Acceptable Use and Abuse Policy
For all F13 customers, services and authorised users
Last updated: 16 July 2026
Important information
This Policy forms part of the terms on which F13 supplies services. It also explains how to report suspected abuse involving an F13 service, IP address or sponsored domain. Send actionable abuse reports to abuse@f13.co.uk.
1. About this Policy
1.1 This Acceptable Use and Abuse Policy (Policy) sets out the standards that apply when F13 Limited provides domain registration, DNS, hosting, email, connectivity, network, cloud, managed, support or other technology services (Services).
1.2 This Policy forms part of the agreement between F13 and each customer. It applies to the customer, its employees, contractors, household members, visitors, end users, resellers and any other person who accesses or uses the Services through the customer. The customer must take reasonable steps to ensure that all such users comply with this Policy.
1.3 This Policy is intended to protect customers, Internet users, F13, our suppliers, registries and networks from unlawful, abusive, insecure or disruptive use. It is not exhaustive. Conduct may breach this Policy where it is materially similar to an expressly prohibited activity or creates a comparable legal, security or operational risk.
1.4 Nothing in this Policy requires a person to give up a statutory right. Where a mandatory law, regulation, registry rule or court order conflicts with this Policy, that requirement takes priority.
2. General standard of use
2.1 You must use the Services lawfully, responsibly and in a way that does not harm other people, systems, networks, services or reputations.
2.2 You must not use, permit or assist the use of the Services to commit, facilitate, encourage, conceal or prepare for unlawful activity.
2.3 You must not use the Services in a way that materially interferes with their normal operation, degrades service for other users, avoids an agreed technical restriction, or imposes an unreasonable burden on shared infrastructure.
2.4 You must follow reasonable technical, security and operational instructions that we issue in relation to the Services, including instructions needed to remedy an active vulnerability, compromised account or abuse incident.
3. Unlawful, fraudulent and harmful activity
3.1 You must not use the Services for fraud, theft, deception, phishing, credential harvesting, impersonation, identity misuse, money laundering, unlawful gambling, sanctions evasion, trafficking in prohibited goods or services, or any other criminal activity.
3.2 You must not create, store, publish, transmit, link to, promote or make available material that is unlawful, including child sexual abuse material, unlawful terrorist content, credible threats of violence, unlawful harassment or stalking, or material that unlawfully incites hatred, violence or criminal conduct.
3.3 You must not publish or transmit material that unlawfully infringes another person’s copyright, trade mark, database right, privacy, confidentiality, data protection or other legal rights.
3.4 You must not knowingly make a false statement, forge evidence or conceal material facts when registering a service, reporting abuse, responding to an investigation or requesting an operation on a domain name.
3.5 You must not use the Services to misrepresent your identity, your authority, the source of a communication, the ownership of a domain or website, or your relationship with another person or organisation.
4. Security and network integrity
4.1 You must not gain or attempt to gain unauthorised access to any account, device, system, data, network or service, or exceed the permission given to you.
4.2 You must not scan, probe, test or exploit a system or network without the owner’s express permission. Legitimate security testing is permitted only where it is authorised, appropriately scoped and carried out so as not to disrupt third parties or shared infrastructure.
4.3 You must not create, install, host, distribute or control malware, ransomware, spyware, worms, viruses, botnets, malicious scripts, exploit kits, credential theft tools or command-and-control infrastructure.
4.4 You must not carry out or facilitate denial-of-service attacks, distributed denial-of-service attacks, packet flooding, amplification attacks, resource exhaustion or deliberate interference with another service.
4.5 You must not falsify source addresses, manipulate routing or message headers to conceal origin, circumvent authentication or access controls, or defeat technical restrictions, usage controls or security safeguards.
4.6 You must take reasonable steps to keep systems and software secure, apply relevant updates, protect credentials, restrict administrative access, and prevent your Services from being used as an open mail relay, open proxy, insecure recursive DNS resolver or other facility that can readily be abused.
4.7 You must notify us promptly if you know or reasonably suspect that an account, device, domain, mailbox, website, server or other Service has been compromised or is being used without authority.
