What we act on
TLDBunker is a privacy host, and privacy is for lawful users. It is not cover for abuse. Our Acceptable Use Policy names the conduct we prohibit outright: unsolicited bulk email (spam), phishing and credential harvesting, malware distribution and command-and-control, unauthorised network scanning and intrusion, denial-of-service origination, and child sexual abuse material. That AUP is the line between a privacy host and a so-called bulletproof host — we publish it, we mean it, and we enforce it. We do not sell, imply, or tolerate DMCA-ignored, bulletproof, or residential-RDP framings, and we do not want that traffic.
A useful report is a specific one. Tell us the exact affected resource — an IP address, a hostname, or a full URL — and describe what it is doing, with timestamps in UTC where you can. Logs, headers, or sample payloads make triage far faster. The more precisely you point, the faster we can act without disturbing the many unrelated services on our network.
How we handle a report — a graduated procedure
We do not pull servers on receipt of an accusation. Each report moves through a documented, graduated procedure so that action is proportionate to what we actually find:
- Acknowledge and log. Within 24–48 h acknowledgement the report is recorded with a case reference and assigned to the abuse desk.
- Investigate. We reproduce or corroborate the claim against our own signals before we touch a customer account. Weak or unverifiable reports are parked, not enforced.
- Notify the customer. Where the facts hold up and the situation allows, we contact the customer, cite the specific AUP clause, and give a defined window to remediate. Most genuine issues — a compromised application, a misconfigured mailer — are resolved here, without suspension.
- Restrict, then suspend. If harm is active or the customer does not respond, we apply the narrowest effective measure first — rate-limiting, a port block, null-routing a single address — and escalate to suspension only when a lesser step will not stop the harm.
- Decide, in writing. Every enforcement action closes with a reasoned decision that states what we found, which policy applied, and how to contest it.
Some categories — CSAM above all, plus active, ongoing attacks — bypass the grace period and are acted on immediately. Speed there is itself the proportionate response.
Reasoned decisions, one point of contact
Our decisions are motivated: we explain them. When we restrict or suspend a service, the notice identifies the resource, the AUP provision engaged, the evidence relied on, and the route to appeal. Reporters and customers deal with a single point of contact — the same abuse desk — rather than being bounced between queues. This is the notice-and-action posture described in our transparency reporting, and it is designed to align with hosting-provider obligations such as the EU Digital Services Act where those apply to our entity or infrastructure.