Quick answer: Cloud2Y prohibits unsolicited bulk email in any form — bought lists, harvested addresses, spamvertised sites and open relays all violate the policy. Legitimate opt-in mailing (transactional mail, subscribed newsletters) is acceptable when properly configured. Binding terms are in the official Terms of Service.
Overview
Spam is the fastest way to destroy an IP range's reputation, which hurts every customer sharing the network — that is why enforcement is strict. The policy covers email sent from your server, email advertising a site hosted on your server (spamvertising), and messaging abuse on other channels (SMS gateways, messengers, forum bots).
Before you start
- Mailing lists must be opt-in: every recipient asked to receive your mail, with working unsubscribe.
- Configure the technical basics before bulk sending: SPF, DKIM, DMARC and a matching PTR record — see email sending limits and abuse policy.
- Never run an open relay or an unauthenticated submission port.
Step-by-step guide
To stay compliant while sending legitimate mail:
- Collect addresses with explicit consent and keep proof (signup source, timestamp).
- Authenticate your mail (SPF, DKIM, DMARC) and set a valid PTR for the sending IP.
- Include a working unsubscribe mechanism and honour it promptly.
- Watch bounce rates and spam complaints; clean your list continuously.
- For genuinely large volumes, describe your use case to support first — some setups are better served by a specialised ESP.
Common issues
- Compromised CMS sending spam: outdated plugins with mail scripts are a classic source — the report still lands on your service, so patch and monitor.
- "I bought a verified list": purchased lists are unsolicited by definition and violate the policy.
- Blacklisted IP: spam from your server can get the IP listed; cleanup requires fixing the cause first, then delisting.
When to contact support
Open a ticket before starting large-scale legitimate mailing, if your IP appears on a blocklist, or if you suspect your server sends mail you did not authorise.
Frequently asked questions
What makes an email campaign count as spam?
Recipients who never opted in. Bought, rented or harvested lists are unsolicited by definition, while confirmed subscribers with working unsubscribe make a campaign legitimate.
My server sent spam because of a hacked plugin. Am I in trouble?
The report still lands on your service, so you must patch the site, remove the mail scripts and reply in the ticket. Handled quickly and honestly, such cases end without suspension.
Do I need SPF, DKIM and DMARC before sending bulk mail?
Yes. Authentication plus a matching PTR record is the technical baseline for deliverability and shows mail providers your sending is legitimate rather than botnet traffic.
Related articles
- Email sending limits and abuse policy
- Prohibited activities
- Abuse handling policy
- Acceptable Use Policy overview
Need a hand? Contact Cloud2Y support →
