask.
03Prohibited
You may not use AgentSend to send, or to help anyone send:
- Unsolicited bulk or commercial email. Marketing or promotional mail to anyone who has not opted in to receive it from you.
- Mail to purchased, rented, traded, scraped, or appended lists. That includes lists from data brokers and lead-generation vendors, "opt-in" lists sold by third parties, co-registration, addresses harvested from websites, and addresses guessed from name patterns.
- Cold outreach at scale. Automated sales prospecting, recruiting, link-building, or partnership sequences to people who have no prior relationship with you, whether a person or an agent writes them. AgentSend is not a cold-email tool.
- Phishing, spoofing, or impersonation. Collecting credentials or payment details under false pretenses, posing as another person, company, or government body, or sending from a domain or address you are not authorized to use.
- Malware. Viruses, ransomware, spyware, or other malicious code, as attachments or as links to sites that host it.
- Deceptive subject lines or headers. Subject lines that misrepresent the message, forged or misleading From, Reply-To, or routing headers, and fake "Re:" or "Fwd:" prefixes.
- Illegal content. Anything illegal where it is sent or received, including fraud, scams, pyramid schemes, infringing material, harassment and threats, and sales of regulated goods without the required licenses. We report child sexual abuse material to the authorities.
- Mail that hides who sent it. Concealing or misrepresenting the sender's identity, using throwaway domains, or spreading volume across domains or accounts to dodge reputation and filtering (snowshoeing).
- Evading suppression or unsubscribes. Re-adding addresses that unsubscribed, bounced, or complained; moving them to another audience, account, or the transactional endpoint to get around suppression; or making unsubscribing hard (asking recipients to sign in, pay, or take more than one step).
- Getting around AgentSend's limits. Opening extra accounts to exceed plan limits or after a suspension, varying content to slip past duplicate and loop detection, or using AgentSend to test which addresses on a list are valid.
04Requirements for every sender
- Verified sending domains you control. Send only from domains you own or are authorized to send for, verified in AgentSend with the SPF, DKIM, and DMARC records we generate. Keep those records in place while you send.
- Accurate sender identity. The From name and address, the Reply-To, and the message itself must accurately identify the business sending it.
- Unsubscribe in every marketing email. Include a visible, working unsubscribe link and a
List-Unsubscribeheader that supports one-click unsubscribe (RFC 8058). AgentSend broadcasts add the headers for you and refuse to send without{{unsubscribe_url}}in the body. If you send marketing mail any other way, you must add both yourself. - Honor unsubscribes immediately. Stop marketing to an address as soon as it unsubscribes, in every system you send from. Legal grace periods (such as CAN-SPAM's 10 business days) do not apply on AgentSend. A broadcast unsubscribe adds the address to your account's marketing suppression list the moment the recipient clicks, so later broadcasts skip it; if you also keep your own list, sync it.
- A physical postal address in marketing email. Every marketing email must include your valid physical postal address: a street address, a registered post office box, or a private mailbox.
- Follow the law. Comply with CAN-SPAM (United States), the GDPR and the ePrivacy rules (European Union; in the UK, the UK GDPR and PECR), CASL (Canada), and the laws of every place your recipients are. That includes getting consent where those laws require it, identifying advertising where required, and keeping proof of consent.
- Keep transactional mail transactional. A transactional email that carries promotional content must meet every marketing requirement above.
- Keep your lists clean. Remove addresses that bounce, and get fresh permission before mailing contacts you haven't emailed in more than 12 months.
- Follow the AWS Acceptable Use Policy. Live mail is delivered through Amazon SES, so your mail must also comply with the AWS Acceptable Use Policy.
05Bounce and complaint limits
We monitor bounce and complaint rates per account, across every domain and API key on it. Keep your bounce rate below 4% and your complaint rate below 0.08% of the email you send. These are limits, not targets: permission-based lists run well under them.
If an account goes over either limit, we may automatically pause its sending, without notice, while we review it. We may also pause an account whose rates are climbing toward a limit. Sending resumes once the cause is fixed, for example after you remove the addresses that bounced or stop the campaign that drew the complaints.
Hard bounces and spam complaints add the address to your account's suppression list automatically, and AgentSend refuses later sends to it.
06Live sending requires review
New accounts send on the sandbox: guardrails, events, webhooks, and suppression all run, and nothing is delivered to real inboxes. To send to real recipients, request live sending in the dashboard and accept the Terms of Service and this policy.
We review every request, including your company, website, use case, expected volume, and sending domain, and we may ask how your recipients opted in, where your lists came from, or for sample content. We decide whether to approve a request, and we may re-review an account or revoke its live access at any time, especially when its volume, content, or bounce and complaint rates change.
07Agents and automation
AgentSend is built for AI agents to operate, and the account holder answers for every send they make. Give agents keys scoped to what they need (sending_access, limited to one domain), set per-key send budgets, and test with dry runs and simulator addresses before you go live.
Guardrails catch common mistakes, but passing them doesn't mean a message complies with this policy or the law. Do not use agents to generate or personalize cold outreach, or to rewrite blocked messages until they pass.
08Enforcement
We investigate suspected violations, which can include reviewing your account's message content, metadata, and sending patterns. If we find or reasonably suspect a violation, we may, without notice:
- block individual sends;
- pause API keys or all sending on the account;
- revoke live sending;
- suspend or terminate the account.
Serious or repeated violations end in termination. We may report illegal activity to law enforcement and share information with Amazon Web Services when that is needed to protect the delivery infrastructure. Fees are not refunded when we suspend or terminate an account for violating this policy.
09Reporting abuse
If you received unwanted or malicious email sent through AgentSend, email abuse@agentsend.co. Include the full message with its headers (in most mail clients, "Show original" or "View source") so we can identify the sending account. We investigate every report.
For anything else, write to hello@agentsend.co.
10Changes to this policy
We may update this policy as the service and the law change. The date at the top of this page shows the latest version. We announce material changes by email or in the dashboard before they take effect, except changes needed to stop abuse or comply with the law, which can take effect immediately.
Also see: Terms of Service · Privacy Policy