Legal & compliance
Anti-Spam Policy for Permission-Based Email Campaigns
This Anti-Spam Policy explains how Secuno LLC ("MailFleet," "we," "us") expects customers to use MailFleet desktop email campaign software. MailFleet is built for legitimate, permission-based business communication — not unsolicited mail, list harvesting, or deceptive sending practices.
MailFleet Anti-Spam Policy (Secuno LLC): MailFleet desktop email campaign software is designed exclusively for permission-based sending. Users must obtain appropriate consent, maintain list hygiene, honor unsubscribes, authenticate sending domains (SPF, DKIM, DMARC), and comply with CAN-SPAM, GDPR, CASL, and local regulations. Unsolicited bulk email, list scraping, and deceptive practices are prohibited.
At a glance
- What it is
- A comprehensive anti-spam and compliance policy governing use of MailFleet desktop email campaign software.
- Who it is for
- MailFleet license holders, agencies, SaaS teams, newsletter operators, and enterprise procurement reviewers.
- Main capabilities
- Consent requirements, list hygiene rules, authentication guidance, unsubscribe standards, regulatory references, abuse reporting, and MailFleet product controls that support responsible sending.
- Platforms
- Applies to all MailFleet deployments on Windows, macOS, and Linux.
- Responsible use
- Permission-based campaigns with documented consent, transparent sender identity, and continuous suppression management — never unsolicited mail or harvested addresses.
Key takeaways
- Send only to recipients with valid consent or another lawful basis documented by your organization.
- Never use purchased, scraped, rented-without-consent, or harvested email lists.
- Include accurate sender identity, physical address where required, and a working unsubscribe mechanism in marketing mail.
- Maintain suppression lists for unsubscribes, complaints, and hard bounces before every campaign.
- Authenticate domains with SPF, DKIM, and DMARC; run pre-send checks before increasing volume.
- Comply with CAN-SPAM, GDPR, CASL, ePrivacy, and all laws applicable to your recipients and business.
- Report abuse involving MailFleet to the address listed in this policy; we may suspend violating licenses.
What is permission-based email?
Permission-based email means every marketing or bulk message reaches a recipient who has agreed to hear from you, has an existing relationship your counsel recognizes as lawful, or falls under another valid legal basis in their jurisdiction. Permission is not assumed because someone visited your website, appeared on a conference attendee sheet, or matched a demographic profile. It is documented, specific, and tied to a clear expectation of what you will send and how often.
MailFleet is professional desktop email campaign software. It gives operators direct control over templates, SMTP and API providers, proxies, SpamAssassin checks, sending capacity scoring, webhooks, and detailed local logs. That control comes with responsibility: the software does not replace your legal obligations, and it is not designed to bypass mailbox provider rules or anti-spam law.
Organizations that treat permission as a operational discipline — not a checkbox — build durable sender reputation, lower complaint rates, and stronger client relationships. This policy describes the minimum standards MailFleet expects and the practices we recommend for sustainable campaign operations.
MailFleet commitment to anti-spam practices
Secuno LLC develops MailFleet for teams who send email through their own providers under their own brands. We do not operate a shared SMTP pool, resell contact data, or encourage high-risk list sources. Our product roadmap prioritizes visibility (logs, reports, diagnostics), pre-send preparation (authentication checks, content scoring), and operational controls (suppression workflows, provider profiles) that support compliant sending.
We publish this Anti-Spam Policy, our Acceptable Use Policy, Privacy Policy, and Terms of Service so customers, partners, and enterprise reviewers can evaluate MailFleet honestly. We do not claim certifications we have not earned. When procurement teams ask security or compliance questions, we answer with accurate documentation rather than marketing exaggeration.
When we learn that a license is used for unsolicited mail, phishing, malware distribution, list harvesting, or deliberate deception, we may warn, suspend, or terminate access. Abuse reports should include headers, timestamps, and samples when available so we can investigate efficiently.
Scope of this policy
This policy applies to anyone who installs, licenses, or uses MailFleet, including agencies sending on behalf of clients, internal IT teams, and consultants managing campaigns for multiple brands. If you configure MailFleet for another organization, you remain responsible for ensuring their lists, content, and compliance practices meet this policy and applicable law.
MailFleet sends mail through SMTP and API providers you configure. Provider terms, rate limits, and abuse policies apply in addition to MailFleet rules. A message that violates Gmail, Microsoft, Amazon SES, SendGrid, or another provider policy may be blocked even if it complies with MailFleet settings.
