Legal

Acceptable Use Policy

A short, honest list of what will get your server taken away. It exists to keep our network up, our IP ranges clean, and our upstream providers willing to keep selling to us — not to police what business you are in.

Effective 31 July 2026 Version 1.0 Part of the Terms of Service

1How this policy works

This Acceptable Use Policy ("AUP") forms part of the Terms of Service and applies to every Blossom Host service, every account, and everyone you let use them.

You are responsible for what happens on your server, whether you did it, a customer of yours did it, or an attacker who compromised it did it. "I was hacked" explains an incident; it does not end your responsibility for stopping it.

We update this policy as new categories of abuse appear. The version published here is the one in force.

The principle behind it

We sell compute, bandwidth, and IP addresses. Three things put that at risk: breaking the law, harming other people's systems, and getting our nodes or address ranges cut off by the people upstream of us. Everything below is one of those three.

2Illegal activity

You must not use the Services for anything unlawful under United States federal law, California law, or the law of any jurisdiction that applies to you or to the location of the server.

The following are prohibited absolutely, and there is no warning, no grace period, and no refund:

  • Child sexual abuse material — storing, producing, transmitting, or facilitating access to it, in any form. We report this to the National Center for Missing & Exploited Children and to law enforcement, and we preserve all associated records.
  • Human trafficking or the sexual exploitation of any person.
  • Terrorist content, or material that incites or provides instruction for violence against people.
  • Malware operations — writing, hosting, or distributing ransomware, wipers, banking trojans, stealers, or cryptominers intended for deployment on machines you do not own.
  • Command-and-control infrastructure for botnets, ransomware, or stealer operations, including panels, drop servers, and exfiltration endpoints.
  • Trafficking in stolen data — hosting, selling, or distributing stolen credentials, payment card data, identity documents, or breach dumps.
  • Unauthorised access to any system, network, or account you do not own or have written permission to test.
  • Any use that violates United States export control or sanctions law.

Security research, penetration testing, and red-team work are welcome, provided you have documented authorisation from the owner of every target and can produce it on request.

3Network abuse

You must not use the Services to attack, disrupt, or degrade any network, system, or service. Prohibited:

  • Denial-of-service attacks of any kind — volumetric, application-layer, or amplification — whether originated from your server, coordinated by it, or sold as a service from it. Running or reselling a "stresser" or "booter" is an immediate termination.
  • Amplification and reflection — running open resolvers, open NTP, open memcached, open SSDP, or any other service configured in a way that lets it be abused as an amplifier.
  • Intrusion attempts — brute-forcing credentials, exploiting vulnerabilities, or attempting to gain access to systems you do not own.
  • Aggressive scanning of networks you do not own, including mass port scanning and vulnerability sweeps. Scanning generates abuse complaints against our ranges regardless of your intent.
  • Traffic interception or spoofing — forging packet headers, spoofing source IP addresses, ARP or DNS poisoning, or intercepting traffic not addressed to you.
  • Circumventing limits — evading our rate limits, transfer meters, port isolation, or tenant isolation, or attempting to reach another tenant's traffic, storage, or processes.
  • Attacking, probing, or attempting to escape the hypervisor, sandbox, host, or management network of our own infrastructure.

4Spam and messaging

Unsolicited bulk messaging is the fastest way to get an IP range blocklisted, which harms every customer sharing it. Prohibited:

  • Sending unsolicited bulk email, or any email that violates the CAN-SPAM Act or equivalent law where your recipients are.
  • Sending to purchased, scraped, harvested, or otherwise non-consensual recipient lists.
  • Operating an open relay or open proxy that permits third-party mail injection.
  • Forging mail headers, envelope senders, or return paths.
  • Bulk unsolicited messaging on any other platform — SMS, Discord, Telegram, or otherwise — where it breaches that platform's rules or applicable law.
  • Hosting any service or content advertised through spam sent from anywhere, including spam you did not send yourself.

Outbound SMTP may be filtered or blocked by default. If you need to send legitimate transactional mail, open a ticket and tell us about your volume and list practices.

We use limited network-flow metadata to identify these behaviors before they generate external complaints. We do not inspect packet contents or customer files as part of routine abuse monitoring. Reports may be sent to abuse@blossomhost.us; include the implicated IP address, timestamp and time zone, and relevant log excerpts, but do not email illegal images or contraband.

5Fraud and identity

Prohibited:

  • Phishing — hosting, building, or distributing pages, kits, or infrastructure designed to capture credentials or payment details by impersonation.
  • Impersonating any person, business, or institution, including using a brand, logo, or domain designed to be mistaken for one.
  • Carding — testing, validating, or exploiting stolen payment card or bank account data.
  • Advance-fee fraud, investment fraud, romance fraud, fake stores, and comparable schemes.
  • Trading in stolen or fraudulently obtained accounts, credentials, or gift cards.
  • Obtaining Blossom Host services themselves by fraud — false identity, a payment instrument you are not authorised to use, or a chargeback used as a substitute for paying. See Terms section 8.

