Skip to content
TLDBunker

Trust & policy

Acceptable Use Policy

The short answer

Our Acceptable Use Policy is the line between a privacy host and a bulletproof host. We protect lawful users’ anonymity; we do not shelter spam, phishing, malware, botnet command-and-control, network attacks, or CSAM. Break the AUP and you face graduated enforcement — notice, then suspension — with transparent reasons.

Status of this document

The doctrine and the prohibited categories below are settled and binding; the exact legal wording is being finalised with counsel and confirmed before launch.

The line

Privacy, not immunity

We built TLDBunker so that lawful users can run infrastructure without surrendering their identity: no email at signup, payment in Monero, and a no-logs policy that limits what exists to be handed over. That is a deliberate design choice, and it is the opposite of a “bulletproof” host. A bulletproof host sells the absence of rules. We publish rules, staff an abuse desk, and enforce them. Anonymity for the customer does not mean impunity for abuse.

This Acceptable Use Policy is the concrete expression of that line. It applies to every service and to anyone acting on your account, regardless of the plan or the jurisdiction you chose. Because we do not proactively inspect the contents of your server, enforcement is driven by valid reports and by network-level signals — the reputation of an IP, evidence of an attack sourced from our range, a court order we are obliged to answer. We do not need to know your name to act on any of them.

Prohibited uses

What you may not run here

The following are prohibited outright. This list is not exhaustive of everything unlawful, but it names the categories that damage other customers, poison our IP space, and put our routing and payment rails at risk. Each carries its own reasoning so there is no ambiguity about why it is here.

Unsolicited bulk email and spam

Sending unsolicited bulk or commercial email, snowshoe or hit-and-run spam campaigns, or operating open relays and mailers used to distribute it. Spam is the fastest way to get an entire IP block listed by Spamhaus and other reputation systems, which degrades deliverability and connectivity for every other tenant on the same range. We cooperate with delisting only after the source is stopped.

Phishing and fraud

Hosting or staging credential-harvesting pages, fake login portals, payment-fraud kits, or content that impersonates a brand, bank, or government service to deceive victims. This targets real people for financial harm and is not a privacy interest we protect.

Malware distribution

Hosting, serving, staging, or distributing malware, ransomware, droppers, loaders, exploit kits, or similar hostile payloads. A compromised, out-of-date server that is unknowingly serving malware is usually remediable under notice; deliberately operating a malware delivery node is not.

Botnet command-and-control (C2)

Running command-and-control for botnets, remote-access trojans, or stressers/booters, and coordinating infected devices from our network. Active C2 directs live harm at third parties and is treated as a severe category with immediate action.

Network attacks and unauthorised scanning

Denial-of-service and DDoS, mass port scanning, brute-force or credential-stuffing runs, and any unauthorised intrusion or exploitation aimed at systems you do not own. Legitimate security research against your own assets, or against a third party with documented written authorisation, is not an attack — keep the authorisation on hand in case a report arrives.

CSAM — zero tolerance

Child sexual abuse material is subject to zero tolerance. There is no notice window, no remediation period, and no privacy interest that shields it. Confirmed CSAM results in immediate termination and is reported to the appropriate authorities. This is the one place where our commitment to not inspecting your server yields entirely to acting on a valid report.

Enforcement

Graduated, transparent, and reversible where it should be

Our default posture is proportionate. Most first-time issues are the result of a compromise or a misconfiguration rather than intent — a hijacked mailer, an outdated CMS serving an injected payload, a leaked key. For those we open with a notice: we tell you which rule is implicated, the category of evidence we received, and a reasonable window to remediate. If the problem is fixed, the matter is closed.

Where abuse is not remediated within that window, is repeated, or is severe on its face, we escalate to suspension. A narrow set of categories — CSAM, live botnet C2, and ongoing attacks that are actively harming third parties — is suspended immediately, because a notice window would let the harm continue. Every enforcement action comes with a stated reason. We do not suspend silently and leave you guessing, and we do not hide behind a vague terms-of-service clause.

When we suspend or terminate a service and it is not the result of deliberate abuse on your part, we return your unused prepaid balance as an account credit. Publishing this is deliberate: many hosts keep the money and go dark. Turning a transparent, refund-backed process into the norm is one of the ways an honest privacy host beats a bulletproof one on the merits.

Legal process

What we do when the law comes knocking

We are a real business, not a lawless one. We respond to legitimate, properly scoped legal process that is valid in the jurisdiction where we operate. But cooperation has a hard boundary: we disclose only what the law actually compels, and never more. We do not volunteer data, we do not answer over-broad fishing requests as written, and we push back on process that exceeds its authority.

Two things bound what any request can extract. First, we cannot produce data we never collected — the design of our no-logs policy and no-email signup is the practical limit on disclosure. Second, we never publicly dox a customer. Even in a public dispute, a viral complaint, or a review war, our public responses cite the policy and the process, never a customer’s account details, contents, or metadata. A privacy host that exposes an unhappy customer has ended its own reason to exist.

We count what we receive and what we execute in our transparency report, so the practice is measurable rather than a slogan. TLDBunker is one of several sites published by the same editor, and that relationship is disclosed on the network page — the same honesty we apply to legal process, we apply to who we are.

Reporting

How to report abuse

If you believe a service on our network violates this policy, report it. Our abuse desk is the single point of contact for notice-and-action, and we acknowledge every report within 24–48 h acknowledgement. The fastest path and the details we need are on the report-abuse page; reports also reach us by email at [email protected].

A useful report includes the target (IP address, hostname, or URL), timestamps with time zone, and any logs or headers that evidence the activity. Concrete evidence lets us act quickly and proportionately; vague or automated complaints without specifics slow everyone down. We do not share a reporter’s details with the customer beyond what is needed to resolve the issue, and we do not share a customer’s details with a reporter.

Prices, specifications, and plans referenced elsewhere on this site are illustrative pending launch; see pricing for the current breakdown. This policy governs all of them, including no-KYC and Monero-paid services.

AUP questions

If you don’t collect my identity, how do you enforce the AUP?

Enforcement is tied to the server, not your name. We act on valid abuse reports and network signals affecting an IP or account. We do not need to know who you are to notice a server, throttle it, or suspend it — and we still cannot hand over identity data we never collected.

Will you suspend my server on a single complaint?

No. Most first reports get a notice and a reasonable window to remediate — a compromised CMS or a misconfigured mailer is fixable. Suspension follows only when abuse is unremediated or severe. A narrow set of categories (CSAM, live botnet C2, ongoing attacks) is suspended immediately.

Do I get a refund if you suspend me?

Where a suspension or termination is not the result of deliberate abuse, we return your unused prepaid balance as account credit. We publish this so you can compare it against hosts that keep your money and go quiet.

Does cooperating with legal process mean you expose customers?

We respond to legitimate, properly scoped legal process, and we disclose only what the law actually compels — nothing more. We never publicly dox a customer, even during a public dispute. What we can produce is bounded by what we retain; see our no-logs policy.

Is this the final, binding policy?

This page states our intent and doctrine. The binding AUP text is being finalised with counsel before launch (gate G0). The prohibited categories and enforcement approach described here are stable; exact legal wording may change.

Questions about acceptable use?

Read the abuse process, or see how our no-logs design limits what any request can reach.