This Anti-Spam Policy ("Policy") applies to all email delivery and SMTP Services provided by Layer 9 Solutions Ltd.
It applies to:
- Shared SMTP Customers;
- Dedicated SMTP Customers;
- White-Label and Reseller Customers;
- Downstream Customers; and
- every person, application, or system transmitting email through the Service.
A breach of this Policy is a breach of the Layer 9 Solutions SMTP Service Terms of Use.
1. Purpose
Layer 9 Solutions does not permit abusive email activity.
This Policy exists to:
- prevent spam;
- protect recipients;
- prevent phishing and fraud;
- maintain network and IP reputation;
- protect legitimate Customers;
- maintain reliable email infrastructure; and
- promote compliance with applicable electronic-marketing and data-protection law.
Customers remain responsible for determining which laws apply to their sending activity.
Compliance with this Policy does not itself guarantee legal compliance.
2. Layer 9 Solutions May Apply Stricter Standards
Layer 9 Solutions may impose anti-abuse requirements that are stricter than the minimum permitted by law.
A sending practice being technically lawful does not automatically mean Layer 9 Solutions must permit it on the Service.
This is particularly important for high-risk mailing lists and practices likely to damage network or sender reputation.
3. Spam
For this Policy, "Spam" includes email that is:
- sent contrary to applicable electronic-marketing law;
- sent using mailing lists prohibited by this Policy;
- materially deceptive as to sender, origin, or purpose;
- sent after an applicable opt-out;
- sent in a manner likely to generate unreasonable complaints;
- sent without a legitimate explanation for why recipients are being contacted;
- sent to large quantities of invalid recipients;
- used to facilitate fraud, phishing, or abuse; or
- otherwise reasonably considered abusive.
4. Transactional Email
Legitimate transactional and operational messages are permitted.
Examples include:
- password resets;
- invoices;
- receipts;
- order confirmations;
- booking confirmations;
- account alerts;
- security notifications;
- support communications;
- service notifications; and
- application-generated operational email.
A message described as "transactional" must not be used primarily as a disguise for unsolicited marketing.
5. Marketing Email
Marketing email is permitted only where the sender:
- is legally permitted to send the communication;
- has an appropriate lawful basis for any personal-data processing;
- satisfies any consent or soft-opt-in requirement that applies;
- accurately identifies the sender;
- provides an appropriate means to opt out;
- respects previous objections and suppression records; and
- complies with this Policy.
Different rules may apply depending on the type of recipient and jurisdiction.
Customers are responsible for correctly determining the status of their recipients.
6. Corporate and Individual Recipients
UK electronic-marketing law distinguishes between individual subscribers and corporate subscribers.
Customers must apply the appropriate legal requirements to each type of recipient.
Regardless of whether prior consent is legally required for a particular corporate recipient, Layer 9 Solutions requires marketing senders to:
- accurately identify themselves;
- provide a functional opt-out mechanism;
- respect opt-out requests;
- maintain appropriate suppression records; and
- avoid indiscriminate or abusive bulk sending.
7. Purchased, Rented and Third-Party Lists
As a Layer 9 Solutions service policy, you must not use:
- purchased email lists;
- rented email lists;
- leased email lists;
- scraped lists;
- harvested addresses;
- automatically generated address lists;
- addresses copied from websites or directories for bulk campaigns;
- email-appended lists;
- third-party lead databases for unsolicited bulk campaigns; or
- lists where you cannot reasonably demonstrate their legitimate origin.
This prohibition applies even where a list supplier claims that its data is "opt-in", "verified", "GDPR compliant", "clean", or legally marketable.
Layer 9 Solutions deliberately operates a stricter policy because third-party list sending creates substantial abuse and reputation risk.
8. List Provenance
You must be able to explain, where reasonably requested:
- how recipients were obtained;
- when the data was obtained;
- by whom it was obtained;
- why the recipient is being contacted;
- what privacy information was supplied;
- the legal or relationship basis relied upon; and
- how opt-outs are managed.
A failure to provide a credible explanation may result in suspension of the affected campaign or Account.
9. Consent and Soft Opt-In
Where applicable law requires consent, you must be able to demonstrate valid consent.
Where you rely on a legally recognised soft opt-in or another exception, you are responsible for ensuring all applicable requirements are satisfied.
