1.1 SMTPCart operates managed email delivery infrastructure on behalf of BEINCART LLC ("SMTPCart", "we", "us", "our"). The commercial value of that infrastructure depends entirely on its standing with mailbox providers, and that standing depends on our willingness to act against abuse originating from our own customers.
1.2 We therefore treat anti-abuse work as an operational function rather than a complaint-handling formality. We maintain monitored abuse channels, respond to credible reports, cooperate with mailbox providers and blocklist operators, and terminate customers whose conduct threatens the ecosystem — including customers whose revenue we would prefer to keep.
1.3 We do not permit unsolicited bulk email on our infrastructure under any commercial arrangement, at any price, for any customer.
2.1 This Policy applies to all infrastructure, IP ranges, domains and services operated by SMTPCart, and to all traffic transmitted through them.
2.2 SMTPCart publishes four related documents. They are designed to be read together and to answer different questions:
| Document | Question it answers | Primary audience |
| Terms of Service | What are the commercial terms of the contract? | Customers and their counsel |
| Acceptable Use Policy | What may a customer send, and what is prohibited? | Customers |
| Anti-Abuse Policy (this document) | How does SMTPCart prevent, detect and respond to abuse? | Mailbox providers, blocklist operators, complainants, and customers performing due diligence |
| Privacy Policy | How is personal data handled? | Customers, recipients and regulators |
2.3 Where this Policy and the Acceptable Use Policy address the same conduct, the Acceptable Use Policy governs what the customer must do, and this Policy governs what we will do about it.
3.1 For the purposes of this Policy, "abuse" means any use of our infrastructure that breaches the Acceptable Use Policy, violates applicable law, or that harms or threatens to harm recipients, mailbox providers, other customers, or the reputation of our IP ranges.
3.2 This includes, without limitation: unsolicited bulk email; phishing and credential harvesting; malware distribution; sender or brand impersonation; use of purchased, scraped or harvested lists; evasion of volume limits or filtering; distribution of traffic across accounts to avoid detection; and the operation of a compromised account.
3.3 Abuse does not require intent. A customer whose credentials have been compromised, or whose list practices have degraded through neglect rather than design, is still generating abuse and is handled under this Policy — though intent materially affects the enforcement outcome.
4.1 The most effective anti-abuse control is declining to provision the account in the first place. We apply pre-provisioning controls including:
4.2 New Sending Environments are subject to a managed warm-up with agreed daily volume limits. Volume increases are approved against observed complaint, bounce and engagement data rather than granted on request.
4.3 Infrastructure is isolated by design. Segmenting customers and mail streams across distinct environments and IP allocations limits the blast radius of any single incident, and is itself an anti-abuse control.
5.1 We operate continuous monitoring across our infrastructure, including:
5.2 Monitoring is directed at traffic patterns, metadata and delivery outcomes. We do not routinely inspect message content, and nothing in this Policy obliges us to do so. Content may be examined where necessary to investigate a specific report, respond to legal process, or verify remediation.
5.3 Monitoring protects our infrastructure. It is not a compliance service provided to customers, and the absence of an enforcement action is not an endorsement of a customer's practices.
6.1 Anyone may report suspected abuse originating from our infrastructure by writing to [email protected]. This address is monitored and is published in our WHOIS records.
6.2 To allow us to act, a report should include, where available: the full message headers (these are usually essential to identify the sending account), the message body or a representative sample, the date and time of receipt including time zone, the recipient address, and a brief description of why the message is considered abusive.
6.3 We acknowledge credible reports within 48 ~ 72 hours and assign them a category under section 7. We prioritise reports from mailbox providers, blocklist operators and security researchers, and reports concerning phishing, malware or content involving minors are actioned immediately on verification.
6.4 We do not disclose the outcome of an individual investigation to the reporting party, as doing so would disclose customer information. We do act on what we find, and a reporter who continues to receive the same traffic after reporting should tell us.
6.5 Recipients wishing to stop receiving mail from a particular sender should first use the unsubscribe mechanism in the message. Where that mechanism is absent or non-functional, that is itself a breach of our Acceptable Use Policy and should be reported to us directly.
6.6 We do not require reporters to have a prior relationship with us, and we do not charge for handling reports.
7.1 Reports and detections are categorised by the risk they present. The targets below describe our intended initial response; investigation and resolution may take longer.
| Category | Examples | Initial response target | Typical action |
| Critical | Child sexual abuse material; active phishing campaign; malware distribution | Immediate on verification | Termination, evidence preservation, referral to NCMEC or law enforcement |
| Severe | Confirmed unsolicited bulk mail; purchased or scraped list; major blocklist listing; compromised account actively sending | Within 48 ~ 72 hours | Suspension, queue hold, IP freeze pending investigation |
| Significant | Sustained complaint or bounce threshold breach; spam trap hits; non-functioning unsubscribe | Within 48 ~ 72 hours | Throttling or stream-level block, remediation plan required |
| Moderate | Isolated complaint clusters; authentication failures; configuration faults | Within 2 business days | Written notice and guidance under AUP Tier 1 |
| Informational | Third-party reports that do not evidence a breach; recipient queries | Within 3 business days | Logged, assessed, and closed or escalated |
7.2 Where risk is active and ongoing, containment precedes investigation. We may suspend an account, hold queued messages or freeze an IP allocation before determining whether a breach occurred, and we will restore service promptly if it did not.
