docs/policy.md168 lines · 9.0 KB

recvmail policy

recvmail sells short-lived, receive-only email inboxes to AI agents, paid for one call at a time. This page is the whole of our policy: for the services our addresses are given to, for our customers, and for anyone asking what we keep.

For services that receive our addresses

What recvmail is

  • We mint every address: 20 random characters at recvmail.net. Nobody can choose one, so no support@, billing@ or lookalike address of ours exists.
  • Inboxes are short-lived. An inbox lives 75 minutes unless its buyer pays to extend it, and most are gone within hours. Mail is deleted soon after it is read, and all of it when the inbox ends.
  • An address is never reissued. Once an inbox ends, mail to its address is refused for good, so nobody can later receive another holder's password resets.
  • recvmail sends no mail. recvmail.net publishes a DMARC reject policy, so a message claiming to be from it is forged.

Blocking us is fine

Our addresses are on recvmail.net and its subdomains, and always will be: we never add or rotate domains to get around a blocklist. If your service doesn't want throwaway addresses, block the domain and its subdomains, or opt out (next), which also tells our customers before they pay.

Opting your domain out

A domain's owner can have all mail from that domain refused for every recvmail address. We don't ask why. We only check that the request comes from whoever controls the domain's DNS:

  1. Publish a TXT record at _recvmail.<your domain> with the value opt-out.
  2. Then write to abuse@admin.recvmail.net naming the domain. Publish first: a resolver that looked the name up before the record existed can keep its "no such name" answer for as long as your zone's negative-caching TTL (the SOA minimum).

We look the record up ourselves and reply once the opt-out is in place. From then on:

  • mail whose From: domain is yours, or a subdomain of it, is refused when it is sent, authenticated or not, with sender domain opted out;
  • an agent that tells us it expects mail from your domain is refused before it pays.

The record covers the domain it sits under and that domain's subdomains, never a parent: _recvmail.mail.example.com opts out mail.example.com only. You can delegate the name with a CNAME, as with _dmarc. To withdraw, delete the record and write again; we remove the opt-out once the record is gone. We don't publish the list of domains that have opted out.

Reporting abuse

Write to abuse@admin.recvmail.net. Mail to abuse@ or postmaster@ at recvmail.net itself bounces with a pointer there. Name the addresses of ours involved and when, and send the evidence: the offending message as an attachment with its full headers, a lure with our address in its Reply-To:, or an RFC 5965 report. Reports are by mail only, and we answer from a person's own address, since recvmail.net sends none.

  • A report that names an address, with evidence, cancels that inbox. Everything it holds is deleted at once, and its buyer is told it was cancelled for abuse. Until the end of the time that was paid for, mail to it bounces with address disabled for abuse; reports: abuse@admin.recvmail.net, so someone replying to a lure learns why.
  • Most inboxes have ended by the time a report arrives. A report is still worth sending: it shows us the pattern, such as one buyer holding many inboxes that hear from you, and we look into the buyer's other inboxes too.
  • If your service is being farmed, you see the farm better than we do. Name every address you know, or opt out.

We act on the evidence you send, never by reading our customers' mail.

What we tell you, and what we don't

We tell you whether an address was ours and what we did about it. We never tell you who paid for it or what else they hold; we act on that ourselves.

Acceptable use

recvmail is for an agent that needs to receive mail as part of its task. These uses are not acceptable, whoever pays and however few inboxes they take:

  • Getting around a limit a service sets per person: accounts, trials, sign-up credits, votes, purchases, tickets. One timed-entry ticket to a national park for the person you act for is fine; every ticket for a day is not. What counts is what the service means to give each person once, not what its sign-up form allows.
  • Collecting mail by deception: an inbox as the Reply-To: of a phishing message, or a drop for stolen credentials or data.
  • Anything unlawful, reading inboxes you didn't buy, and ignoring 429: a caller that keeps going may be blocked before it reaches the API.

An inbox used this way is cancelled, without refund and without appeal, and its calls answer 410 inbox_cancelled. We may refuse future service to whoever paid for it.

We never cancel an inbox for how much mail it receives or how long it is kept. Heavy use we didn't expect is not abuse.

What we see and keep

Your mail

We don't read it. The operator of the service has the access any host has, and never uses it to look at mail. A message is deleted 5 minutes after you download it, 1 hour after a poll first lists it if you never do, and in any case about 20 minutes after the inbox ends. We keep no copy and no backup: deleted is deleted.

What we look at

  • Routinely, aggregates: counts, sizes and timings, by sender domain and by paying wallet, to see that the service works and how it is used. No addresses.
  • On a case, opened by a report or by a pattern in those aggregates, one inbox's metadata: its lifetime and counts, its sender allowlist and rejections, and for each message the envelope sender, the From: address, size, time and authentication result. Every such look is recorded before anything is shown.
  • Never subjects or content, on a case or otherwise. For the mail this service exists for, the subject is often the secret ("482913 is your code").

What we keep, and for how long

Each period is the most we keep it. We may shorten one, and we lengthen one only by changing this page first.

WhatKept at most
Message content5 minutes after download, 1 hour after a poll first lists it, or until about 20 minutes after the inbox ends
An inbox's record: its id, lifetime, quota, counts, and a keyed hash of the wallet that paid13 months after the inbox ends
What each wallet paid for each inbox: how many calls, their sum, the first and last13 months after the inbox ends
Each payment's own record, with its transaction1 day, then added into the line above; one that never completed, 13 months after the payment
An abuse case: each look and cancel, who took it and why, and the inbox's record3 years after the inbox ends or the case's last action, whichever is later
A domain's opt-out, and how it was verifieduntil withdrawn
Reports mailed to usuntil handled, 30 days at most
Error logs, which can name a delivery's sender and recipient7 days
Sampled request traces: ids, a delivery's sender and recipient, an API caller's approximate location, network and user agent7 days
Usage metrics: inbox ids, counts, sizes, timings, sender domains; no sender addresses3 months
The delivery log of the provider that receives our mail: sender, recipient, subject, result31 days, kept by the provider; we can't shorten it, and don't use it to look at mail

Payments settle on a public blockchain, where the transaction and the paying wallet are public and permanent, outside anything we can delete.

This list is everything we keep. If a legal obligation requires us to preserve a particular record, we keep that record until the obligation ends; content, once deleted, cannot be recovered.

Terms

These terms apply to every paid call. Making one accepts them, for you and for whoever you act for.

  • What you buy. A paid call buys what its route says and nothing else: provision buys an inbox for 75 minutes with a 100 MiB quota, and extend adds 75 more minutes. The price is in the payment challenge before you pay, and nothing is charged afterwards. There is no account and no subscription.
  • Payments are final. They are not refunded: not for an inbox that received nothing, one cancelled under the acceptable-use rules, or one a site wouldn't take. A retry with the same Idempotency-Key is never charged twice.
  • As is. We work to deliver every message, but we don't promise that any message arrives, that any site accepts our addresses, or that the service is available at a given time. Don't use an inbox for an account you will need to recover by email.
  • Liability. As far as the law allows, our liability for anything to do with an inbox is limited to what was paid for it.
  • Cancellation. We cancel an inbox only for use against the acceptable-use rules.
  • Changes. We may change these terms and our prices. A change applies to calls paid after it is published here, never to one already paid.

Security

Report a vulnerability to security@admin.recvmail.net (also in /.well-known/security.txt). Test against inboxes you bought, never anyone else's.