The principle
Send mail to people who asked to hear from you, about something they have a relationship with you for. Everything below follows from that, and if a case is not covered, that sentence is the test.
What Posthaste is for
Mail a recipient is expecting as a result of something they did: password resets, sign-in codes, receipts, order and shipping updates, invoices, security alerts, account notifications, and similar.
And operational announcements to your own users, sent as a broadcast to a contact list: outage and incident notices, changes to your terms or privacy policy, release notes about a product they use, and notices about their account. The test is whether the recipient would be worse off for not being told.
Contacts and broadcasts
Every contact you store must be a person who has a relationship with you — they signed up for your product, they are your customer, or they gave you their consent to be contacted before you imported them — and every contact carries a recorded consent source saying which. The consent source is a statement you make to us. Recording one that is not true is a breach of this policy.
Purchased, rented, scraped, harvested, appended or otherwise acquired lists may not be stored as contacts or mailed, under any consent source.
Broadcasts may not be used for marketing: no newsletters, promotions, offers, sales announcements, re-engagement or win-back mail, and no mail whose purpose is to sell rather than to inform. A broadcast that is marketing is a breach even when every recipient is a genuine customer.
Broadcasts are checked as they run. One is stopped automatically when its bounce or complaint rate crosses the platform’s limits, and an account’s first broadcast to more than 1,000 people is reviewed by Posthaste staff before it starts. A broadcast that fails review is canceled without sending.
What is not allowed
Bulk and marketing mail
No newsletters, promotional campaigns, marketing announcements to a list, or re-engagement mail — regardless of whether recipients opted in, and whether sent one message at a time, as a batch or as a broadcast. This is not a judgement about your marketing; it is that bulk mail carries a different complaint profile, and on shared infrastructure one bad list damages placement for every other customer. The operational announcements described above are the only exception.
Lists you did not earn
No purchased, rented, scraped or otherwise acquired lists. No sending to addresses that have not had a direct relationship with you. These are obvious from the bounce pattern within a day.
Deceptive mail
No forged headers, no misleading sender names or subject lines, no impersonating another person or organisation, and no phishing of any kind.
Unlawful or harmful content
Nothing unlawful in the jurisdiction of sender or recipient. No malware. No content that harasses, threatens or promotes violence against anyone. No child sexual abuse material — reported to the authorities without notice, and the only case where we will not tell you first.
Evading controls
No spreading volume across multiple accounts to get around a sending cap, no attempts to avoid suppression, and no re-sending to addresses that hard bounced or complained.
Suppression is not optional
When a receiving server permanently refuses an address, or a recipient marks your mail as spam, we suppress that address for your account immediately. Attempting to send to it again is refused at the API and is a breach of this policy if done systematically.
We do not suppress on temporary failures — those are retried — because suppressing on a transient error would make a working address unreachable forever.
Unsubscribe
Genuinely transactional mail does not need an unsubscribe link, and adding one to a password reset is confusing. But if a recipient asks you to stop sending them something, stop. If they ask us, we will tell you, and we will act if you do not.
Reporting abuse
If mail from our infrastructure is unwanted, deceptive or fraudulent, send it to [email protected] with full headers if you can. The address is monitored by a person, not a filter, and reports are acted on.
Every message we send carries a unique return path, so we can identify precisely which account and which send a report refers to.
What happens when this is breached
In most cases we contact you first, explain what we are seeing and what needs to change. Sending is capped or paused while it is sorted out.
Where the breach is severe — phishing, malware, illegal content, or sending that is actively damaging our IP reputation — we suspend immediately and tell you afterwards. Repeat or deliberate breaches end the account, under section 11 of the terms of service.
We would rather lose your business than have our IP blocklisted, because a blocklisting harms every other customer’s password resets at the same time.
Questions before you send
If you are not sure whether something is in scope, ask at [email protected] before sending it. We would much rather answer that question than have the conversation afterwards.