Legal
Terms of Service
The agreement that governs an Infrabox account: what you are buying, what you are not, who the domain is registered to, what access Infrabox holds over the mailboxes it creates, and what happens when either side walks away.
Last updated 19 August 2026. Three clauses below carry more weight than the rest — the registrant identity of your domains (section 6), the administrative access Infrabox holds (section 8), and what does and does not survive termination (section 11). Read those before you buy.
1. The agreement
These Terms of Service (the “Terms”) govern your use of the Infrabox platform and everything bought through it. They are an agreement between Infrabox (“Infrabox”, “we”, “us”) and the person or company that opens the account and pays for the services (“you”). Where you open an account for a company, you confirm you are authorised to bind it, and “you” means that company.
You accept these Terms by creating an account, placing an order or using any part of the service. If you do not accept them, do not use the service.
The Acceptable Use Policy, the Refund Policy and the Privacy Policy form part of these Terms and are incorporated by reference. Where these Terms and one of those documents conflict, these Terms govern — except on questions of what may be sent, where the Acceptable Use Policy governs.
The deliverability SLA published on this site is a draft written for a guaranteed-placement tier that Infrabox does not currently sell. It is not part of these Terms and creates no obligation on either side. Nothing in it should be relied on when deciding to buy.
2. Eligibility and your account
- You must be able to enter a binding contract, and you must use the service for business purposes. This is business sending infrastructure; it is not sold to consumers for personal use.
- The information you give us — billing details, and any contact details you elect to use as a domain registrant under section 6 — must be accurate and kept current. Registrars and registries can suspend a domain over inaccurate registrant data, and that is a consequence we cannot reverse for you.
- You are responsible for everything done under your account, including by anyone you invite to your team and by any sending tool you connect. Keep dashboard logins and relay credentials secure, and tell us promptly if you believe either has been compromised.
- We send provisioning notices, abuse notices and billing notices to the email address on the account. Keep it monitored; a notice sent there is treated as given.
3. What Infrabox provides
Subject to payment and to these Terms, Infrabox provides some or all of the following, as ordered:
- Domain registration and DNS. Registration of domains through a registrar Infrabox holds an account with, and hosting of those domains’ DNS in a zone Infrabox manages. You may instead connect a domain you already own, provided its DNS is pointed at that zone.
- Google Workspace mailboxes. Mailboxes on your domain, created as users inside Google Workspace accounts that Infrabox holds. Your domain is attached to one of those accounts as a secondary domain. You do not sign up for Workspace, do not receive a Workspace bill, and do not hold the Workspace admin password.
- Automated provisioning. A 8-step pipeline that places the Workspace order, creates the admin account, waits for Google to activate it, publishes MX, SPF and DMARC, obtains Google’s domain verification, generates and publishes a DKIM key and enables signing, mints and verifies a sending credential, and puts the mailbox on its renewal schedule.
- An SMTP relay. Sending access at
smtp.infrabox.ioon port 587 over STARTTLS, authenticated with a relay credential issued by Infrabox rather than by Google, subject to a default cap of 2,000 messages per mailbox per day counted midnight to midnight UTC. - Status and monitoring. Live provisioning status per mailbox, and the abuse monitoring described in section 6 of the Acceptable Use Policy.
4. What Infrabox does not provide
This section is deliberately explicit, because the gap between what is sold and what people assume is sold is where most disputes start.
- Any mailbox platform other than Google Workspace. Microsoft 365 and Outlook mailboxes, Azure-hosted mail, and plain self-hosted or IP-based SMTP sending are not offered today. Nothing on this site is an offer to supply them, and no order can be placed for them.
- A sending tool. Infrabox is the infrastructure underneath a sequencer, not a sequencer. Whatever you pay yours is separate and unchanged.
- Programmatic mailbox reading for you. The sending credential sends; it does not give you IMAP. Replies do arrive at the mailbox, because MX is published during provisioning.
- Any guarantee of deliverability, inbox placement, sender reputation or campaign outcome. No placement rate is promised here and no service level stands behind one. Whether your mail reaches an inbox depends on your content, your lists and the receiving provider’s judgement.
