Version: 4 September 2026
This Policy forms part of the Terms of Service. It applies to all Maildroppa accounts, sending channels, forms, landing pages, automations, files, APIs, webhooks and integrations.
1. Permission-based email marketing
Maildroppa is intended for legitimate, transparent and expected communication. You may contact a person only where you have a valid basis under applicable law for the specific message and can demonstrate it on request.
For marketing email to recipients in Germany, this generally requires prior express consent. The narrow existing-customer exception in section 7(3) of the German Unfair Competition Act applies only if every statutory condition is met. A legal basis under data-protection law does not by itself permit electronic direct marketing.
Maildroppa may request evidence of an address’s source, signup flow, consent wording, timestamps, relationship with the recipient and previous messages. A simple statement that “I have permission” is not sufficient during a review.
2. Permitted contact sources
Permitted contacts include those who:
- signed up through your own transparent form and, where required, completed double opt-in;
- gave documented consent that is sufficiently specific as to sender and purpose;
- may lawfully be contacted within an existing customer relationship and receive a clear opt-out;
- receive a specific, expected, non-marketing transactional or service message necessary for the requested service;
- are imported from another system you control while source, notice, legal basis, objection status and required evidence remain intact.
An import or integration does not change the legal quality of a contact. Uploading an address to Maildroppa does not cure missing consent or objection records.
3. Prohibited contact sources and sending methods
You must not use Maildroppa for:
- purchased, rented, borrowed, swapped or brokered lists, including lists obtained from lead sellers;
- addresses scraped, harvested or automatically collected from websites, directories, social networks, public registers or other sources;
- a partner’s or affiliate’s list where the recipient could not reasonably expect the specific Maildroppa customer and communication;
- co-registration or prize promotions using unclear, bundled or unlimited “partner” consent;
- mass cold email, cold-email sequences or automated prospecting without a prior, demonstrable relationship or permission;
- mass messages to role addresses such as
info@,sales@oroffice@without a specific lawful recipient relationship; - list washing, email appending, address enrichment or matching unknown addresses for the purpose of creating sendable contacts;
- re-adding anyone who unsubscribed, objected, complained or hard-bounced unless a demonstrably new lawful basis exists;
- snowshoe spam, domain or IP rotation, frequent sender changes, replacement accounts or any other method used to evade blocks, filters, limits or reputation consequences;
- misleading sender names, reply-to addresses, subjects, preheaders, links, domains or identities;
- hiding link destinations through URL shorteners, redirect chains or similar techniques where this misleads recipients or protection systems;
- sending to addresses created or tested through automated generation, verification or rate attempts.
4. Requirements for every message
Every message must:
- clearly identify the true sender and responsible organisation;
- use an accurate, non-misleading subject and body;
- contain sender and contact information required by law;
- provide a conspicuous, functioning and free unsubscribe method for marketing communication;
- promptly apply unsubscribes, withdrawals, objections, complaints and hard bounces across all relevant lists, segments, automations and connected systems;
- be sent through a verified sender domain and authenticated with the SPF, DKIM and DMARC settings required by Maildroppa or relevant mailbox providers;
- preserve any
List-Unsubscribeand one-click unsubscribe mechanisms supplied by Maildroppa and not interfere with their operation; - comply with the law of the recipient’s country and additional rules for regulated content.
You must not require a login, reason, fee or additional marketing consent to unsubscribe. You must not obscure an unsubscribe link or make it harder to use through deceptive design.
5. Content and activity that is always prohibited
You must not use the service for content or activity that:
- is unlawful or promotes unlawful conduct;
- involves phishing, identity theft, fraud, scams, fake invoices, advance-fee fraud or misleading investment offers;
- distributes malware, malicious code, credential harvesting, hacking services or instructions to bypass safeguards;
- impersonates senders, brands, officials or other people, or deceptively uses manipulated media or deepfakes;
- involves child sexual exploitation, non-consensual intimate content, human trafficking or paid sexual services;
- promotes hatred, violence, terrorism, self-harm or specific threats;
- offers illegal drugs, counterfeit medicines, counterfeit or stolen goods;
- offers weapons, explosives or specific instructions for their unlawful manufacture or use;
- infringes copyright, trade marks, privacy, personality or other third-party rights;
- coordinates false news, manipulated reviews or deceptive political identities;
- harms the security, availability or integrity of Maildroppa or any third party;
- processes special categories of personal data under Article 9 GDPR or criminal-conviction data under Article 10 GDPR without Maildroppa’s prior express written approval.
