Acceptable Use Policy
Last updated 9 August 2026
This policy is issued by Suburban Australia (ABN 24 550 297 597), trading as Suburban Secure, the operator of Can They Email As Me?.
General fair use
Can They Email As Me? is intended for reasonable, lawful checks of public domain and email-security signals, including checks by domain owners, administrators, advisers, customers, suppliers and people assessing a domain before trusting email from it. You do not need to own a domain to run an ordinary public check because the service reads public information only. Ownership verification is required for private monitoring, reporting and remediation features.
Use must remain proportionate and must not unreasonably affect the service, other users or the systems being checked. Published plan quotas, technical limits, caching and rate limits form part of this fair-use policy.
Prohibited use
You must not use or attempt to use the service to:
- break any applicable law, facilitate fraud, phishing, impersonation, harassment or other harm;
- bulk-submit, scrape or enumerate domains or results without our prior written permission;
- bypass rate limits, access controls, plan limits, account verification, CAPTCHAs or other safeguards;
- guess, enumerate, obtain or access another person’s private result link, account, workspace or non-public data;
- falsely claim control of a domain or upload DMARC reports or sender information for a domain you are not authorised to administer;
- interfere with mail delivery, DNS, websites, networks or third-party services, or instruct another person to publish unsafe DNS changes;
- probe, attack, overload, disrupt, reverse engineer or introduce malicious code into the service, except for good-faith research conducted under our responsible disclosure guidance;
- use results to create misleading security claims, public weakness lists, harassment campaigns or deceptive marketing;
- resell, mirror or commercially reproduce the service or its data at scale without permission; or
- help another person do any of the above.
Automation and research
Ordinary individual checks are welcome. Automated, scheduled, bulk or research use requires our prior written approval unless it is an account feature expressly provided for that purpose. Approval may include limits on scope, rate, retention, publication and notification. Public DNS data is still subject to responsible use; availability of information does not authorise harmful collection or publication.
Results and sharing
Results are point-in-time automated observations with known limitations. Do not present them as proof that an organisation is insecure, compromised or negligent. If you share or publish a result, preserve its context, date and limitations, consider the risk of helping an attacker, and comply with applicable law and professional obligations. Private result links should be shared only with intended recipients.
Enforcement
We may cache or refuse checks, throttle requests, suspend or close accounts, revoke access, preserve relevant security evidence, or report conduct where reasonably necessary to protect the service, other users, third parties or comply with law. We may act without notice where urgent security, abuse or legal concerns require it. Where appropriate, we may ask you to reduce or change otherwise legitimate high-volume use.
No service guarantee
Access is provided on an “as is” and “as available” basis. Fair-use access does not guarantee availability, reliability, scan completion, monitoring frequency, alert delivery, retention or continued access to any feature. See the Terms of Use for the full service limitations.
Contact
Ask about approved bulk/research use or report suspected abuse through support or [email protected].