5. Email, messaging and unsolicited communications
5.1 You must not send or facilitate unsolicited bulk messages, unsolicited commercial email, spam, spamvertising, mail bombing, chain messages or substantially similar communications.
5.2 Commercial and direct marketing messages must comply with applicable law, accurately identify the sender, use lawful contact data, and include a clear and effective method of opting out where required.
5.3 You must not continue to send marketing messages to a recipient who has withdrawn consent or made a valid request not to receive them.
5.4 You must not harvest, scrape, buy, sell or use email addresses or contact lists where doing so would be unlawful or contrary to the reasonable expectations of the people concerned.
5.5 You must not forge or materially obscure message headers, sender identity, return paths or routing information, or use a third party’s systems to relay messages without permission.
5.6 You must take reasonable steps to prevent mailing lists, web forms, autoresponders, contact forms and customer systems from being abused to send spam or malicious content.
6. Hosting, websites, applications and stored content
6.1 You are responsible for content, applications, code and data placed on or transmitted through your Services, and for ensuring that you have the permissions and licences needed to use them.
6.2 You must not host or operate phishing pages, fraudulent storefronts, malware distribution sites, credential theft services, botnet infrastructure, piracy services, counterfeit-goods operations or services primarily designed to evade lawful enforcement.
6.3 You must not knowingly store or disclose personal data, confidential information or private communications without a lawful basis or authority.
6.4 You must not use shared hosting, cloud or managed infrastructure in a way that causes persistent excessive CPU, memory, storage, database, bandwidth, process or network consumption that materially affects other customers. Applicable limits may be stated in the Order or service description.
6.5 You must maintain appropriate independent backups unless the Order expressly includes a managed backup service. A breach of this Policy does not transfer responsibility for your data or backups to F13.
7. Domain names and DNS
7.1 You must not register, configure or use a domain name or DNS service for phishing, malware, fraud, impersonation, spam, botnet control, unlawful content or any other activity prohibited by this Policy.
7.2 You must provide and maintain complete and accurate registration and contact information, respond to reasonable validation requests and comply with applicable registry and registrar rules.
7.3 You must not knowingly register or use a domain name in a way that unlawfully infringes another person’s rights, amounts to passing off, or falsely suggests an affiliation or endorsement.
7.4 You must not use fast-flux, domain-generation, DNS-tunnelling or similar techniques primarily to conceal or sustain abusive activity, evade detection or frustrate lawful investigation.
7.5 A complaint about ownership, trade marks, passing off or entitlement to a domain may need to be determined by the applicable registry dispute process, court or other competent body. F13 is not required to decide a complex legal dispute merely because an abuse complaint has been made.
7.6 We may place a domain or DNS service on hold, lock, suspend, redirect or otherwise restrict it where required or permitted by applicable registry rules, a lawful authority, a court order, a supplier, or where proportionate action is reasonably necessary to address serious abuse or security risk.
8. Connectivity, networks and equipment
8.1 You must not use a connectivity or network service to interfere with radio services, telecommunications networks, routing, addressing, network management or other users’ access to services.
8.2 You must not connect unlawful, unsafe, non-compliant or deliberately interfering equipment, or alter managed or supplier-owned equipment without permission.
8.3 You must not resell, share or provide public access to a Service where the Order prohibits this, or present yourself as authorised to resell F13 services without our written agreement.
8.4 Where a Service is described as unlimited, fair use and technical limits may still apply to protect network integrity and other users. We will not use this clause to impose an undisclosed routine usage charge or arbitrary restriction.
9. Resellers and downstream users
9.1 A customer that resells, bundles, manages or provides Services to downstream users remains responsible for compliance with this Policy and must maintain reasonable abuse contacts and processes for those users.
9.2 A reseller must not obstruct or unreasonably delay an abuse investigation, conceal the identity of a downstream customer where disclosure is lawfully required, or continue supplying a Service where serious abuse remains unresolved.
