legal

Abuse policy

How to report misuse of an Upkyo service, how we handle it, and the email sending rules our customers must follow.

legal

Abuse and Anti-Spam Policy

This policy supplements our Terms of Service and Acceptable Use Policy. It applies to every Upkyo service and every customer.

Last updated: October 5, 2026

1. Purpose and Scope

Upkyo, the trade name of a Limited Liability Company organized under the laws of the State of New Mexico, USA, company number 6867626, is committed to keeping its network safe and trustworthy. This policy explains how to report abuse carried out through an Upkyo service, how we handle reports and which email sending rules our customers must follow.

It applies to web and WordPress hosting, cloud, VPS and dedicated servers, professional email, domain names registered through Upkyo and every other service we provide. Customers are responsible for the activities of their own users, clients and contractors.

2. What You Can Report

You can report, among other things: spam or unsolicited email sent from our servers, or spam promoting a site we host; phishing and impersonation of a person or brand; distribution of malware, ransomware or spyware; botnet command and control servers, denial of service attacks, port scans, intrusion or brute force attempts originating from our network; fraud, scams and the sale of counterfeit goods; child sexual abuse material; incitement to terrorism or violence and threats; defamation, privacy violations or misuse of someone's likeness; trademark infringement; domain name abuse; and any other illegal content or conduct.

Copyright infringement follows the specific process described in our Copyright Policy.

3. How to Report

Send your report to support@upkyo.com with “Abuse” in the subject line, followed by the type of abuse, for example “Abuse: phishing.” Customers can also open a ticket from their client area.

To help us act quickly, include: the type of abuse; the exact IP address, domain name or URL involved; the date and time of the incident with the time zone; any evidence you have, such as server logs, screenshots or email headers; your contact details if you are willing to be contacted; and, if you are acting for someone else, your role.

Send one report per incident or campaign, preferably in plain text. Never send a malicious file unprotected. If one is needed, attach it in a password-protected archive and include the password in your message. Never send a copy of child sexual abuse material. Give us only the location where it can be found.

4. Reporting Spam: Full Headers

A spam report is only actionable if it includes the original message with its full headers, which show the servers the message passed through. Simply forwarding the message or sending a screenshot is not enough, because the headers are lost.

Your email client lets you view the original message or message source. Copy all of that text into your report or attach the message as an .eml file. You may redact your own email address from the text if you wish.

Mailbox providers can send us automated reports in the standard ARF format to the same address.

5. How We Handle Reports and Set Priorities

Every report is logged and reviewed by our team, which is available 24/7. We give priority to reports that pose an immediate risk to people or to network security: child sexual abuse material, threats of violence, active phishing, malware, botnets and ongoing attacks. Other reports are handled within a reasonable time based on their severity and the quality of the information provided.

We verify that the reported activity actually comes from an Upkyo service and that it is sufficiently established. We may ask you for more information. We do not always share the details of the action we take, in particular to protect our customers' data, but we acknowledge complete reports when you have provided your contact details.

6. Notice to the Customer and Time to Act

Except in the serious cases described below, we notify the affected customer by email at the account address or in the client area. We describe the problem and ask the customer to fix it or reply within a deadline that we set based on the severity of the issue and state in our message.

If the customer does not respond by that deadline, if the response is inadequate or if the abuse happens again, we may restrict, suspend or terminate the service involved, without prejudice to our other rights. The customer must continue to pay for the service while it is suspended.

7. Immediate Suspension in Serious Cases

We may immediately and without notice suspend all or part of a service, block an IP address, disable an email account or make content inaccessible when necessary to stop serious abuse, including: child sexual abuse material; an active phishing page; malware distribution; a botnet command and control server; an ongoing attack against a third party or our network; a high volume of spam; a risk to the security, availability or reputation of our infrastructure or other customers; or a request from a competent authority.

The customer is notified of the action as soon as possible, unless the law or an authority prohibits it or notice would compromise an investigation. When the service is part of shared hosting, we may act on the offending content alone or on the entire account, depending on what is technically possible.

8. Phishing

Phishing means imitating a legitimate service, such as a bank, government agency, email provider or shipping company, to obtain credentials, payment details or personal information. It is strictly prohibited on our services.

An active phishing page is disabled as soon as we confirm it. If a customer's site was compromised without the customer's knowledge, we let the customer know and require them to clean the site, fix the vulnerability and change their passwords before it is reactivated. If the customer created the page, the account is terminated without a refund and the evidence may be shared with authorities and anti-phishing organizations.

9. Malware and Compromised Sites

Hosting, distributing or controlling malware, ransomware, spyware, hidden cryptocurrency miners or any other harmful code is prohibited. Our anti-malware protections may automatically quarantine or neutralize a file detected as malicious, without notice.

Most infections come from an outdated plugin, theme or application, or from a compromised password. Customers are responsible for the security of their sites and applications. We can help restore a backup, but backups are a convenience service and do not replace the customer's own security measures. Cleanup performed by Upkyo at the customer's request may be billed at the rate shown in the client area or on a quote.

10. Botnets, Attacks and Network Activity

The following are prohibited on our services and from our network: hosting botnet command and control servers; denial of service attacks; unauthorized port or vulnerability scanning; intrusion or brute force attempts; IP address spoofing; operating open mail relays, open proxies or open recursive DNS resolvers; and intercepting traffic that does not belong to you.

Security testing is allowed only on your own systems or with the written consent of their owner. A compromised server taking part in an attack may be isolated from the network immediately, even if the customer is not the attacker.

11. Child Sexual Abuse Material

Upkyo has zero tolerance. Any child sexual abuse material is removed or disabled as soon as we become aware of it, and the account involved is terminated without notice or refund.

