Formpost
Log in

Legal

Acceptable Use Policy

Last updated 6 August 202610 sections

Deliverability is shared. Every form on Formpost sends from the same infrastructure, so one account sending junk makes mail slower to arrive for everybody else. This page is the line between the two.

01Why this exists

Formpost delivers mail on your behalf. That means your forms and our reputation share the same envelope: a form used to send junk damages the delivery rate of every other customer on the platform, including the ones doing everything right.

This policy sets out what may pass through the service. It applies alongside the Terms of Service and the Privacy Policy, and using the service means accepting it.

02What the service is for

Forms on sites you control, filled in by people who chose to contact you. Specifically:

  • Collecting messages from visitors who deliberately submitted them — contact forms, job applications, support requests, feedback.
  • Delivering those messages to addresses you own, and to webhooks or chat channels you configured.
  • Sending an automatic acknowledgement back to the person who filled in the form, because they are expecting one.

03What it is not for

The endpoint accepts a submission and sends an email. That makes it useful to people who want to send email they should not be sending. None of the following is permitted:

  • Bulk or unsolicited mail of any kind. This is not a mailing tool, and a form is not a mailing list.
  • Delivering to addresses you do not own or have not verified on your account. This is enforced technically as well as contractually.
  • Impersonating a person, company or brand, or asking people for credentials, card numbers or identity documents under a false name.
  • Distributing malware, or links whose purpose is to compromise the recipient.
  • Harassment — threatening, abusive or discriminatory material aimed at a person or a group.
  • Anything unlawful where you are, where your visitors are, or where we operate.
  • Deliberately degrading the service: circumventing rate limits, running load tests against the endpoint without asking, or probing for vulnerabilities without permission.

04Content we will not carry

Regardless of consent, we do not deliver forms whose purpose is any of the following. This list exists because mail providers treat these categories as spam signals, and one account can move the reputation of the whole platform.

  • Sexually explicit material, escort or adult services.
  • Gambling, betting tips and casinos.
  • Prescription drugs, controlled substances, and unlicensed health products.
  • Multi-level marketing, pyramid and matrix schemes.
  • Get-rich-quick offers, forex and crypto signal services, and anything promising guaranteed returns.
  • Credit repair, debt elimination and payday lending.
  • Sale or rental of contact lists, and scraped or purchased leads.
  • Purchased engagement — followers, likes, reviews, installs.

06One account per person or organisation

Do not open extra accounts to get around plan limits, rate limits or a suspension. If the free plan is not enough, the paid plans exist for exactly that; if you need something the plans do not cover, ask.

07What you need to protect, and what you do not

A form's endpoint is public by design — it sits in the HTML of your page and anyone can read it. It is not a credential, and there is no need to hide it. What it can do is bounded: deliver mail to the one address that form was set up for. If you want to stop other sites posting to it, turn on domain locking.

Two things are credentials and must be protected: your account password, and the API key that reads your submissions. The API key grants read access to every submission on the account — keep it server-side and rotate it if you think it has leaked. We are not responsible for what happens through credentials you have exposed.

Public by designKeep it secret
What it isThe form ID in your page's HTMLYour password, and the API key that reads submissions
What it can doDeliver a message to the one address that form was set up forRead every submission on the account, or sign in as you
If it leaksTurn on domain locking; nothing to rotateRotate it immediately

If an API key has ever been pasted into client-side code, treat it as leaked and rotate it — anything in the browser is readable by anyone who opens the page.

08How this is enforced

We watch delivery patterns rather than read your mail. Spikes in bounces, complaints or blocked recipients are what surface a problem, and they usually surface it before you notice.

Depending on severity we may throttle a form, disable it, or suspend the account. Where the situation allows, we tell you what we found and give you a chance to fix it first — an account that is compromised or misconfigured is a different thing from one that is deliberately abusing the service, and we try to treat them differently. Serious cases are actioned immediately and may be reported to the relevant authorities.

Submissions blocked by your own spam settings are not a policy problem and never count against you.

What we seeWhat usually happens
Bounces or complaints climbing on one formWe throttle that form and write to you
A report through /report-abuseA person reads it and looks at the form behind it
Phishing, malware or impersonation, confirmedThe form is disabled the same day
Deliberate or repeated abuseThe account is suspended, and reported where the law requires

09Reporting a violation

If you have received something abusive that came through Formpost, or you have found a form using the service for any of the above, report it at /report-abuse. Reports are read by a person.

10Changes

This policy will change as the service does. Material changes are announced by email to account holders, and the date at the top of this page always reflects the current version.