Skip to content

Acceptable Use Policy

Last updated 16 August 2026.

Short version: do not use our servers to harm other people, and do not do things that get our IP space blocklisted. Everything below is detail on those two ideas.

Never, under any circumstances

  • Child sexual abuse material. Reported to the authorities, terminated immediately, no refund, no discussion.
  • Attacking other systems. DDoS, port scanning at scale, brute-forcing, exploitation of hosts you do not own.
  • Malware and botnets. Distributing it, hosting a command-and-control node, or running as part of one.
  • Phishing. Impersonating a bank, a brand, a government service, or anyone else to harvest credentials.
  • Spam. Unsolicited bulk email, SMS gateways for bulk messaging, or supporting infrastructure for either.
  • Fraud. Carding, credential stuffing, stolen-data marketplaces, money-mule coordination.
  • Content that is illegal where the server sits, or that we are ordered by a competent authority to remove.

Restricted, but negotiable

  • Outbound SMTP (port 25) is closed by default. Ask, tell us what you are sending and roughly how much, and we will usually open it. This is spam control, not an upsell — there is no fee to have it opened.
  • Public proxies, VPN exits and Tor exit nodes. Tell us first. Tor exits in particular attract abuse complaints that land on us, so we need to agree it in advance rather than find out via our upstream. Relays and bridges are fine without asking.
  • Mining. Not banned, but a plan's CPU allowance is shared and sustained 100% usage on every core will get you throttled. If mining is the plan, say so and we will price it properly.
  • Adult content that is legal, consensual and age-verified is allowed. Tell us if it will be high-traffic so we can put you somewhere sensible.

Resource use

Use what you have paid for. If sustained usage degrades other customers on the same node we will contact you and work out either a throttle or a bigger plan. We will not send you a surprise overage invoice, and we will not null-route you without talking to you first — unless an active attack is coming from your server, in which case we act immediately and explain afterwards.

How we handle reports

Abuse reports go to abuse@vpslatch.net and are read by a person. Our normal process:

  1. We look at the report and check it is credible.
  2. We forward it to you and ask you to deal with it, usually within 24 hours.
  3. If it is not dealt with, or it recurs, we suspend.
  4. For anything in the "never" list above, or an attack in progress, we skip to suspension.

We will tell you what the complaint was and who it came from, unless we are legally barred from doing so. We would much rather work with you than terminate you — but we will not put our other customers' deliverability and connectivity at risk for one account.

Reporting abuse to us

Email abuse@vpslatch.net with the IP address, timestamps in UTC, and log excerpts. That gets action. A vague complaint without an IP or a timestamp usually cannot be acted on at all, however genuine it is.