Layer 9 Solutions may request reasonable evidence of the basis relied upon.
10. Unsubscribe and Opt-Out
All marketing email transmitted through the Service must include a clear, functional means for recipients to stop further marketing messages.
The opt-out process must:
- be clearly identifiable;
- be reasonably easy to use;
- not be deceptive;
- not require payment; and
- not impose unnecessary barriers.
Where applicable law or a material receiving network requires one-click or another specific unsubscribe mechanism, the Customer must comply with that requirement.
Opt-out requests must be honoured promptly and within any applicable legal deadline.
11. Suppression Lists
Customers must maintain appropriate suppression records for recipients who:
- unsubscribe;
- object to direct marketing;
- make a valid spam complaint;
- permanently fail delivery where continued sending would be inappropriate; or
- otherwise must no longer receive marketing.
Suppression information may be retained where reasonably necessary to ensure that an opted-out recipient is not accidentally re-added.
A suppression list must not be used as a new marketing list.
12. Stale and Inactive Lists
Customers must maintain reasonable mailing-list hygiene.
Long periods without engagement can indicate that a list is stale or no longer suitable.
Layer 9 Solutions may require a Customer to:
- revalidate a materially stale list;
- reduce sending volume;
- remove inactive recipients; or
- demonstrate the continuing basis for sending.
As an operational risk indicator, Layer 9 Solutions may treat marketing recipients with no meaningful engagement or relationship for approximately 24 months or more as higher risk.
This is an anti-abuse guideline and does not represent a universal legal expiry period for consent.
13. Bounce Management
Customers must monitor delivery failures and stop repeatedly sending to addresses known to:
- not exist;
- be invalid;
- be permanently disabled; or
- generate persistent hard bounces.
High levels of invalid-recipient activity may result in throttling, investigation, or suspension.
14. Complaint Management
Customers must monitor and appropriately respond to complaints.
Layer 9 Solutions may investigate where sending creates excessive:
- spam complaints;
- hard bounces;
- unsubscribes;
- blocklist events;
- abuse reports; or
- other negative reputation signals.
Layer 9 Solutions is not required to wait until a fixed numerical threshold is reached before acting.
Where appropriate, current complaint or reputation thresholds may be communicated separately.
15. Sender Identity
Email must not contain materially false or misleading:
- sender names;
- From addresses;
- Reply-To addresses;
- subject lines;
- sender domains;
- routing information; or
- other identity information.
You must not impersonate another person, company, government body, financial institution, or organisation without lawful authority.
16. Domains and Authentication
You may only send using domains that you own, control, or are authorised to use.
Layer 9 Solutions may require proof of control.
Customers must configure and maintain reasonable sender-authentication and DNS controls required for legitimate sending.
Authentication must not be deliberately configured to conceal abuse or evade enforcement.
17. Prohibited Abuse
The Service must not be used for:
- phishing;
- credential theft;
- malware;
- ransomware;
- identity theft;
- fraudulent invoices;
- advance-fee fraud;
- lottery scams;
- fake investment schemes;
- malicious attachments;
- malicious links;
- deceptive impersonation;
- unlawful threats or harassment;
- child sexual exploitation or abuse;
- unlawful content; or
- communications intended to facilitate criminal activity.
18. List Bombing and Address Enumeration
You must not:
- subscribe third parties to mailing lists without authority;
- intentionally trigger large quantities of email to another person;
- use the Service for list bombing;
- systematically guess or enumerate recipient addresses; or
- deliberately probe recipient systems to build mailing lists.
19. Evasion
You must not evade this Policy by:
- creating replacement Accounts following suspension;
- rotating sending domains;
- rotating IP addresses;
- changing sender identities;
- splitting prohibited activity between Services;
- routing prohibited campaigns through Downstream Customers;
- altering content specifically to defeat abuse controls; or
- using another technical mechanism intended to conceal abusive activity.
Evasion may result in termination of related Services.
20. Dedicated Services
Dedicated infrastructure and dedicated IP addresses remain fully subject to this Policy.
"Dedicated" does not mean unrestricted sending.
Layer 9 Solutions may apply reasonable:
- IP warm-up requirements;
- temporary rate limits;
- recipient restrictions;
- domain restrictions;
- additional verification; or
- other reputation-protection measures.
Allocation of a dedicated IP does not transfer ownership of that IP.
