Acceptable Use Policy
Last updated: April 7, 2026
1. Purpose
This Acceptable Use Policy ("AUP") defines the rules for using Meridix email services. It applies to all users, organizations, and API consumers. Violations may result in immediate suspension or termination.
2. Prohibited Content
You may not use Meridix to send, store, or process:
- Spam — unsolicited bulk email, purchased mailing lists, or messages sent without clear opt-in consent
- Malware — viruses, trojans, ransomware, or any malicious software
- Phishing — messages designed to deceive recipients into revealing credentials or personal information
- Fraud — scams, impersonation, or misrepresentation of identity
- Illegal content — anything violating applicable laws including CSAM, incitement to violence, or harassment
- Deceptive headers — forged sender addresses, misleading subject lines, or manipulated DKIM/SPF records
3. Email Sending Rules
Consent
All marketing and bulk email must be sent only to recipients who have explicitly opted in. You must maintain proof of consent and honor unsubscribe requests within 24 hours.
Identification
All messages must accurately identify the sender. You must include a valid physical mailing address or registered business address in bulk email as required by CAN-SPAM, GDPR, and CASL.
Unsubscribe
All bulk email must include a working one-click unsubscribe mechanism (RFC 8058). Meridix provides this automatically for messages sent via the API.
4. Rate Limits and Quotas
Each organization has a monthly sending quota based on their plan. Exceeding your quota will result in queued messages until the next billing cycle. Attempting to bypass rate limits, quotas, or throttling mechanisms is a violation of this policy.
5. Relay and IP Warming
Meridix operates a relay fleet for outbound email delivery. You agree not to:
- Send high volumes through new relay IPs without following the warming schedule
- Deliberately trigger bounces or spam complaints to damage IP reputation
- Use Meridix relay infrastructure to relay email for third parties
6. API Usage
- API keys must be kept confidential and not shared or embedded in client-side code
- Automated systems must respect rate limit headers (429 responses) and implement exponential backoff
- The MCP server interface must not be used to grant unauthorized access to mailbox data
7. Security
You must not:
- Attempt to access another user's data, mailbox, or organization
- Probe, scan, or test vulnerabilities without authorization
- Interfere with the service's availability or performance for other users
- Circumvent authentication, encryption, or access controls
8. Abuse Reporting
To report abuse, phishing, or spam originating from Meridix, email [email protected]. Include the full email headers and any relevant evidence. We investigate all reports within 24 hours.
9. Enforcement
Violations are handled as follows:
- First offense — warning and 24-hour sending suspension
- Repeat offense — 7-day suspension and review
- Severe violation — immediate account termination without refund
We reserve the right to suspend any account without notice if it poses an immediate threat to our infrastructure, IP reputation, or other users.
10. Contact
Questions about this policy: [email protected]
General support: [email protected]