6Resource abuse

Shared nodes work because no single tenant consumes everything. Prohibited on shared plans:

  • Sustained resource consumption that materially degrades other tenants — including sustained full-core CPU load across all allocated cores, storage I/O saturation, or sustained line-rate network use.
  • Cryptocurrency mining, and distributed-compute or proof-of-work schemes of any kind, on any shared plan. This is a hard rule: it is uneconomic for us at our prices and it degrades every neighbour. It is permitted on dedicated bare metal where the machine is entirely yours.
  • Deliberately evading transfer accounting or rate limiting.
  • Using a plan as bulk storage for material unrelated to a running workload, where that use is out of proportion to the plan you bought.

Published transfer allowances are fair-use figures. If you are heading toward a limit, talk to us — the Priority Bandwidth add-on and larger plans exist for exactly this, and we would rather sell you capacity than throttle you.

7Endangering our infrastructure

This section is the one most likely to affect an otherwise ordinary customer, so it is worth reading carefully. You must not do anything that puts our ability to operate at risk, including:

  • Any activity that causes an upstream provider, datacenter, transit provider, machine marketplace, or connectivity provider to suspend, terminate, throttle, or threaten our account or our hardware.
  • Any activity that gets an IP address or range assigned to us listed on a DNS blocklist, a reputation blocklist, or an abuse database. Our ISP-line addresses are a small, finite, and clean block, and their reputation is the product. Burning one address harms every other customer on that node and costs us capacity we cannot quickly replace.
  • Generating a volume or pattern of abuse complaints that we, in our reasonable judgement, cannot sustain the cost of handling.
  • Any activity that draws law-enforcement seizure, a court order, or a registrar or regulator action against our infrastructure.
  • Reselling, sublicensing, or rebranding the Services to third parties without our prior written consent. Ask us — we are usually willing, but we need to know who is behind an address when a complaint arrives.
Why this is broad

We depend on a small number of upstream relationships. When one of them tells us to remove a customer, we do not get to litigate it — we comply or we lose the node and everyone on it. This section lets us act quickly in that situation. We will always tell you what happened and why.

8Residential seats — additional rules

Residential seats run on machines connected through real residential internet connections belonging to real households. Abuse there does not just cost us a server — it can get a private individual's home internet disconnected, and it can end our access to an entire class of supply.

On residential seats you additionally must not:

  • generate any traffic likely to draw an abuse complaint to the line's owner or their ISP;
  • send email or any bulk messaging whatsoever;
  • run any scanning, probing, or automated authentication attempts against third-party systems;
  • saturate the line — these are shared household connections, not datacenter uplinks;
  • host anything that attracts law-enforcement attention to a residential address; or
  • attempt to determine, publish, or make use of the physical location or subscriber identity behind the connection.

Enforcement here is stricter and faster than elsewhere, and we will suspend first and discuss afterwards.

9What this policy does not do

We are deliberate about what we do not claim authority over.

We do not vet, approve, or police your business model, and this policy is not a general requirement that you comply with the terms of service of every website you connect to. Whether a particular use of your server is permitted by a third-party service is a matter between you and that service. Under Terms section 10, determining that and complying with it is entirely your responsibility, and you indemnify us for any dispute arising from it under Terms section 18.

What this means in practice: we are not going to ask what you are automating, and we do not want a copy of your scripts. But if a third party sends us a valid legal demand, or an upstream provider requires us to act, we will act — and section 7 is what we act under.

We also make no representation that any IP address we assign you will be accepted, permitted, untracked, or treated in any particular way by any third-party service, now or later. Reputation changes, and it is not something we can warrant.

10Enforcement

When we believe this policy has been breached, we may take any of the following steps, in any order, with or without prior notice:

ActionWhen we typically use it
Notice — we contact you and ask you to fix itFirst-time, low-harm, plausibly accidental. A compromised server emitting traffic.
Filtering or throttling — we block a port or limit a rateOngoing harm we can contain without taking you offline.
Suspension — the server is powered off, data retainedActive harm, an upstream demand, or an unanswered notice.
Termination — the account is closed, servers destroyed, no refundSection 2 categories, repeat breaches, or anything that has already cost us a node or an address range.
Preservation and disclosure of recordsWhere required by law, by valid legal process, or to respond to a payment dispute or law-enforcement request.

Termination for breach of this policy carries no refund of any kind, including the unused portion of a prepaid term. Suspension does not pause or extend your billing term.

If your server is causing harm because it has been compromised, tell us. We are far more helpful to a customer who reports it than to one we discover.

We may also charge our reasonable costs of handling an abuse incident you caused, including staff time, delisting fees, and any charge passed to us by an upstream provider.

11Reporting abuse

To report abuse originating from a Blossom Host address, email ben@blossomhost.us with:

  • the offending IP address;
  • timestamps with a stated timezone;
  • relevant logs, headers, or packet captures; and
  • a contact we can reply to.

We investigate every credible report. Reports with enough detail to identify the responsible server are actioned considerably faster than those without.

For law-enforcement requests, preservation requests, and valid legal process, use the same address and identify yourself and your agency.