Skip to content
CodexaCloud

Acceptable Use Policy

Last updated:

This policy exists for two reasons: to keep our network stable for everyone on it, and to keep our IP ranges out of blocklists. Both directly affect whether your site loads and whether your email is delivered, so we enforce it seriously.

1. Prohibited content and activity

You may not use our services to host, transmit or facilitate:

  • Phishing and fraud — pages impersonating banks, payment providers, couriers or any other organisation in order to collect credentials or payment details
  • Malware — viruses, ransomware, trojans, exploit kits, or command-and-control infrastructure
  • Unsolicited bulk email — spam of any kind, including mail sent to purchased, scraped or otherwise non-consenting lists
  • Child sexual abuse material — reported immediately to the relevant authorities, with the account terminated without notice and without refund
  • Attacks on others — port scanning, brute-force attempts, denial of service, or unauthorised access to any system
  • Copyright and trademark infringement — including pirated software, media or counterfeit goods
  • Content that is illegal in your jurisdiction or ours, or that incites violence or unlawful discrimination

2. Fair use of shared resources

Shared and reseller plans described as offering “unlimited” sites or “unmetered” bandwidth are sold on the basis of normal website use. They are not a substitute for a VPS or dedicated infrastructure. On those plans you may not:

  • Use the account primarily for file storage, backup, archiving or media distribution rather than for serving a website
  • Run cryptocurrency mining, distributed computing, public proxies, VPN exit nodes or Tor relays
  • Run sustained CPU-intensive processes, long-running daemons or heavy background job queues
  • Run public trackers, streaming services or high-volume file-sharing endpoints

Each plan carries specific CPU, memory, process and I/O limits, published in the knowledge base. Where an account exceeds them we throttle it rather than suspending it, and we contact you to discuss the right plan. We do not silently bill overages.

3. Email

  • Mail may only be sent to recipients who have genuinely opted in. Keep evidence of consent.
  • Every marketing message must carry a working unsubscribe mechanism, honoured promptly.
  • Shared hosting and mailbox plans are limited to 500 recipients per hour per mailbox. Bulk campaigns must go through a dedicated sending service.
  • Forged headers, misleading subject lines and false sender identities are prohibited.
  • We reserve the right to rate-limit or block outbound mail from an account whose bounce or complaint rate threatens the deliverability of our ranges.

4. Security obligations

Compromised sites are the most common source of abuse on any hosting platform, and keeping yours patched is your responsibility. You must:

  • Keep applications, themes, plugins and dependencies up to date
  • Use strong, unique credentials and enable two-factor authentication
  • Remove software you no longer use, rather than leaving it unpatched
  • Act promptly when we notify you of a compromise

Where a compromised account is actively sending spam or serving malware, we may suspend it immediately to protect the network and others on it, then work with you to clean and restore it.

5. Reporting abuse

Report abuse to abuse@codexacloud.com. Please include the URL or IP address, the nature of the problem, and — for email complaints — full message headers.

We acknowledge reports within a few hours and act on verified phishing and malware reports the same day. We do not disclose customer identities in response to a report except where required by a valid legal order.

6. Enforcement

Depending on severity, we may:

  1. Contact you and ask you to resolve the issue within a stated period
  2. Throttle or restrict the affected resource
  3. Suspend the affected site or the account
  4. Terminate the account without refund
  5. Report the matter to law enforcement

For most issues — a resource limit exceeded, an out-of-date plugin — we start at step one and would rather help you fix it. For phishing, malware, child sexual abuse material and active attacks, we act immediately.