Legal
Sending policy and appeals
This page describes how Refresh protects sending, what a pause looks like, and how an organization admin appeals.
Effective September 30, 2026
1. Start in test mode
New API keys default to Test. Test keys simulate bounces and complaints without touching reputation. Free allows 3,000 messages a month and 100 a day.
2. Limits that protect every sender
A new organization starts with four alert rules e-mailed to the person who created it: a 2% hard-bounce rule and a 0.1% complaint rule that pause sending when they fire, a provider-block rule that holds mail to a blocking provider for four hours, and a delivery-silence rule. Bounce and complaint rules need at least 50 sent messages in their window before they fire. Admins can change or add rules per organization or per domain on Settings → Alerts.
When a rule with Pause sending fires, the platform pauses that domain for a domain-scoped rule, or the organization for an org-wide rule. Provider blocks open a hold on that provider only.
3. What a pause looks like
The console shows the reason and the source. The source is an admin, an alert rule, or the delivery provider. The console also shows how many messages are parked and the next step.
When an alert rule or the delivery provider pauses sending, every admin receives an e-mail. The API answers 403 sending_paused instead of accepting mail it cannot send. Parked messages stay queued and are sent when sending resumes. We do not delete queued mail during a pause.
Trust & Safety holds
Refresh screens outgoing mail and new sending domains for phishing, fraud and impersonation, with rules and an AI review. When a new organization’s mail looks like one of these, the platform holds its sending while a person reviews it. The API answers 403 under_review and the console shows the hold. Every organization admin receives an e-mail, and a reply to it reaches a person. An organization admin cannot resume a hold; we lift it when the review clears, usually within a day. Mail that links to a site on Google’s phishing or malware lists suspends the organization at once and removes its sending domains; its admins receive an e-mail, and a reply reaches a person.
4. Review and appeal
Write to hello@f5send.com. A person replies within 24 hours with the reason in writing and what is needed to resume. An organization admin can resume an alert-driven pause from the console at any time. We do not close a review without a reason.
5. What we do not allow
You may not send:
- purchased, rented, scraped, or harvested lists;
- mail without consent, or without an existing relationship that makes the message expected;
- phishing, impersonation, or a From address that is not yours;
- content that is illegal where it is sent.
The full terms are in the Terms of Service.
6. Provider blocks
The platform classifies the receiving provider’s reply on each bounce or delay. A Pause sending rule opens a hold on that provider for a bounded time. Other providers keep flowing. Every admin receives an e-mail. The e-mail includes the delist form or address when the provider has one. Because the platform operates the sending addresses, we file the delist request where the provider has a form, and you can file one too with the reply text of your message. See the provider blocks guide.