This document is not legal advice. Requirements vary by country, industry, and recipient type (consumer vs. business). Consult qualified counsel for jurisdiction-specific obligations. This policy states MailFleet expectations and industry-recognized responsible practices.
- Applies to all MailFleet desktop installations and license holders.
- Covers marketing, newsletter, transactional-adjacent bulk, and operational mail sent through MailFleet.
- Works alongside the Acceptable Use Policy, Terms of Service, and Privacy Policy.
- Does not override stricter contractual obligations you accept with clients or providers.
Consent and lawful contact requirements
Explicit opt-in is the strongest foundation for marketing email. A recipient actively subscribes through a clear form, confirms via double opt-in where appropriate, or otherwise takes an affirmative action that shows they want your messages. Record the source, timestamp, IP address or form identifier, and the wording shown at signup. These records protect you during audits, client reviews, and complaint investigations.
Some jurisdictions allow email to existing customers or parties with a relevant business relationship, subject to notice, opt-out, and purpose limitations. If you rely on this model, document the relationship, the products or services involved, and the legal basis your counsel approves. Do not stretch "existing relationship" to cover cold prospects or years-old contacts who never opted in to marketing.
Cold email to purchased lists, LinkedIn exports without consent, scraped directories, and "one-click unsubscribe from a list you never joined" are incompatible with MailFleet. If you cannot prove permission for an address, do not import it into MailFleet.
- Document how and when each contact opted in or otherwise lawfully entered your list.
- Separate marketing consent from purely transactional communication where regulations require it.
- Honor regional rules: EU/UK GDPR and ePrivacy, Canada CASL, US CAN-SPAM, and local equivalents.
- Re-confirm consent after long inactivity if your counsel or industry practice requires it.
Prohibited sending practices
The following practices are prohibited when using MailFleet, regardless of jurisdiction. They expose recipients to harm, damage shared sending infrastructure, and violate the purpose for which MailFleet was built.
Attempts to hide true sender identity, forge headers, use misleading subject lines, or impersonate brands, government agencies, or individuals are forbidden. So are phishing, credential harvesting, malware attachments, illegal goods promotion, harassment, threats, and content that violates applicable criminal or civil law.
Using MailFleet to test filter evasion, rotate through deceptive domains solely to avoid blocks, or automate unsolicited outreach at scale is prohibited. MailFleet includes proxy and provider management for legitimate operational reasons — such as organizing client infrastructure or routing through approved endpoints — not for abuse.
- Unsolicited bulk email (spam) to recipients without permission or lawful basis.
- Purchased, rented-without-consent, scraped, or harvested address lists.
- Dictionary attacks, address harvesting from websites, or forum scraping.
- Deceptive subjects, hidden identities, or forged routing information.
- Phishing, malware, fraud, or illegal content.
- Circumventing provider suspension, law enforcement requests, or court orders.
- Sending on behalf of third parties without authority and compliance oversight.
List hygiene and data quality
A permission-based list degrades without maintenance. People change jobs, abandon mailboxes, report mail as spam, or withdraw consent. Sending to stale or unengaged addresses increases bounces, traps, and complaints — signals mailbox providers use to throttle or block your domain.
Before each campaign, validate that imported segments respect suppressions. Remove role accounts (info@, admin@) unless you have a documented B2B reason and legal basis. Segment by engagement and sunset contacts who have not opened or clicked within periods your policy defines, after any legally required notice.
Hard bounces should be suppressed immediately. Soft bounces should be retried per your operational playbook, then suppressed if they persist. Repeated sends to known bad addresses suggest poor list hygiene and may trigger provider enforcement.
- Maintain a global suppression list across clients and brands where your workflow allows.
- Deduplicate addresses before import; avoid sending duplicate messages in the same batch.
- Track list source and age; retire sources with high complaint or unknown consent history.
- Use MailFleet logs and reports to identify recurring bounce patterns before they scale.
Sender identity and transparency
Recipients and mailbox providers must be able to identify who sent a message. Marketing email should display a recognizable From name and address aligned with your brand or your client's authorized brand. "Re:" or "Fwd:" prefixes in subjects to simulate personal threads, fake local personas, or random sender rotations intended to confuse filters violate this policy.
CAN-SPAM requires a valid physical postal address in many commercial messages to US recipients. Other regions impose similar identification duties. Include your organization name, a contact method, and links to privacy notices where appropriate.
