Acceptable use
Acceptable Use Policy
What ShieldMail may and may not be used for, why rule-evasion damages the tool for everyone, and how abuse reports are handled.
Last updated
This policy exists for a practical reason as much as an ethical one. Abuse of disposable email services is why so many websites block them, and every abusive use makes the tool worse for the people using it properly.
Acceptable
- Receiving a single expected message: a download link, a confirmation, a quote, a portal code
- Keeping a permanent address out of low-stakes signups you do not want to maintain
- Manually testing signup, verification, and password-reset flows in systems you own or are authorised to test
- Reading a newsletter before deciding whether it deserves a durable address
- Registering for read-only access to a community you will not participate in
The common thread: you need to receive something, and you have no reason to give the sender a durable channel.
Not acceptable
Evading a restriction. Using a fresh address to get around a ban, a suspension, a one-account-per-person rule, or a free-trial limit. If the only reason you need a new address is that a service has decided you should not have one, that decision is the answer.
Deceiving people. Impersonating somebody, running a scam, phishing, or any use where the disposability of the address is what makes the deception work.
Harassment. Using the service in any part of a campaign to harass, threaten, stalk, or intimidate.
Unlawful material. Receiving or storing anything illegal in your jurisdiction or ours.
Automated abuse. Scripting mailbox creation, hammering the API, load-testing the service, or building a product on top of it. There is no public API and no capacity for automated use.
Circumventing controls. Working around rate limits or other technical measures here.
Why rule-evasion matters more than it seems
It is tempting to treat a second free trial as victimless. In aggregate it is not, and the mechanism is direct.
Services detect abuse, add the domain to a block list, and share that list with the rest of the industry. The domain stops working everywhere — including for somebody using it exactly as intended to collect a whitepaper.
So the cost of evasion is not borne by the service being evaded. It is borne by every other user of every disposable email tool. That is why this policy names it specifically rather than leaving it implied.
Automated use
There is no public API, no documented endpoints, and no rate allowance for scripts. Programmatic mailbox creation will be rate-limited and blocked.
If you need disposable addresses at volume for legitimate testing, the correct answer is a catch-all address on a domain you own, or a dedicated mail-testing service. Both are cheap, both are private, and neither depends on somebody else's free tool. The reasoning is in temporary email for testing websites and apps.
Reporting abuse
If a ShieldMail address has been used against you or a service you run, write to abuse@shieldmail.shop with the address involved, the approximate time, and what happened. Message headers help considerably.
Reports are prioritised above all other mail and answered within one working day. Please report quickly: these mailboxes are short-lived and no archive exists, so the window for acting is narrow.
Enforcement
Since there are no accounts, enforcement is applied at the network level. Depending on severity:
- Rate limiting on the source
- Blocking access to the service
- Referral to the relevant authorities, in cases involving illegal activity
Your own responsibility
Using ShieldMail does not exempt you from any other service's terms. Many explicitly require a working contact address, and some ban disposable domains outright. Complying with that is your responsibility, not ours, and a rejection at their signup form is their decision to make.
FAQ
Is it acceptable to use a temporary address for a free trial?
Only for a first trial, where the service permits it. Taking repeated trials by generating new addresses breaches their terms and this policy.
What if a website's terms forbid disposable addresses?
Then using one there breaks your agreement with them. This policy does not override theirs, and we will not intervene on your behalf.
Can I use ShieldMail for security research?
For systems you own or are explicitly authorised to test, yes. Unauthorised testing of third-party systems is not acceptable use regardless of intent.
How quickly are abuse reports handled?
Within one working day. They take priority over everything else in the inbox.
Will you tell me who used a particular address?
No. There are no accounts, so no record linking an address to a person exists anywhere in the service.