6. Excluded and approval-only business models
The following business models are excluded because their main purpose typically involves non-permission-based acquisition, deception or unacceptable complaint risk:
- selling, renting, swapping, brokering or enriching contact lists;
- mass cold-email, link-building, lead-generation or appointment-setting services without a demonstrably permission-based audience;
- phishing simulations directed at third parties without a documented mandate and controlled recipient group;
- pyramid or Ponzi schemes, “get rich quick”, guaranteed-return or comparable models;
- unlicensed gambling or unlawful financial, credit, investment, pharmaceutical or health offers;
- pornography, escort or other paid sexual services;
- debt-collection or intimidation campaigns directed at mass-imported recipients;
- political mass communication to lists that were not built voluntarily and verifiably.
The following higher-risk areas may use Maildroppa only with prior written approval and the evidence Maildroppa requests:
- gambling, sports betting or lotteries;
- cryptocurrencies, tokens, NFTs, foreign-exchange trading, trading signals or investment products;
- loans, debt relief, financial advice, insurance or fundraising;
- cannabis, CBD, alcohol, tobacco, vaping or other age-restricted products;
- medicines, supplements, weight loss, medical or therapeutic claims;
- dating, matchmaking, astrology or psychic services;
- affiliate marketing, multi-level marketing, lead generation, recruitment or large applicant campaigns;
- political parties, campaigns, advocacy or belief-based organisations;
- real-estate, franchise or business-opportunity offers with a high cold-outreach component.
Approval is not legal advice and may be withdrawn when facts or risk change. Maildroppa may reject a model not expressly listed where it presents comparable risk. Decisions must not be discriminatory or arbitrary.
7. Review, safeguards and cooperation
Maildroppa may review account and business information, domain ownership, sending patterns, delivery failures, complaints, spam-trap signals, unsubscribe rates, content characteristics and source evidence. There is no published metric below which unlawful sending becomes acceptable. Thresholds may vary with volume, history, mailbox-provider rules and risk.
Based on account age, domain history, recipient source, planned volume and reputation signals, Maildroppa may require gradual volume ramp-up, hourly or daily volume limits, a review pause or additional authentication. New or materially changed senders must follow the specified warm-up and sending pace. Splitting activity across accounts, domains or integrations to evade these limits is prohibited.
You must cooperate truthfully and promptly. Maildroppa may request:
- a description of the business model and audience;
- examples of signup, notice and consent;
- source, time and evidence for a sample of contacts;
- current sender and domain evidence;
- an explanation of unusual bounce, complaint or unsubscribe rates;
- cleansing, reconfirmation or permanent suppression of a dataset.
8. Measures following a violation
Maildroppa may temporarily restrict the affected sending or account while a concern is reviewed. Where recipients, systems, sending reputation or legal compliance face an immediate risk, restriction may occur without prior notice.
Depending on severity, remediability and recurrence, Maildroppa may warn, request evidence or remediation, limit volume, block content or contacts, stop a campaign, suspend an account or terminate for cause. Measures are limited to what is necessary. Unless doing so would prejudice the review or security, Maildroppa will explain the reason and provide an opportunity to respond.
Data export generally remains available where lawful and where it would not distribute harmful, unlawful or security-sensitive data. Legal retention, restriction and evidence obligations remain unaffected.
9. Reporting and appeal
Unwanted email, phishing, illegal landing pages or other violations can be reported through Report illegal content and abuse. Where possible, include full email headers, the recipient address, sending time, exact URL and a short explanation.
Customers may submit a measure for human review through the same channel together with relevant evidence.