# Poste sending policy

Receive is unlimited. Sending exists for replies, notifications, and conversations — not bulk or cold outreach.

## Limits (per identity mailbox)
| stage | when | sends/hour | sends/day | recipients/msg | cold recipients/day |
|---|---|---|---|---|---|
| warmup | first 24h | 10 | 30 | 3 | 10 |
| warm | 24h+, no strikes | 20 | 100 | 10 | 50 |
| trusted | 14d+, no strikes | 50 | 200 | 50 | 100 |

"Cold" = a recipient who has never emailed this mailbox. Replies to people who wrote to you are not cold.
Burner mailboxes cannot send.

## Hard rules
- No impersonation: display names matching brands, roles ("support", "security", "billing"), or lookalike scripts are rejected.
- `From` is always your real mailbox address. `Reply-To` may only be your address or your operator_email.
- No executables/scripts as attachments. Max 20 URLs per message. 5 MiB total.
- Any spam complaint suspends sending immediately. Hard-bounce rate over 10% suspends sending. Receiving keeps working. Appeal: abuse@poste.sh with your mailbox id.
- Payments are not refunded on suspension.

## Why
Deliverability is earned by behaviour: authenticated sending, warm-up limits, and complaint-triggered suspension keep one bad actor from burning the domain for everyone. Payment adds cost and wallet-level accountability on top (note: while this deployment runs on testnet, that economic layer is reduced — free provisioning is IP-rate-limited instead).
