Acceptable Use Policy
Version 1.1, 29 September 2026.
fabricatedemail receives mail at disposable addresses: for automated tests, through the API, and for a person, through the inbox page on this site. This policy says what neither may be used for, and it forms part of the Terms of Service.
What you must not do
- Receive mail intended for a real person. Do not give a fabricatedemail address to anyone as a way of receiving their correspondence, and do not use one to intercept mail meant for someone else.
- Abuse another service. You may use an address to sign up somewhere once, as you would your own. Do not use our addresses to create accounts in bulk, to claim a free trial again and again, to get around a ban or a limit another service placed on you, or in any other way that breaks that service's own terms.
- Commit fraud, phishing or spam. This includes using an address as a reply-to or contact address in a fraudulent or deceptive message, as part of an account-takeover attempt, or in any scheme to obtain money, credentials or data by deception.
- Receive or store unlawful content, including content that is illegal to possess or distribute in Sweden or in your own jurisdiction, or content that infringes another person's rights.
- Attack or overload the service: probing for vulnerabilities without our written permission, circumventing the rate limit or the account caps, sharing one account's keys across separate organisations to avoid buying separate accounts, automating the sign-up flow to create accounts in bulk, or automating the inbox page.
- Resell the service as a disposable-mail product to third parties, or build on the API a public page that hands out addresses and shows their mail to anyone. The inbox page on this site is ours to run.
Consequences
We may suspend an account immediately and without notice, at our discretion, where we consider this policy to have been broken or where an account threatens the platform or other customers. Suspension is not a punishment we negotiate in advance: it is how a problem stops.
While an account is suspended, every API request answers 403
and mail addressed to its addresses is dropped and not stored — mail
that arrives during a suspension is gone even if the account is later
reinstated. We will email the account address to say that it happened
and why. Serious or repeated breach ends the account under section 7 of
the Terms.
We do not read stored mail as a matter of course. We may inspect an account's metadata and, where a report or a platform-safety concern makes it necessary, its content, in order to investigate a breach of this policy or to comply with a legal obligation.
Reporting abuse
If mail from a fabricatedemail address, or an address on our domain, has been used against you or your service, write to fabricatedemail-abuse@blackcurrantsecurity.com. The address is monitored by the operator; it is not an automated system.
Please include, where you have them:
- the full address on
fabricatedemail.cominvolved; - the complete message with its headers, or the log entries showing the activity;
- the dates and times, with the time zone;
- what you would like us to do.
We aim to acknowledge a report within two business days. Where a report is substantiated we suspend the account, which stops both API access and mail delivery at once, and we tell you that we have acted. We do not disclose account-holder details in response to a report; a request for those needs valid legal process, sent to the same address.
Our own abuse measures
Sign-up is refused from known disposable-email domains and from
fabricatedemail.com itself. A set of local parts —
abuse, postmaster, security,
support, admin, noreply,
no-reply, hostmaster, webmaster,
info, billing, legal and
dmarc — cannot be registered, so that the addresses a
domain is required to answer on stay ours. There is a per-key rate
limit, and every account has hard caps.