Anti-Spam Policy
Draft pending legal review. Placeholders in [brackets] will be completed before this document takes effect.
Last updated 30 September 2026
This policy applies to every e-mail sent from an application hosted on Forge, operated by Beesworx Groupe (Pty) Ltd (Reg. No. 2024/800456/07) ("Beesworx", "we"), and in particular to e-mail sent through Forge's managed e-mail service. It forms part of the Acceptable Use Policy and the Terms of Service. A breach of this policy is a breach of those documents.
South African law restricts unsolicited electronic communications, including section 45 of the Electronic Communications and Transactions Act 25 of 2002 (ECTA), section 69 of the Protection of Personal Information Act 4 of 2013 (POPIA), and, where it applies, section 11 of the Consumer Protection Act 68 of 2008 (CPA). You are responsible for complying with them and with the law of every country you send to. [ATTORNEY TO CONFIRM THE STATUTORY REFERENCES AND ANY OTHER APPLICABLE LAW].
1. What Forge's managed e-mail is for
Forge's managed e-mail is for transactional e-mail: messages a person expects because of something they did in your application, such as sign-in codes, password resets, receipts, notifications and replies. It is not a bulk or marketing e-mail service. Each message sent through the platform's e-mail relay is marked as transactional, and the relay refuses marketing sends, carbon copies, blind copies, attachments and scheduled sends.
If you need to send newsletters or marketing campaigns, use a dedicated e-mail marketing provider under its own terms, configured as your own provider, and comply with this policy anyway.
2. Consent and unsolicited e-mail
You may not use Forge to send, or to help anyone send, unsolicited commercial e-mail ("spam"). In particular:
- Send direct marketing only to people who have consented to receive it, or to your existing customers about your own similar products or services, as POPIA section 69 allows, and keep a record of that consent.
- Do not send to purchased, rented, scraped or harvested address lists, or to addresses generated by guessing.
- Every marketing message must identify you, give a valid contact address, and offer a free, working way to opt out. Honour opt-out requests promptly and do not send to that address again.
- Do not disguise the sender, forge headers, use misleading subject lines, or impersonate another person or brand.
- Do not use Forge to send phishing, malware, or messages that promote unlawful goods or services.
These rules apply to every e-mail your application sends, whether through Forge's managed e-mail, your own provider, or any other route.
3. Sender domains
To send through Forge's managed e-mail, your organisation must prove it controls the domain it sends from. You add the domain in the dashboard, publish a TXT record Forge gives you, and publish the DKIM and sender records the platform returns. Forge sends only from domains your organisation has verified this way; a message whose From address is on any other domain is refused. A domain another customer has already verified cannot be claimed by a second organisation. If the proof record is removed, the domain stops being verified at the next check.
4. Sending limits
Every organisation sending through Forge's managed e-mail has hourly and daily sending limits set by its plan. The current limits are:
| Plan | Per hour | Per day |
|---|---|---|
| Free | 50 | 300 |
| Indie | 500 | 5,000 |
| Agency | 2,000 | 20,000 |
[OWNER TO CONFIRM THESE PLAN NAMES AND LIMITS MATCH THE PLANS SOLD ON FORGESERVER.APP.] A message sent to several recipients counts once per recipient, and a single message may have at most 50 recipients. Sends above a limit are refused until the window resets. Limits exist to protect the platform's sending reputation for every customer; do not try to get around them with multiple organisations, accounts or keys.
5. Direct mail from your apps
Outbound connections from your applications directly to other mail servers on port 25 may be blocked at the network layer [OWNER TO CONFIRM WHETHER THE OUTBOUND PORT BLOCK WILL BE ENABLED ON FORGESERVER.APP]. Send through Forge's managed e-mail or through your own e-mail provider's authenticated submission service instead.
6. Bounces and complaints
Keep your lists clean. Remove addresses that bounce and people who complain or unsubscribe. The platform's e-mail provider keeps a suppression list and may pause sending when bounce or complaint rates are high; because that reputation is shared with other customers, we treat high bounce or complaint rates from your organisation as a breach of this policy. [OWNER TO CONFIRM BOUNCE AND COMPLAINT RATE THRESHOLDS, IF ANY ARE TO BE STATED].
7. Enforcement
We may investigate any complaint or signal of spam from your organisation. Depending on severity, we may, without notice where there is active harm:
- rotate or revoke your organisation's e-mail sending credentials, which stops every app in the organisation from sending through the platform until new credentials are issued;
- remove a verified sender domain;
- stop the application responsible; or
- suspend your organisation under the suspension ladder in the Acceptable Use Policy. A suspended organisation cannot send through Forge's managed e-mail.
8. Reporting spam
If you receive spam sent from an application hosted on Forge, report it to abuse@beesworx.co.za with the full message headers. See the Acceptable Use Policy for how reports are handled.