Acceptable use policy
Last updated 27 August 2026
What the service does
SenderCheck performs read-only lookups of publicly published DNS records, and one HTTPS request to the fixed, specification-defined location of an MTA-STS policy file. That is the entirety of what it touches.
What it deliberately does not do
These are design decisions, not missing features. The service does not and will not perform:
- Port scanning or service enumeration
- Vulnerability probing or exploitation of any kind
- SMTP connection testing, relay testing or mail injection
- Credential testing against any system
- Discovery of hosts on private networks
- Any modification of DNS records
Permitted use
Manual checks read public information and may be run against any domain, including ones you do not control — the same information is available to anyone with a DNS client. Continuous monitoring requires proof of control via a verification record, because it stores history and sends alerts.
Prohibited use
- Circumventing rate limits, quotas or plan restrictions, including through multiple accounts
- Automated bulk querying beyond the limits of your plan
- Reselling access without a written agreement
- Using output to target a domain owner for harassment
- Anything unlawful in your jurisdiction or ours
Enforcement
Automated systems apply rate limits and flag anomalous patterns. Where abuse is clear we may suspend an account, with notice by email and an explanation of what triggered it. Suspension decisions can be appealed by replying to that email.
Reporting abuse
Security vulnerabilities: security@sendercheck.net. We will acknowledge within 3 working days and will not pursue action against good-faith research that respects user privacy and avoids service degradation.