9.3 Where requested, a reseller must provide its downstream terms, relevant customer contact details and reasonable evidence of the steps taken to investigate and remediate abuse.
10. Reporting abuse
10.1 Suspected abuse involving an F13 service, network, IP address or sponsored domain should be reported to abuse@f13.co.uk. This address is monitored by personnel able to assess and act on actionable abuse reports.
10.2 Please include, where available: the affected domain name, IP address, URL, mailbox or account; the nature of the alleged abuse; relevant dates, times and time zone; full message headers or logs; screenshots or other supporting evidence; and your contact details.
10.3 We will normally acknowledge an abuse report within one Business Day and in all cases within five working days. An acknowledgement is not a finding that abuse has occurred.
10.4 Where there is an immediate threat to life, safety or property, contact the police or relevant emergency service first. In the United Kingdom, call 999 for an emergency.
10.5 General support enquiries, billing issues and complaints about F13 customer service should be sent through our normal support or complaints channels rather than the abuse address.
10.6 You must not knowingly submit a false, malicious, misleading or repetitive abuse report, or use the abuse process to harass another person or gain an improper commercial advantage.
11. Investigation and co-operation
11.1 We may investigate suspected abuse and may request information, evidence, corrective action or confirmation from the customer, registrant, user, reporter, supplier or another relevant party.
11.2 Where lawful and reasonably necessary, we may review relevant logs, metadata, account information, configurations, traffic indicators and hosted content to identify, contain or remediate abuse or a security incident.
11.3 We may preserve and disclose relevant information to a customer, registrant, host, network operator, supplier, registry, Nominet, regulator, professional adviser or law-enforcement body where necessary and lawful. Personal data will be handled in accordance with our Privacy Notice and applicable law.
11.4 We may refer a report to the party better placed to investigate it, including the actual hosting provider, upstream carrier, registry, registrar, platform provider or rights-enforcement process.
11.5 We are not required to disclose confidential information, security methods, personal data or the detailed outcome of an investigation where disclosure would be unlawful, compromise security, prejudice an investigation or infringe another person’s rights.
11.6 We do not undertake to monitor all customer content or communications and the absence of action does not amount to approval of any activity.
12. Enforcement and remedial action
12.1 We will act reasonably and proportionately, taking account of the seriousness, urgency, evidence, impact, customer history, whether a system has been compromised, and the steps taken to remedy the issue.
12.2 Depending on the circumstances, we may issue a warning, require information or remediation, reset credentials, block ports or traffic, rate-limit, quarantine, remove or disable content, suspend an account or Service, restrict DNS or a domain, notify relevant parties, or terminate the affected Agreement.
12.3 Where there is an urgent legal, security, safety or network-integrity risk, or where a registry, supplier, court or lawful authority requires action, we may act immediately and without prior notice. Otherwise, we will normally give reasonable notice and an opportunity to remedy the breach.
12.4 Where a customer is the innocent victim of compromise, our priority will ordinarily be containment and remediation. We may nevertheless suspend or restrict the affected Service until the risk is controlled.
12.5 Charges may continue during a suspension caused by a breach, compromise or failure to take required remedial action, subject to the Agreement and any mandatory consumer or regulatory rights.
12.6 Repeated breaches, deliberate abuse, failure to co-operate, or a single serious incident may result in termination and refusal of future service.
12.7 A customer may challenge our handling of an abuse matter through the F13 Complaints Procedure. A complaint does not require us to reverse urgent protective action while the underlying risk remains.
13. Changes to this Policy
13.1 We may update this Policy to reflect changes in law, regulation, registry requirements, technology, security threats, supplier requirements or the Services.
13.2 The current version will be published on our website with its last-updated date. Material changes affecting an existing recurring Service will be notified in accordance with the applicable Terms, except where urgent legal or security action is required.
14. Contact details
14.1 Abuse reports: abuse@f13.co.uk
14.2 General enquiries and support: office@f13.co.uk or +44 (0)114 361 0113.
14.3 Website and contact information: https://f13.co.uk/contact/
14.4 F13 Limited is registered in England and Wales under company number 17045453.