As required by 18 U.S.C. § 2258A, we report this material to the National Center for Missing and Exploited Children, which forwards it to the appropriate authorities, and we preserve the information the law requires. When the facts concern a European Union country, we also report them to the competent authorities of that country.

If you come across such material, do not download it and do not send us a copy. Give us only the location where it can be found, and also report it to the authorities or the hotline in your country.

12. Anti-Spam Rules: Consent

Our customers may send commercial or bulk email, whether from our servers or to promote a site we host, only to recipients who have expressly consented or with whom they have an existing relationship that permits the email under applicable law.

For recipients in the European Union, consent must be freely given, specific, informed and unambiguous, as required by the GDPR and the rules on electronic marketing. We strongly recommend double opt-in, where recipients confirm their subscription by clicking a link. Customers must be able to show us, on request, the date, source and method of consent for every recipient.

13. Unsubscribing, Sender Identification and CAN-SPAM

Every commercial email must comply with the U.S. CAN-SPAM Act, codified beginning at 15 U.S.C. § 7701, and with the laws of the recipients' countries. Among other things, it must: use accurate headers and sender information; have a subject line that does not mislead about the content; be identifiable as an advertisement when it is one; include a valid physical postal address for the sender; and offer a simple, free way to unsubscribe that keeps working for as long as the law requires.

Unsubscribe requests must be honored within the time required by applicable law, and the address may not then be reused, sold or transferred. Customers remain responsible for these obligations even when they use a third-party sending service.

14. Prohibited Practices

The following are prohibited, among others: using purchased, rented, traded or harvested lists; automated harvesting of addresses from websites; dictionary attacks; sending from multiple domains or IP addresses to evade filters; forging headers; using a third-party relay or server without permission; hosting with Upkyo a site promoted by spam sent from another network; and sending deceptive or fraudulent email or email that impersonates someone else.

Our email services may not be used to send large-scale newsletters or campaigns. Those must go through a dedicated email marketing platform that manages consent, unsubscribes and bounces.

15. Sending Limits

To protect our servers' reputation, we limit the number of emails an account can send per period. These limits depend on the service you subscribe to and are shown in the client area or provided on request. We may change them at any time.

We may throttle, queue or block email that exceeds these limits or that shows an abnormal rate of bounces, complaints or invalid addresses, and we may disable a compromised email account that is sending spam. Customers must remove invalid addresses from their lists and process bounce messages.

16. Blocklists and Cleanup Fees

If a customer's activity causes an Upkyo IP address or domain to be listed on a blocklist or reputation list, or requires intervention by our team, the customer may be required to pay reasonable fees for diagnosis, cleanup and delisting requests, at the rate shown in the client area or on a quote, along with any other loss Upkyo suffers.

We do not guarantee removal from a blocklist, which is up to the list operator. We may move a service to another IP address or suspend it until the problem is resolved.

17. Cooperation with CERTs, Reputation Lists and Authorities

Upkyo cooperates with computer emergency and security incident response teams, known as CERTs or CSIRTs, with blocklist and reputation list operators, with mailbox providers and with anti-phishing and anti-malware organizations. We may share the technical information needed to stop abuse with them.

Requests from authorities are handled under our Law Enforcement Requests Policy. For services provided in the European Union, we handle notices of illegal content in accordance with Regulation 2022/2065, the Digital Services Act, and give the affected customers a statement of reasons for our decisions. When we become aware of information giving rise to a suspicion that a criminal offense threatening the life or safety of one or more people has occurred, is occurring or is likely to occur, we inform the competent authorities, as that regulation requires.

18. False Reports and Abuse of the Process

Reports must be made in good faith. A report that is deliberately false or misleading, or that is meant to harm a competitor, censor lawful content or harass a customer, may expose its author to liability. We may disregard reports that are plainly abusive or repetitive and stop handling reports from a sender who abuses the process.

Upkyo is not liable for the consequences of action taken in good faith based on a report that turns out to be inaccurate. The person who made the report is responsible for it.

19. Reporter Confidentiality

Whenever possible, we do not share your identity or contact details with the affected customer. We may share them, however, if you consent, if the law requires it, if an authority or court orders it, or when the process requires it, in particular for DMCA notices and some trademark or other rights claims, which must allow the customer to respond.

Personal data in reports is processed in accordance with our Privacy Policy, solely to handle the abuse, defend our rights and meet our legal obligations.

20. No Duty to Monitor and Discretion

Upkyo does not generally monitor, and is not required to monitor, its customers' content and communications. We decide, at our sole discretion and in accordance with the law, what action is appropriate in each situation. Not acting on a report, or acting late, does not mean we approve of the content or activity involved and does not waive any of our rights.

To the fullest extent permitted by law, Upkyo is not liable to any customer or third party for action taken in good faith under this policy. The liability caps and exclusions in our Terms of Service apply, and customers indemnify Upkyo against any claim arising from abuse carried out through their service.

21. Changes, Language and Contact

We may update this policy at any time. Customers are notified of material changes by email or in their client area. This policy is published in several languages, and the English version controls if there is any inconsistency.

Reports and questions: support@upkyo.com. Mailing address: Upkyo, 1178 Broadway, 3rd Floor #1249, New York, NY 10001, USA.

Web hosting, email and servers on high-availability infrastructure.

write to ussupport@upkyo.com
what now

Switch hosts without losing a thing.

Our engineers move your website, email and domains for you. Leave your email and we will get back to you.

© 2026 upkyo / 1178 broadway, 3rd floor, new york, ny 10001, usafr / es / legal center / legal notice / terms of service / privacy / domain registration agreement