When agencies send for clients, the visible sender should reflect the client relationship truthfully. Subdomains and dedicated sending domains are preferable to unrelated domains that confuse recipients about who controls the communication.
- Use From names and domains recipients will recognize.
- Align Reply-To and envelope sender with your operational setup where providers require it.
- Include physical address and contact details when law or best practice demands it.
- Avoid misleading subject lines that promise unrelated content to increase opens.
Unsubscribe, opt-out, and suppression management
Every marketing message must include a clear, functional way to stop future marketing email. One-click unsubscribe (RFC 8058) is increasingly expected by major providers. Process opt-out requests promptly — CAN-SPAM mandates honoring within 10 business days; many organizations aim for near-real-time suppression.
Unsubscribe must not require login, payment, or unrelated surveys. You may offer preference centers, but the baseline opt-out path must remain simple. Suppressed addresses must not re-enter marketing sends through list merges, A/B test pools, or "re-engagement" batches without fresh lawful consent.
MailFleet operators should export suppression data regularly and store it in durable systems. Webhooks and local logs can help confirm that provider-side complaints map back to internal suppressions. Treat spam complaints as seriously as explicit unsubscribes.
- Include visible unsubscribe links or List-Unsubscribe headers in marketing mail.
- Suppress unsubscribes globally for marketing purposes unless counsel approves a narrow exception.
- Document opt-out timestamps and honor them before the next scheduled send.
- Never sell or share suppressed addresses as "active leads."
Bounce, complaint, and feedback loop handling
SMTP responses and API webhooks tell you when mail was accepted, deferred, or rejected. MailFleet records delivery outcomes locally so teams can diagnose issues without guessing. Operators should review bounce categories after every significant send and before increasing volume.
Complaint feedback loops (FBLs) from major providers signal that recipients marked your message as spam. A rising complaint rate is often more dangerous than a moderate bounce rate. Investigate content, frequency, list source, and consent when complaints spike.
If a provider suspends your account, stop sending through that account until the provider restores access and you have corrected root causes. Switching providers solely to evade a suspension violates this policy and the Acceptable Use Policy.
- Monitor hard bounces, soft bounces, blocks, and deferrals in MailFleet campaign logs.
- Register for feedback loops offered by your sending providers where available.
- Pause campaigns when complaint rates exceed your internal thresholds or provider limits.
- Root-cause fix consent, content, or frequency before resuming high-volume sends.
Content standards and honest messaging
Mailbox filters evaluate words, links, images, HTML structure, and engagement history. MailFleet includes SpamAssassin-oriented checks to help operators catch risky patterns before send. High scores do not guarantee spam folder placement, but they flag content that may hurt deliverability or annoy recipients.
Avoid sensational claims, hidden text, URL shorteners that obscure destinations, and attachment types commonly associated with malware. Balance images and text; include plain-text alternatives where appropriate. Personalization should use data the recipient expects you to hold — not creepy or fabricated details.
Honest subject lines improve trust and reduce complaints. If a message is a newsletter, say so. If it promotes a product, do not disguise it as a personal note. Regulatory bodies and mailbox providers increasingly penalize deceptive patterns regardless of technical authentication.
- Run pre-send content checks inside MailFleet before large campaigns.
- Use reputable link domains; disclose affiliate or tracking parameters where required.
- Keep HTML accessible and avoid executable content in email bodies.
- Match message body to subject and preview text promises.
Authentication, DNS, and deliverability preparation
SPF, DKIM, and DMARC prove that your mail is authorized by the domain owner and help receivers detect spoofing. Before sending at scale, publish correct DNS records, align the From domain with DKIM signing, and set a DMARC policy appropriate to your maturity (often p=none during monitoring, tightening as you gain confidence).
MailFleet provides diagnostic tools and documentation links for SPF, DKIM, DMARC, BIMI, MTA-STS, and related checks. Use the free tools at mailfleet.app/tools to validate public DNS before blaming application settings. Authentication failures do not excuse unsolicited mail — but they do undermine legitimate operators who otherwise have permission.
Deliverability is not guaranteed. Inbox placement depends on reputation, engagement, content, infrastructure, and recipient mailbox policies. MailFleet helps you prepare and observe; it does not promise inbox placement or bypass third-party filtering.
- Configure SPF includes for every sending path you use.
- Sign outbound mail with DKIM keys managed securely.
- Publish DMARC and monitor aggregate reports for unauthorized use.