- Any assurance about what Google, a registrar or a registry will do. Each can suspend, refuse or reclaim an account or a domain on its own terms and its own schedule.
- Lists, content, or legal advice. You choose the recipients and write the messages, and you are responsible for the lawfulness of both.
5. Your obligations
Infrabox is an infrastructure provider, not a sender. You are solely responsible for the content, the recipients and the legality of every message sent through infrastructure we provision for you. The Acceptable Use Policy applies in full to that sending and forms part of these Terms; a breach of it is a breach of these Terms.
In addition, and without limiting that policy, you must:
- leave the SPF, DKIM and DMARC records Infrabox publishes for your domains in place and unmodified — ask us if you need them changed, because editing them yourself breaks the authentication chain the rest of the service assumes;
- stay within the relay’s per-mailbox daily cap and any ramp schedule we publish, and not rotate identities or forge headers to get around either;
- not use the mailboxes for anything other than business email, and not use them in a way that would breach Google’s own terms;
- not resell or provide access to a sender who would themselves be refused under the Acceptable Use Policy;
- hold a lawful basis for every recipient you contact, and comply with the law of both the sending and the receiving jurisdiction.
Indemnity. You will indemnify Infrabox against third-party claims, regulatory penalties, blocklist remediation costs and reasonable legal costs arising from your sending, your content, your recipient data or your breach of these Terms. This indemnity is not subject to the cap in section 13 — that cap limits what Infrabox owes you, not what you owe us.
6. Domains, registrant identity and DNS
This is material and belongs in plain sight rather than in a schedule. By default, a domain bought through Infrabox is registered under Infrabox’s own registrant identity, with WHOIS privacy enabled. You are not the registrant of record unless you choose to be.
There is an explicit option at purchase to use your own contact details as the registrant of record instead. It is a real choice with real consequences, and it is worth making deliberately: if the registrant identity matters to you — because the domain is an asset you intend to keep, or because your own name appearing in WHOIS is part of how you present — select your own identity when you buy. Changing it afterwards depends on registrar and registry procedures and is not a setting you can flip.
- What the default means in practice. Where a domain stands in Infrabox’s registrant identity, the registrar recognises Infrabox, not you, as the party entitled to instruct it. You direct what happens to the domain through your account; the registrar relationship is ours.
- What it does not mean. Infrabox will not send from your domains for its own purposes, will not transfer a domain you paid for to another customer, and will not park, monetise or sell it while your subscription is current.
- DNS. Domains under management must be served by the DNS zone Infrabox manages, because every provisioning step works by writing records into it — MX, SPF, DMARC, the Google verification token and the DKIM key. A domain whose DNS you want to keep elsewhere is not compatible with this service.
- Renewal and lapse. Domains are registered by the year. A registration that is not renewed and paid for lapses at the registry, after which the name may be registered by anyone. Registration, renewal and transfer are all governed by registrar, registry and ICANN rules that neither of us can vary.
- Names you choose. You are responsible for ensuring a name you ask us to register does not infringe someone else’s trademark or other rights. We may refuse to register a name.
What happens to domains when the agreement ends — including the state of transfer-out today — is in section 11.
7. The Google Workspace relationship
Your mailboxes are Google Workspace users inside Workspace accounts that Infrabox holds and administers. Infrabox is Google’s customer for those accounts. You do not hold a Workspace contract with Google for them, do not receive a Workspace invoice, and do not hold the admin password.
- Google’s terms apply to the mailboxes. Mail sent from them is subject to Google’s terms, sending limits and program policies as well as to these Terms. Use that would breach Google’s terms is also a breach of ours.
- Google’s decisions are final as to Google. Google can suspend a mailbox, a domain or an entire Workspace account for its own reasons and on its own schedule. There is no appeal process Infrabox controls, and we do not promise a particular outcome from one. Workspace accounts in our pool are deliberately kept well below Google’s ceiling on domains per account, so a suspension affects a bounded set of domains rather than everything at once.
- Google’s platform can change. Where Google changes an API, a policy or an administrative surface the service depends on, Infrabox may have to change how a step works or, in the extreme, stop offering it. Section 12 covers what happens then.
Google’s own limits sit underneath the relay cap in section 3. The lower of the two is the one that binds.