21. Credential Compromise
If Service credentials are compromised, the Customer must promptly:
- stop or restrict unauthorised sending;
- rotate affected credentials;
- investigate the compromise;
- notify Layer 9 Solutions where material abuse occurred; and
- take reasonable steps to prevent recurrence.
Layer 9 Solutions may immediately disable compromised credentials.
A genuine compromise will be considered when deciding enforcement action, but does not require Layer 9 Solutions to allow abusive sending to continue.
22. White-Label and Reseller Customers
White-Label Customers must:
- impose anti-spam terms on Downstream Customers that are at least as protective as this Policy;
- provide an appropriate abuse-reporting process;
- maintain sufficient records to identify responsible Downstream Customers;
- carry out reasonable risk checks;
- respond promptly to Layer 9 Solutions abuse reports;
- investigate suspected abuse;
- suspend offending Downstream Customers where reasonably necessary;
- prevent suspended Downstream Customers from immediately recreating equivalent Services to evade enforcement; and
- reasonably cooperate with Layer 9 Solutions investigations.
Layer 9 Solutions may restrict:
- a credential;
- sending identity;
- domain;
- IP address;
- Downstream Customer;
- individual Service; or
- entire reseller environment
where reasonably necessary to stop serious abuse or protect infrastructure.
23. Monitoring
Layer 9 Solutions may use relevant operational information to identify abuse, including:
- sending volume;
- sending velocity;
- bounce information;
- complaints;
- recipient responses;
- authentication events;
- sender domains;
- blocklist reports;
- IP reputation indicators; and
- abuse reports.
Where reasonably necessary and permitted by law, an investigation may include review of relevant message information.
24. Investigations
Layer 9 Solutions may request information including:
- campaign purpose;
- mailing-list origin;
- recipient-acquisition method;
- consent evidence;
- other legal basis relied upon;
- unsubscribe records;
- domain ownership;
- identity information;
- complaint information; and
- Downstream Customer information.
Customers must reasonably cooperate.
Failure to provide sufficient information may result in continued restriction or suspension.
25. Suspension
Layer 9 Solutions may immediately suspend or restrict sending where it reasonably believes:
- spam is being sent;
- phishing or fraud is occurring;
- credentials are compromised;
- sender reputation is at serious risk;
- complaints or invalid-recipient levels are excessive;
- prohibited lists are being used;
- enforcement controls are being evaded;
- unlawful activity is involved; or
- immediate action is necessary to protect recipients, Customers, infrastructure, or networks.
Potentially harmful sending does not have to remain active while an investigation occurs.
26. Remediation
Where appropriate, Layer 9 Solutions may permit remediation instead of termination.
Remediation may include:
- list cleaning;
- removing invalid recipients;
- implementing suppression;
- improving authentication;
- reducing sending rates;
- revalidating recipients;
- completing an IP warm-up process; or
- demonstrating a legitimate sending basis.
Offering remediation in one case does not require it to be offered in another.
27. Termination
Serious or repeated violations may result in termination.
Immediate termination may be appropriate for:
- deliberate spam;
- deliberate use of purchased or harvested lists;
- phishing;
- malware distribution;
- deliberate fraud;
- deliberate evasion;
- serious unlawful activity; or
- knowingly permitting repeated abuse by Downstream Customers.
Services terminated for serious abuse are not eligible for refunds except where required by law.
28. Applicable Law
Customers must comply with all laws applicable to their sending activity and recipients.
Depending on circumstances, this may include:
- UK GDPR;
- the Data Protection Act 2018;
- the Privacy and Electronic Communications Regulations 2003, as amended;
- other applicable UK electronic-marketing legislation;
- applicable EU privacy or electronic-marketing requirements;
- the US CAN-SPAM Act where applicable; and
- equivalent requirements in other jurisdictions.
This list is not exhaustive.
29. Reporting Abuse
Suspected abuse involving Layer 9 Solutions should be reported to:
[email protected]
Where possible, include:
- full email headers;
- sender information;
- date and time;
- relevant message evidence; and
- any other information that may assist investigation.
30. Changes to this Policy
Layer 9 Solutions may update this Policy in response to:
- changes in law;
- changes in industry requirements;
- abuse trends;
- receiving-network requirements;
- security risks; or
- operational requirements.
Material changes affecting existing Customers will normally be communicated in advance.