Skip to content
All policies

Abuse Prevention Policy

Last updated 4 July 2026

This page covers how outr protects the deliverability, reputation, and integrity of the inboxes and domains behind your outreach, and how you can report abuse. It works alongside our Acceptable Use Policy, which sets out what you may and may not do; here we focus on the controls we run to keep the shared sending environment healthy.

Many customers send through inboxes and domains we set up, and in some cases through a shared sending environment. Abuse by one account can hurt deliverability for everyone. The controls below exist to stop that.

1. Guardrails at the point of building

Before the agent builds a campaign, compliance guardrails run first, with no AI and no charge. They refuse:

  • requests to target consumers rather than business contacts, and requests to use purchased or rented lists;
  • harmful requests, including phishing, malware, fraud, adult content, and harassment; and
  • channels outr does not support (for example cold calling, SMS, ads, or scraping other platforms).

outr is for legitimate business-to-business outreach only. A refused request gets a templated reply and does not proceed.

2. The approval gate

Every campaign starts as a draft. Nothing sends until you review the leads and the copy and click Approve and launch. No cron job, webhook, or background process starts sending on its own. This keeps a person in control of every send and is our strongest safeguard against accidental or abusive sending. You decide who is contacted and what is said; outr runs the campaign you approved.

3. Unsubscribes and bounces are suppressed

  • Every message we send carries a one-click unsubscribe.
  • Unsubscribes and bounces are suppressed for good, so anyone who opts out or whose address bounces is never contacted again.

4. Deliverability protections

  • Inbox warmup. New inboxes are warmed up before and while they are used, on a warmup-safe schedule, so sender reputation builds gradually.
  • Volume and rate limits. Sending is bounded by per-inbox daily send limits and per-account plan capacity. Schedules spread sends over time rather than blasting them.
  • Sender identity. Messages must identify the sender with a real, working reply address and must not use deceptive subject lines or headers, in line with our Acceptable Use Policy and anti-spam law.

5. Anti-spam law

You and outr both rely on the controls above to stay within anti-spam law:

  • United States (CAN-SPAM). Every campaign must identify the sender, use a real and monitored reply address, avoid deceptive subject lines and headers, and honor opt-outs promptly. Our one-click unsubscribe and permanent suppression support this.
  • Canada (CASL). CASL needs a lawful basis (consent or a recognized business relationship) to send commercial email, clear sender identification, and a working unsubscribe. You are responsible for having a lawful basis to contact each Canadian recipient you target.
  • European Union and United Kingdom. Outreach to business contacts must rest on a lawful basis under the GDPR and UK GDPR and follow ePrivacy and national rules, with an easy opt-out on every message.
  • Everywhere else. You must follow every law that applies to you and to your recipients, wherever they are, including local anti-spam, marketing, and data-protection rules. The suppression, unsubscribe, and warmup controls we run help your compliance, but they do not replace your own duty to have a lawful basis to contact each recipient.

6. Inbox scrub when an account leaves

When an account lapses, cancels, or is deleted, its inboxes are released and a daily scrub detaches them from all campaigns and resets the sender display name to a neutral value. The part of the address before the @ cannot be changed (a limit of our email-sending provider), so it is not reset, but the display name is. Pooled inboxes become claimable again only after this scrub; dedicated inboxes are cancelled and never reused. This stops one customer's identity or sending history from leaking into another's.

7. Monitoring

We watch campaign engagement and inbox health (open, reply, and bounce signals, and inbox-health snapshots), surface benchmarked warnings, and review pool health. Abnormal patterns that put deliverability or the shared pool at risk get investigated.

8. We can pause risky campaigns

We can pause, suspend, or stop any campaign, inbox, or account that, in our reasonable judgment, creates spam, deliverability, legal, or reputational risk, or breaks this policy, our Acceptable Use Policy, or our Terms of Service. Where we can, we will tell you and give you a chance to fix it, but we may act immediately where the risk to the shared environment or to other people is serious. We are not liable to you for action taken in good faith to protect the sending environment.

9. Your responsibilities

You stay responsible for the recipients you pick, the content you approve, and your compliance with anti-spam and data-protection law, as set out in our Terms of Service and Acceptable Use Policy. You confirm you have a lawful basis and the right to contact the audience you target. You must not try to bypass the guardrails, the approval gate, the suppression lists, or the sending limits.

10. Reporting abuse

If you have gotten unwanted messages sent through outr, or you think an account is abusing it, report it to us at support@tryoutr.io. Include the sending address, the message (with full headers where you can), and the date you received it. We investigate every report and take appropriate action, which may include suppression, pausing or stopping campaigns, or ending an account.

11. How this fits together

Read this alongside our Acceptable Use Policy, which lists prohibited content and uses in full, and our Terms of Service.

12. Changes

We may update this policy as our controls evolve. Material changes show up here with a new version and date.

13. Contact

For abuse reports and general or legal questions, email support@tryoutr.io.

Questions about this page? Email support@tryoutr.io.