8. Administrative access, and what Infrabox can see
Stated plainly, because it is structural rather than incidental: Infrabox is technically able to read mail in the mailboxes it provisions.
Sending credentials are minted through Google domain-wide delegation, which is impersonation of a user within an authorised list of scopes, and that list includes reading Gmail as well as sending it. Infrabox also holds the Workspace admin credentials for the pooled account your domain sits in. This is not a policy choice we could simply reverse: any provider that provisions and operates Google mailboxes on your behalf holds something equivalent. What varies between providers is which scopes they took and what their contract says about using them. Ours says this:
- The delegated scope list is kept to what provisioning and operation require — sending mail, reading mail, and administering users and domains in the directory. Each extra scope widens the blast radius of a leaked key, so the list is deliberately short. The mechanism is described in full in the delegation guide.
- We use that access to provision, operate, repair and support your mailboxes; to investigate a suspected breach of the Acceptable Use Policy or a security incident; and where we are required to by law. We do not read your mail for commercial purposes, do not use its contents for our own sending, and do not sell it.
- Messages you send through the relay pass through Infrabox systems, which process them in order to hand them to Gmail. What is retained, and for how long, is described in the Privacy Policy.
- Administrative actions are logged, and enforcement actions are logged and retained under section 6 of the Acceptable Use Policy.
If mail whose contents cannot be visible to a vendor is going to pass through these mailboxes, this is not the right service for it, and no clause here changes that.
9. Fees, billing and renewal
There are two kinds of charge, and they behave differently.
- Mailboxes are billed at $3.79 per Google Workspace mailbox per month, recurring until cancelled.
- Domains are billed per registration, per year, priced per TLD, and include a platform markup — $6 on a newly registered domain and $10 on one already 12 months or older. The tables on the pricing page are indicative; the price quoted at checkout is the price charged.
There is no minimum term, no setup or onboarding fee, and no per-record DNS charge. Prices are quoted in US dollars. Any sales tax, VAT or equivalent that applies to you is your responsibility unless it is itemised on your invoice.
- Renewal. Mailbox subscriptions renew automatically each month until you cancel. Domain registrations run for their registered year; renewal is scheduled as the final provisioning step so a mailbox does not quietly lapse mid-campaign.
- Failed payment. If a charge fails we may suspend sending and, if it stays unpaid, terminate the affected services under section 10. A domain whose renewal is not paid for will lapse at the registry, and a lapsed domain takes its mailboxes with it.
- Price changes. We may change prices. A change to a recurring mailbox fee applies from your next renewal after we tell you about it, and you are free to cancel before that renewal rather than accept it. Domain pricing follows registrar and registry pricing, which can move without notice to us.
- Refunds are governed by the Refund Policy. The short version is that a domain registration is spent the moment it succeeds and a mailbox subscription is not.
10. Suspension and termination
By you. There is no minimum term. You may cancel a mailbox subscription at any time; what happens to the remainder of a paid period is in the Refund Policy.
By Infrabox. We may suspend sending, suspend an account, or terminate services where:
- a payment fails and is not resolved;
- the Acceptable Use Policy is breached — the enforcement ladder in its section 6 sets out which trigger produces a warning, an automatic sending pause, or termination for cause;
- complaint or bounce behaviour crosses the automated thresholds, in which case a sending pause may be applied by the system before anyone reviews it;
- Google, a registrar, a registry, a blocklist operator or a legal authority requires it;
- the activity endangers the pooled infrastructure or the other customers on it — a pooled Workspace means one sender’s conduct can put other people’s mailboxes at risk, and we will act to prevent that.
Where we terminate for cause under this section, prepaid fees for the affected service are not refunded. We may also stop selling a service, or close an account without cause, in which case we will tell you, stop charging you, and treat money already paid under the Refund Policy.
11. What happens to domains and mailboxes at the end
Mailboxes end. They exist as users inside a Google Workspace account that Infrabox holds, so there is nothing to hand over: no export turns them into mailboxes in a Workspace you own, because the account they live in is not yours to receive them into. When the subscription ends, the mailboxes and their contents are deleted. If mail held in one matters to you, retrieve it while the mailbox still exists — tell us before you cancel and we will help you arrange it. Once deleted, it cannot be recovered.