- Verify MX, reverse DNS, and provider-specific requirements before launch.
Sending volume, warmup, and operational pacing
New domains, IPs, or provider accounts need gradual volume ramps. Sudden spikes from cold infrastructure look like abuse to receivers. Plan warmup schedules aligned with provider documentation and your list engagement. MailFleet sending capacity scoring helps operators reason about batch sizes relative to provider limits — use it as one input among many.
Segment engaged recipients for early sends when warming new infrastructure. Avoid mixing old unengaged lists with fresh domains. Coordinate with clients so multiple teams do not unknowingly blast from the same domain simultaneously.
Rate limits exist at SMTP gateways, APIs, and recipient systems. Exceeding them produces deferrals and blocks that harm everyone on shared reputation pools. Throttle consciously and monitor deferral rates in logs.
- Increase daily volume gradually on new sending identities.
- Separate transactional and marketing streams when providers recommend it.
- Document warmup plans for enterprise and agency deployments.
- Pause and investigate when deferrals or throttling exceed normal baselines.
Regulatory framework overview
United States CAN-SPAM Act imposes requirements on commercial email: truthful headers, ad identification, physical address, opt-out mechanism, and honoring opt-outs within statutory timeframes. It does not replace permission best practices — many US brands adopt stricter opt-in standards because permission drives results and provider acceptance.
European GDPR and ePrivacy rules generally require a lawful basis for processing personal data, including email addresses. Marketing often relies on consent or legitimate interest assessments with strict conditions. Document data processing agreements when agencies handle client data.
Canada's Anti-Spam Legislation (CASL) is consent-forward with limited exceptions. Many other countries — Australia, Brazil, Japan, South Africa, and others — maintain anti-spam or data protection rules. If you email recipients in a region, you are responsible for understanding that region's requirements.
- CAN-SPAM (US): identification, opt-out, honor requests, no deceptive routing.
- GDPR / UK GDPR: lawful basis, data subject rights, privacy notices, processor agreements.
- CASL (Canada): express or implied consent rules with strict record-keeping.
- Sector rules: finance, health, and education may impose additional constraints.
How MailFleet product features support compliance
MailFleet stores campaign data locally on your device by default. That architecture keeps content and lists under your control but does not remove compliance duties. Use local logs, campaign reports, and export options to demonstrate due diligence during client or regulatory reviews.
Provider profiles let you separate brands, clients, or environments without sharing credentials insecurely. Proxy profiles help organize approved routing for legitimate multi-client agency workflows. SpamAssassin checks and sending capacity scoring support pre-send review. Webhooks included in both licenses help integrate delivery events into your suppression and analytics stack.
Free diagnostic tools on the MailFleet website — SPF, DKIM, DMARC, blacklist, domain health, and more — complement in-app checks. Together they form a preparation layer before messages leave your infrastructure.
- Campaign templates and logs for audit trails.
- SMTP/API provider profiles with connectivity testing.
- SpamAssassin-oriented content scoring before send.
- Webhooks for event-driven suppression and monitoring integrations.
- Documentation at /docs and tools at /tools for authentication validation.
Operator and license holder responsibilities
You are responsible for list acquisition, message content, sending decisions, and regulatory compliance. MailFleet provides software; it does not vet your lists or approve your campaigns. Enterprise procurement may require you to demonstrate controls — maintain written procedures for consent, suppression, incident response, and provider escalation.
Train staff who access MailFleet. A single operator importing a bad list can damage domains used by an entire agency. Use role separation, client-specific workspaces where your process allows, and periodic audits of active campaigns.
Keep MailFleet updated. Security patches and application updates protect your local environment. License validation uses encrypted connections and does not require uploading campaign content to MailFleet servers.
- Maintain documented consent and suppression procedures.
- Assign ownership for each sending domain and provider account.
- Review campaign reports after every major send.
- Escalate provider warnings and legal inquiries promptly.
Agency, enterprise, and multi-brand use
Agencies often send on behalf of multiple clients. Each client list must meet the consent standards in this policy. Contracts should state who owns consent records, who responds to complaints, and how suppressions propagate when a client departs.
Enterprise deployments may require VPNs, disk encryption, SSO, or deployment guides. MailFleet's desktop model fits environments where data residency and local control matter. Security reviews should cover workstation access, backup policies, and webhook endpoint hardening — not only the application binary.
