Quick answer: Run any legitimate service — websites, apps, APIs, VPNs for your own use, game servers, mail in reasonable volumes. Prohibited: port scanning, DDoS participation or "stress testing", spam, phishing, brute-force attacks, open resolvers/amplifiers, IP spoofing and other abuse. Violations lead to suspension, and knowing the line protects your own uptime.

Overview

Cloud2Y is unmanaged hosting: you get root and freedom. That freedom ends where it harms others or the network. Abuse from one IP can get ranges blacklisted, triggers upstream complaints, and pollutes the neighbourhood for every customer — so these rules are enforced, automatically and by hand.

Allowed (a non-exhaustive list)

  • Websites, e-commerce, APIs, databases, dev/staging environments.
  • Game servers, voice servers, personal VPN endpoints, CI runners.
  • Transactional and opt-in mail with proper SPF/DKIM and clean lists.
  • Security research on your own infrastructure.

Prohibited

  1. Attacks: DDoS in any role (attacker, booter/stresser front, controller), brute-forcing third-party services, exploitation attempts.
  2. Scanning: unsolicited port or vulnerability scanning of networks you don't own or lack written permission to test.
  3. Spam & fraud: unsolicited bulk mail, phishing, malware hosting, botnet C2.
  4. Amplifiers: open DNS resolvers, open NTP/memcached/SSDP responders — misconfigurations that others weaponize.
  5. Spoofing: forging source IPs or ARP/neighbour tricks.

Common issues

  • "I was hacked, not malicious" — compromised servers doing abuse get suspended just the same; secure your box and monitor it.
  • Accidental open resolver: installed BIND/dnsmasq listening on the public IP — restrict to localhost or your networks.
  • "Stress testing my own site" from many sources — testing your own service is fine; renting botnets or hitting shared infrastructure is not. When unsure, ask first.

When to contact support

Ask before doing anything borderline (authorized pentests, high-volume mail campaigns, unusual protocols) — a one-line ticket saves a suspension. Received an abuse notice? Respond in the ticket promptly; ignoring it escalates. Full policy: Acceptable Use Policy overview.

Frequently asked questions

Can I run a VPN or game server?

Yes — VPN endpoints for your own use, game servers and voice servers are normal, fully allowed workloads on Cloud2Y VPS, VDS and dedicated servers.

Is port scanning ever allowed?

Only against infrastructure you own or have written permission to test. Unsolicited scanning of third parties is prohibited and triggers abuse complaints.

What happens if my server is hacked and sends abuse?

It gets suspended just like an intentionally abusive one — you are responsible for securing your server. Respond to abuse tickets promptly.

Related articles

Need a hand? Contact Cloud2Y support →

Was this answer helpful? 0 Users Found This Useful (0 Votes)