Acceptable Use Policy

Last updated 2026-08-23

This policy exists for one reason: everything that leaves our IP ranges is attributed to us. One tenant running an attack gets the whole range blocklisted, and every other customer on it goes down with them. So the rules below are strict, and we enforce them quickly.

1Scope

This policy applies to every service you buy from CoresServer, to anyone you let use it, and to anything you host on it. You are responsible for your customers and users as if their actions were your own.

2Prohibited outright

These will get a server suspended immediately, without warning:

  • Denial-of-service attacks of any kind, including participating in, controlling, or reselling access to a botnet.
  • Port scanning, vulnerability scanning, brute-forcing, or credential stuffing against systems you do not own.
  • Unsolicited bulk email, whether sent from our network or advertising a service hosted here.
  • Phishing, fake login pages, or impersonating a person, business or government body.
  • Distributing malware, ransomware, or running command-and-control infrastructure.
  • Child sexual abuse material. Reported to the relevant authorities, no exceptions, no appeal.
  • Anything that is a criminal offence where the server is located.

3Restricted, ask first

  • Outbound SMTP (port 25) is blocked by default. Open a ticket describing what you are sending and to whom, and we will usually unblock it. This keeps our ranges off blocklists, which protects everyone here including you.
  • Sustained full-CPU workloads — mining, distributed compute, video transcoding farms. These are shared machines. Tell us first and we will tell you honestly whether the plan can take it.
  • Open proxies, exit nodes and public VPN endpoints. Not forbidden, but they generate abuse reports that we have to answer. Run them responsibly, log nothing you do not need, and expect us to come to you first when a complaint arrives.

4Sanctions and prohibited jurisdictions

Our network is subject to export-control and sanctions law. You may not use our services from, or provide services to, a jurisdiction or party subject to comprehensive sanctions. We block obvious cases at signup; that check is not an assurance that your use is lawful — that remains your responsibility.

5How we enforce this

We suspend first and discuss after.

Abuse complaints are answered in hours, not days. If we spend a day investigating before acting, the IP range is blocklisted or null-routed — and then every customer sharing it goes down, not just the one causing the problem. Suspending one server first is the least damaging option available to us, and this clause is what makes it something we agreed on rather than something we did to you.

A suspension is not a termination. Your data stays where it is. Reply to the suspension email and we will work through it with you. If the report turns out to be wrong or you have fixed the cause, we bring the server straight back.

Repeat or deliberate violations end in termination without refund. For the categories in section 2 we terminate on the first occurrence.

6Reporting abuse

Email abuse@coresserver.com with the IP address, timestamps including timezone, and logs or headers if you have them. We read that mailbox first thing, every day.

Questions about any of this? support@coresserver.com. Reporting abuse? abuse@coresserver.com.