Trust

Anti-spam policy

Deliverability is a shared resource. These rules exist so one sender cannot spend everyone else's inbox reputation.

Permission-based sending only

You may only send to people who gave you permission to email them. In practice that means someone signed up, bought something, or otherwise asked to hear from you, and you can show when and how.

Purchased, rented, scraped, or appended lists are not allowed. Not as a one-off, not "just to test", and not if the vendor told you the list was opted in. Uploading one is grounds for immediate suspension.

Account review before you send

Every account is reviewed by a person before it can send. We ask what you are sending, to whom, and how they joined your list. This is the main reason the private beta onboards in small batches rather than opening public signup.

One-click unsubscribe on all marketing email

Every marketing message carries a working unsubscribe link and the List-Unsubscribe headers that let a mailbox provider offer one-click opt-out in its own interface. You cannot turn this off.

An unsubscribe applies across your entire workspace, not just the sequence it came from. Someone who opts out stays opted out even if a later import re-adds their address.

Genuinely transactional email, such as a password reset or a receipt, is exempt, because an unsubscribe link on a password reset is not a feature. Do not use a transactional send to deliver marketing.

Complaint and bounce thresholds

We monitor spam complaints and hard bounces per account and enforce thresholds on them. Sustained rates above what mailbox providers tolerate will get your sending paused while we work out what happened.

A pause is not a punishment. A sending reputation takes months to build and days to destroy, and once it is gone it is gone for everyone sharing the infrastructure.

What you may not send

  • Anything to a list you did not build yourself with consent.
  • Content that misrepresents who the sender is, including forged headers or a misleading From address.
  • Deceptive subject lines that do not match the message.
  • Malware, phishing, or links to either, whether or not you knew.
  • Anything illegal where you are, where we are, or where the recipient is.

How we enforce this

We would rather fix a problem with you than close your account. In most cases the first step is a conversation. Where the risk to other senders is immediate, such as a purchased list or an active phishing campaign, we suspend first and talk afterwards.

Reporting abuse

If you received email through SendHeron that you did not ask for, tell us at [email protected]. Include the full message with headers if you can. We investigate every report.

See also the GDPR and data residency page for how contact data is stored and processed, and the terms of service.