Domains are a different question, and the honest answer is uncomfortable. A registration you paid for runs to the end of its registered year regardless of whether the mailboxes on it are still running. But transfer-out is not automated: there is no self-service path in the product today to obtain an authorisation code and move a domain to another registrar. Moving one is a manual request handled by a person, not a button in the dashboard.
- We will not unreasonably refuse a transfer-out request for a domain you have paid for and which is not the subject of an unpaid invoice or an open abuse investigation.
- Timing is governed by registrar and registry rules, including the restrictions that apply to recently registered or recently modified domains. Those rules bind us as much as they bind you.
- Where the domain stands in Infrabox’s registrant identity under section 6, moving it also involves a change of registrant, which some registries treat as a separate process with its own conditions.
- If being able to walk away with your domains on your own schedule is a requirement, raise it before you buy rather than after. This clause is the whole of what we can promise today.
Account data after termination is handled under the Privacy Policy.
12. Availability, provisioning times and support
These Terms contain no uptime commitment, and no availability percentage is published anywhere on this site. We do not offer a service level agreement today, and we would rather say that than print a number no measurement of ours would support. We operate the service with reasonable skill and care, and that is the commitment.
Provisioning times are estimates, not commitments. The typical case is roughly 7 hours end to end, and it is dominated by a single step: waiting for Google to confirm it can see the domain-verification record. That wait is paced by DNS propagation and by Google’s own checking schedule. Nobody — not Infrabox, not you, not a support ticket — makes it go faster. The per-step breakdown is on how it works.
The DKIM step still depends on driving Google’s Admin Console rather than calling an API, because Google exposes no API for it, and it is therefore the step most likely to need attention. A mailbox without DKIM can still send; what it loses is a signing identity, so DMARC has only SPF to align against and SPF does not survive forwarding.
We may change, add to or withdraw features, and we may perform maintenance that interrupts the service. Where a change removes something you were relying on, we will tell you, and you may cancel. Support is by email at hello@infrabox.io; these Terms do not set a response time.
13. Warranties, liability and disputes
To the fullest extent the law allows, the service is provided as it is, and Infrabox excludes implied warranties of merchantability, fitness for a particular purpose and non-infringement. Nothing here excludes liability that cannot lawfully be excluded, including for fraud or for death or personal injury caused by negligence, and nothing here affects rights you hold under mandatory law that applies to you.
Infrabox is not liable for:
- lost profits, lost revenue, lost business, lost or delayed campaigns, wasted expenditure, or loss of goodwill or reputation;
- deliverability outcomes, spam-folder placement, blocklisting, or a receiving provider’s treatment of your mail;
- acts and decisions of Google, a registrar, a registry, a blocklist operator or any other third party, including suspension, refusal or reclamation of an account or a domain;
- loss of mailbox contents where you did not retrieve them before the mailbox was deleted under section 11;
- anything arising from your own breach of these Terms.
Cap. Infrabox’s total aggregate liability arising out of or in connection with these Terms is limited to the fees you paid Infrabox for the affected service in the three months before the event giving rise to the claim. That is a policy choice rather than a legal necessity, and it is stated here so it is visible before purchase rather than after a dispute.
One thing these Terms do not settle. They do not name a governing law, a court or an arbitration forum. Rather than print a jurisdiction that has not actually been decided, we have left it out; until it is settled, a dispute is resolved under whatever law and forum would apply anyway. If that matters to you, raise it before you buy and we will deal with it in writing.
14. Changes to these Terms
We may update these Terms. The date at the top of this page is the date of the current version, and it changes when the document does. Where a change materially affects a service you are subscribed to, we will tell you at the account email address before it applies to your next renewal. Continuing to use the service after that is acceptance; if you do not accept a change, cancel before the renewal it would apply to. Changes never apply retroactively to a period already paid for.
15. Contact
Questions about these Terms, anything in them you want settled in writing before you buy, and requests under sections 10 and 11 all go to the same place: hello@infrabox.io. You can also use the get started page. Questions that come up more than once end up on the FAQ, phrased the way they were asked.