8.1 Confirmed and suspected abuse is handled through a defined sequence:
| Stage | What happens | Indicative timeframe |
| 1. Intake | Report received via [email protected], feedback loop, monitoring alert or provider notification; logged and assigned a reference | On receipt |
| 2. Triage | Category assigned under section 5; risk to infrastructure and to other customers assessed | Within 48 ~ 72 hours |
| 3. Containment | Where risk is active: throttling, stream blocking, queue hold, account suspension or IP freeze | Immediately upon triage where warranted |
| 4. Investigation | Logs, headers, authentication results, consent evidence and account history examined | 1-5 business days depending on category |
| 5. Determination | Breach confirmed or dismissed; enforcement tier set under the Acceptable Use Policy | On completion of investigation |
| 6. Remediation | Customer remediation plan reviewed; delisting requests filed; affected providers notified | Ongoing until resolved |
| 7. Closure | Service restored, restricted or terminated; record retained under section 10 | On resolution |
8.2 Enforcement outcomes are determined under section 10 of the Acceptable Use Policy, which sets out the four-tier ladder from advisory notice through restriction and suspension to termination.
8.3 Where an account is compromised rather than deliberately abusive, our objective is containment and secure restoration: we suspend sending, require credential rotation and confirmation that the compromise is closed, and may require a fresh warm-up before full volume resumes.
8.4 Where abuse has caused a blocklist listing, we file and manage delisting requests for our own IP ranges. We may require the customer to file its own requests for listings against its domains, and to demonstrate remediation before we support the request.
8.5 Where an incident has affected mailbox provider reputation, we may notify the affected providers, describe the remediation taken, and request reputation review. Customers must not contact providers on our behalf in respect of our IP ranges.
8.6 Customers may appeal an enforcement decision, and should submit appeals and remediation plans to [email protected] in accordance with section 11 of the Acceptable Use Policy.
9.1 We cooperate with mailbox providers, blocklist and reputation operators, feedback loop operators, upstream network providers and industry anti-abuse organisations. We regard these relationships as infrastructure, not as adversaries.
9.2 We may share information about confirmed abuse — including account identity, sending domains, IP allocation and the nature of the breach — where necessary to protect our infrastructure, secure a delisting, prevent ongoing harm, or comply with the requirements of an upstream provider.
9.3 Content involving the sexual exploitation of minors is reported to the National Center for Missing & Exploited Children and to competent law enforcement, without notice to the account holder, and records are preserved.
9.4 We respond to lawful requests from law enforcement and to valid legal process. Requests should be directed to [email protected]. We require process that is valid in the relevant jurisdiction, and we narrow overbroad requests where lawful to do so.
9.5 We do not sell, rent or otherwise commercially exploit abuse reports or the data within them.
10.1 On identifying credible abuse we preserve relevant records, including delivery logs, message headers, authentication results, account and verification records, and the report itself.
10.2 Abuse investigation records are retained for 3 months, or longer where required by law, by an ongoing investigation, or by legal process. Message content is retained only as long as necessary for the investigation.
10.3 Retention and processing of personal data within these records is governed by our Privacy Policy and applicable data protection law. Abuse prevention is a legitimate interest, and records are held on that basis.
11.1 Abuse imposes real costs on us: IP remediation and delisting, reputation recovery, provider escalation, engineering time, and loss of infrastructure capacity while a range recovers.
11.2 Under the Terms of Service, these costs are recoverable from the customer whose conduct caused them. No refund or credit is given for periods of suspension resulting from a customer's breach.
11.3 We may decline to provide services in future to any person associated with an account terminated for abuse.
12.1 Abuse reports: [email protected] — monitored, published in WHOIS, and the correct channel for spam, phishing, malware and unsubscribe failures.
12.2 Security and compromise reports: [email protected] — for vulnerability disclosure and reports of compromised accounts or infrastructure. We do not pursue legal action against researchers who report in good faith, act proportionately, and do not access or exfiltrate data belonging to others.
12.3 Legal process: [email protected], or in writing to BEINCART LLC, [email protected].
12.4 Provider and blocklist escalation: mailbox providers, blocklist operators and upstream providers requiring escalation beyond the abuse desk may request in writing to BEINCART LLC through [email protected], and we will respond on a priority basis.
13.1 This Policy describes our operational practice. It does not create rights enforceable by any third party, and nothing in it obliges us to take or refrain from any particular action in a given case.
13.2 The response targets in section 7 are objectives, not contractual commitments, and do not form part of any service level agreement.
13.3 We may update this Policy to reflect changes in law, mailbox provider requirements, or abuse patterns. Material changes take effect on publication.
13.4 This Policy is effective from 09/26/2026 and is governed by the laws of the State of Wyoming, United States, in accordance with the Terms of Service.
