Acceptable Use Policy
Version 1.0, 2 September 2026.
fabricatedemail exists for one purpose: receiving mail that your own systems send, so that automated tests can assert on it. This policy says what falls outside that, and it forms part of the Terms of Service.
What you must not do
- Receive mail intended for a real person. The addresses are for systems under test, not for people. Do not give a fabricatedemail address to anyone as a way of receiving their correspondence, and do not use one to intercept mail meant for someone else.
- Create accounts on third-party services. Do not use an address to register on a site that is not yours, to evade a service's sign-up limits, to claim free trials repeatedly, or to bypass an email-verification step on someone else's platform.
- Commit fraud, phishing or spam. This includes using an address as a reply-to or contact address in a fraudulent or deceptive message, as part of an account-takeover attempt, or in any scheme to obtain money, credentials or data by deception.
- Receive or store unlawful content, including content that is illegal to possess or distribute in Sweden or in your own jurisdiction, or content that infringes another person's rights.
- Attack or overload the service: probing for vulnerabilities without our written permission, circumventing the rate limit or the account caps, sharing one account's keys across separate organisations to avoid buying separate accounts, or automating the sign-up flow to create accounts in bulk.
- Resell the service as a disposable-mail product to third parties, or expose the addresses through a public web page that shows the mail arriving at them.
Consequences
We may suspend an account immediately and without notice, at our discretion, where we consider this policy to have been broken or where an account threatens the platform or other customers. Suspension is not a punishment we negotiate in advance: it is how a problem stops.
While an account is suspended, every API request answers 403
and mail addressed to its addresses is dropped and not stored — mail
that arrives during a suspension is gone even if the account is later
reinstated. We will email the account address to say that it happened
and why. Serious or repeated breach ends the account under section 7 of
the Terms.
We do not read stored mail as a matter of course. We may inspect an account's metadata and, where a report or a platform-safety concern makes it necessary, its content, in order to investigate a breach of this policy or to comply with a legal obligation.
Reporting abuse
If mail from a fabricatedemail address, or an address on our domain, has been used against you or your service, write to abuse@fabricatedemail.com. The address is monitored by the operator; it is not an automated system.
Please include, where you have them:
- the full address on
fabricatedemail.cominvolved; - the complete message with its headers, or the log entries showing the activity;
- the dates and times, with the time zone;
- what you would like us to do.
We aim to acknowledge a report within two business days. Where a report is substantiated we suspend the account, which stops both API access and mail delivery at once, and we tell you that we have acted. We do not disclose account-holder details in response to a report; a request for those needs valid legal process, sent to the same address.
Our own abuse measures
Sign-up is refused from known disposable-email domains and from
fabricatedemail.com itself. A set of local parts —
abuse, postmaster, security,
support, admin, noreply,
no-reply, hostmaster, webmaster,
info, billing, legal and
dmarc — cannot be registered, so that the addresses a
domain is required to answer on stay ours. There is a per-key rate
limit, and every account has hard caps.