For vendor questionnaires and SOC-style reviews, start with our Security page, Privacy Policy, and this Anti-Spam Policy. Contact us for supplemental documentation; we provide factual answers rather than unsupported certification claims.
- Separate client lists, suppressions, and sending domains logically.
- Define offboarding steps to export or delete client data.
- Include anti-spam obligations in client contracts and SOWs.
- Request enterprise review at /contact for procurement support.
Third-party provider and infrastructure rules
MailFleet connects to SMTP relays and HTTP APIs operated by third parties. Each provider prohibits spam and publishes acceptable use terms. You must comply with those terms in addition to MailFleet policies. Providers may throttle, suspend, or permanently ban accounts that generate complaints or authentication failures.
Shared IP pools carry shared reputation. Dedicated IPs require warmup and ongoing hygiene. API keys and SMTP credentials must be stored securely on devices running MailFleet; rotate them when staff leave or clients change.
If a provider mandates one-click unsubscribe, list-unsubscribe headers, or registration in their sender programs, follow those requirements. MailFleet does not exempt you from provider-specific obligations.
Abuse reporting and enforcement
Report suspected abuse of MailFleet software to [email protected]. Include full message headers, sending domain, approximate send time, and description of the violation. We prioritize phishing, malware, clear unsolicited bulk mail, and deceptive practices.
Enforcement may include warnings, required remediation plans, license suspension, or termination. We may cooperate with lawful requests from providers, recipients, or authorities when appropriate. Repeated or egregious violations are unlikely to receive multiple warnings.
If you believe a report against you is mistaken, reply with evidence of consent records, suppression timing, and corrective actions. Good-faith operators who fix root causes are treated differently from deliberate abusers.
- Abuse contact: [email protected]
- Include .eml samples or headers when possible.
- We may suspend licenses pending investigation.
- See also Acceptable Use Policy and Terms of Service.
Monitoring, audit trails, and continuous improvement
Responsible sending is continuous. Schedule weekly reviews of bounce rates, complaint signals, authentication alignment, and suppression integrity. Monthly, audit list sources and consent language on signup forms. Quarterly, revisit regulatory changes in markets you serve.
MailFleet campaign logs and reports support post-send analysis. Export data for client reporting and internal QA. When webhooks feed external systems, validate that failures do not silently drop suppression events.
Document changes: DNS updates, template revisions, provider migrations, and volume increases. Audit trails help you explain decisions during deliverability crises or legal inquiries.
Policy updates and contact information
We may update this Anti-Spam Policy as regulations, provider expectations, or MailFleet features evolve. Material changes will be reflected on this page with an updated modification date. Continued use of MailFleet after updates constitutes acceptance of the revised policy where permitted by law.
Secuno LLC operates MailFleet from 30 N Gould Street, Sheridan, Wyoming, USA 82801. For legal, privacy, or abuse inquiries, use the contact paths published on mailfleet.app/contact.
Related documents: Acceptable Use Policy (/acceptable-use-policy), Privacy Policy (/privacy), Terms of Service (/terms), Security and Trust (/security), and Documentation (/docs).
Summary
MailFleet exists to help professional teams run permission-based email campaigns with clarity and control. Anti-spam compliance is not a constraint on legitimate operators — it is the foundation of sustainable deliverability, client trust, and brand reputation.
Obtain and document consent. Keep lists clean. Authenticate your domains. Honor unsubscribes. Send honest content at sensible volumes. Use MailFleet diagnostics and logs to catch problems early. When in doubt, do not send.
Questions about this policy or enterprise compliance reviews: contact us through mailfleet.app/contact. Abuse reports: [email protected].
Delivery note: MailFleet helps users manage campaigns through their own sending providers. Delivery outcomes depend on sender reputation, DNS authentication, content quality, recipient engagement, list quality, provider rules, and mailbox filtering systems.
For US commercial email requirements, see the FTC CAN-SPAM Act compliance guide for business.
Last updated: 2026-07-07. Published: 2025-01-15.
Frequently asked questions
No. MailFleet is for permission-based campaigns only. Purchased, scraped, harvested, or unsolicited lists violate this Anti-Spam Policy and the Acceptable Use Policy. Operators must document lawful consent or another valid legal basis for every recipient.
Get started
Need compliance documentation for procurement?
Contact MailFleet for security reviews, vendor questionnaires, and enterprise deployment planning.
Available on
- Windows 10+
- macOS 12+
- Linux (DEB & RPM)
Same desktop experience across every platform — one workflow for your entire team.
