Acceptable use policy
This policy protects our address space, other networks and you. It applies to everyone who uses an address we provide, including your own customers and end users. Breaking it can lead to suspension.
1. What you must not do
You must not use Penduses to:
- Send spam. No unsolicited bulk or commercial email, and no email sent without a working way to opt out.
- Scan. No port scans, vulnerability scans or network mapping of systems you do not own or do not have written permission to test.
- Attack accounts. No credential stuffing, password spraying or brute-force login attempts.
- Attack availability. No DDoS, flooding, amplification or reflection, and no hosting of stresser or booter services.
- Scrape against the rules. No scraping of websites or APIs in violation of their terms, robots rules or rate limits.
- Resell the service. No reselling or sublicensing of static egress or IP Tunnel, and no running a proxy or VPN service for third parties with our addresses.
- Run open relays. No open, public or anonymous proxies, relays or VPN exits.
- Run bulletproof hosting. No hosting, proxy or connectivity service that is built to ignore abuse reports, or to shield abusive content or operators from takedown, complaints or law enforcement.
- Host or distribute illegal content. This includes child sexual abuse material, malware, phishing, fraud, stolen data and content that infringes others’ rights or is illegal where we operate (France and Germany) or where you are.
- Evade bans and limits. No use of our addresses to get around a ban, block or rate limit that someone has placed on you or your users, to create fake or duplicate accounts, or to bypass geographic restrictions or paywalls in breach of a site’s terms.
- Misrepresent our addresses. Do not present our datacenter addresses to others as residential or mobile connections.
- Reach internal networks. No attempts to reach internal RFC 1918 ranges, loopback or cloud-metadata addresses through our proxy or tunnel, or to get around the destination allowlist.
- Break sanctions rules. No use by, or for the benefit of, persons or places that EU or other applicable sanctions law prohibits us from serving.
- Forge or hijack. No IP spoofing, and no use of address space that was not assigned to you.
- Run botnets. No command-and-control servers for malware or botnets.
- Attack us or share access. Do not interfere with our systems, or share your credentials or WireGuard configuration with people outside your organisation.
2. Email and port 25
Port 25 is closed by default. We open it after verification for legitimate mail, which means a proper sending hostname, matching rDNS and a real opt-out process. We may close it again if it is misused.
3. Hosting providers
If you assign our addresses to your own customers, you are responsible for their conduct. You must have your own acceptable use policy, act on abuse reports quickly, and be able to tell us which customer used an address at a given time when we ask about an abuse report. You may not resell static egress or IP Tunnel access itself.
4. Verification (know your customer)
We may ask you to verify your identity, your business and what you will use the service for. We may ask before we start a service, before we open port 25 or an open destination mode, or when we see a risk. We may refuse, suspend or end the service if you do not complete a verification, or if the answers do not match how the service is used.
5. How we enforce this policy
- Suspend first. If we see or receive credible evidence of a breach, we may suspend the affected service immediately and explain afterwards.
- 24-hour response target. We aim to review every abuse report within 24 hours of receiving it. The pilot is best effort, so this is a target and not a promise.
- IP quarantine. An address linked to abuse can be taken out of service and held back for a cooling-off period before it is used again. We may move you to a different address.
- Blocking. We may block ports, destinations or traffic patterns that harm other networks.
- Termination. For serious or repeated breaches we may terminate the service, without a refund for the current period.
- Sharing information. We may share the minimum needed with affected parties, and with authorities when the law requires it or to stop abuse.
6. Reporting abuse
Send abuse reports to abuse@penduses.com. The abuse page explains what to include.
7. Changes
We may update this policy. We will email active customers about material changes before they apply to you.