Abuse & security
Something coming from our address space?
Tell us what you saw and we will act on it. Reports are read by the engineers who can stop an instance, not by a mailbox nobody opens.
- Acknowledged
- < 12hBy a person, with a reference
- Active abuse
- < 2hOngoing attacks are handled first
- Disclosure
- Safe harbourNo legal action for good-faith research
- Evidence
- UTC + IPTimestamps in UTC and the address make it actionable
Report
What did you see, and when?
Two things make a report actionable: the address or reference involved, and a timestamp in UTC. Log lines, headers or a packet capture help; a screenshot rarely does.
What we do about it
- Network abuse
- Port scanning, brute force and denial of service from our range are stopped on sight — the instance is suspended while we talk to the account.
- Phishing and fraud
- Content impersonating a third party is taken down without waiting for a discussion.
- Malware and botnets
- Command and control, or hosting of malicious binaries, ends the account.
- Spam
- Outbound mail abuse is suspended; instances have no special mail privileges to begin with.
- Copyright
- We are not the publisher of what customers run. Send a precise claim with the material and the rights you hold, and we forward it and act where required.
- Lawful requests
- Requests from authorities are answered when they are valid and properly served. We do not hand over data on an informal email.
Reporting a vulnerability in our own platform?
Choose the category that fits, describe the issue and stop at proof of concept. The rules of engagement and what we promise in return are on the trust page.