Skip to content
TLDBunker

Trust & safety

Report abuse

The short answer

Report abuse to [email protected]. We acknowledge every report within 24–48 h acknowledgement, verify it against our published AUP before acting, and reply with a reasoned decision from a single point of contact. Encrypt sensitive reports to our published PGP key. We investigate before we suspend.

Contact

Where to send a report

Abuse mailbox

[email protected]

RFC 2142 standard address, monitored by a human. Not a bot autoresponder.

PGP key

Our published PGP key

Encrypt reports containing sensitive material. Our published key signs this address.

Acknowledgement SLA

24–48 h acknowledgement

Time to first human acknowledgement, not to final decision. Every report gets a case reference.

What acknowledgement means

Within 24–48 h acknowledgement you receive a case reference and confirmation that a person is reviewing your report. That is a commitment to look, not a promise to act — we still verify the claim against our Acceptable Use Policy before anything happens to a customer's server.

What we act on

TLDBunker is a privacy host, and privacy is for lawful users. It is not cover for abuse. Our Acceptable Use Policy names the conduct we prohibit outright: unsolicited bulk email (spam), phishing and credential harvesting, malware distribution and command-and-control, unauthorised network scanning and intrusion, denial-of-service origination, and child sexual abuse material. That AUP is the line between a privacy host and a so-called bulletproof host — we publish it, we mean it, and we enforce it. We do not sell, imply, or tolerate DMCA-ignored, bulletproof, or residential-RDP framings, and we do not want that traffic.

A useful report is a specific one. Tell us the exact affected resource — an IP address, a hostname, or a full URL — and describe what it is doing, with timestamps in UTC where you can. Logs, headers, or sample payloads make triage far faster. The more precisely you point, the faster we can act without disturbing the many unrelated services on our network.

How we handle a report — a graduated procedure

We do not pull servers on receipt of an accusation. Each report moves through a documented, graduated procedure so that action is proportionate to what we actually find:

  1. Acknowledge and log. Within 24–48 h acknowledgement the report is recorded with a case reference and assigned to the abuse desk.
  2. Investigate. We reproduce or corroborate the claim against our own signals before we touch a customer account. Weak or unverifiable reports are parked, not enforced.
  3. Notify the customer. Where the facts hold up and the situation allows, we contact the customer, cite the specific AUP clause, and give a defined window to remediate. Most genuine issues — a compromised application, a misconfigured mailer — are resolved here, without suspension.
  4. Restrict, then suspend. If harm is active or the customer does not respond, we apply the narrowest effective measure first — rate-limiting, a port block, null-routing a single address — and escalate to suspension only when a lesser step will not stop the harm.
  5. Decide, in writing. Every enforcement action closes with a reasoned decision that states what we found, which policy applied, and how to contest it.

Some categories — CSAM above all, plus active, ongoing attacks — bypass the grace period and are acted on immediately. Speed there is itself the proportionate response.

Reasoned decisions, one point of contact

Our decisions are motivated: we explain them. When we restrict or suspend a service, the notice identifies the resource, the AUP provision engaged, the evidence relied on, and the route to appeal. Reporters and customers deal with a single point of contact — the same abuse desk — rather than being bounced between queues. This is the notice-and-action posture described in our transparency reporting, and it is designed to align with hosting-provider obligations such as the EU Digital Services Act where those apply to our entity or infrastructure.

Report form

File a report

Prefer email or PGP for anything sensitive. This form is a convenience: it opens your own mail client and addresses a plain-text message to [email protected] — nothing is transmitted to us until you press send in your mail application, and no data is stored in the page.

The exact address or hostname you are reporting.

What is happening, and when (UTC timestamps help). Paste logs, headers, or samples if you have them.

A reply address so we can send you the case reference and outcome. Leave blank to report pseudonymously.

Email us directly

Implementation note

The form above uses a mailto: handoff so it works with no JavaScript and no server round-trip. A server-side submission path is planned so reports can land as tracked tickets with automatic case references and PGP-encrypted delivery.

For customers

If your service was flagged

If you host with us and your server is named in a report, we investigate before we act, and we tell you what we found. A suspension notice is never a black box: it carries a case reference, quotes the specific AUP clause, and describes the evidence. Compromise is common and rarely malicious — a vulnerable app turned into a spam relay, a leaked key abused by someone else. Where the facts allow, we reach out and give you a window to fix it before service is interrupted.

To contest a decision, reply to the notice with your case reference. We reopen the case, re-examine the evidence with fresh eyes, and either restore service or explain — in writing — why the action stands. Where a suspension is upheld and your account carried a balance, remaining value is handled per our published billing terms. We would rather keep a legitimate customer online than win an argument, and our whole process is built to separate genuine abuse from collateral damage.

This page is one of several trust surfaces we keep public and versioned: the Acceptable Use Policy that defines the rules, the no-logs policy that bounds what we can even produce about you, the transparency report that counts the authority requests we receive and act on, and the network disclosure. Proof, not promises — including here.

Scope

This page describes how we handle abuse reports operationally. It is not legal advice and does not waive or expand any right or obligation set out in our Acceptable Use Policy or terms of service.

Frequently asked questions

How fast will you respond to an abuse report?

We acknowledge every report to [email protected] within 24–48 h acknowledgement. Acknowledgement is not a verdict — it confirms a human has the report and opened a case. A reasoned decision follows once we have investigated, usually within a few business days depending on complexity.

Do I need to identify myself to file a report?

No. A working reply address helps us send you the case reference and outcome, but you may report pseudonymously. We weigh the evidence in the report, not the identity of the reporter. Reports over PGP are welcome for sensitive material.

Are you a “bulletproof” or “DMCA-ignored” host?

No, and we never will be. We are a privacy host with a published Acceptable Use Policy and a staffed abuse desk. Privacy protects lawful users; it is not immunity for spam, phishing, malware, C2, scanning, or CSAM, all of which are prohibited.

A server was suspended and I think it was a mistake. What now?

Reply to the suspension notice, which carries a case reference and the specific AUP clause cited. We reopen the case, re-examine the evidence, and either restore service or explain the decision in writing. Legitimate customers get a real path to contest.

Reporting abuse of our infrastructure?

Email [email protected] — acknowledged within 24–48 h acknowledgement, handled by a person, decided in writing.