Legal
Hostwover Legal Center

Policies, agreements, and legal information for using Hostwover services.

Abuse Handling Policy

Language note

The English version of Hostwover's legal agreements and policies is the authoritative version. Translated versions are provided for convenience. If there is any conflict between translations, the English version shall prevail.

Last updated: August 14, 2026

This Abuse Handling Policy ("Policy") explains how Hostwover ("Hostwover", "we", "us", or "our") receives, reviews, investigates, prioritizes, escalates, mitigates, and resolves reports of suspected abuse involving services provided, sold, resold, managed, or made available through Hostwover.

This Policy applies to abuse reports concerning Hostwover Services and describes both:

  • how persons may report suspected abuse; and
  • how Hostwover may respond to reported or detected abuse.

This Policy should be read together with the:

  • Hostwover Terms of Service.
  • Acceptable Use Policy.
  • Acceptable Use Agreement.
  • Privacy Policy.
  • applicable product agreement; and
  • applicable upstream-provider requirements.

1. Purpose

Hostwover seeks to maintain a secure, reliable, lawful, and trustworthy service environment.

The purpose of this Policy is to establish a consistent process for handling reports involving:

  • phishing.
  • malware.
  • botnets.
  • spam.
  • fraud.
  • network attacks.
  • compromised systems.
  • domain abuse.
  • DNS abuse.
  • abusive email.
  • intellectual property complaints.
  • unlawful content.
  • security incidents; and
  • other violations of Hostwover policies.

2. Scope

This Policy may apply to abuse involving any Hostwover Service, including:

  • domain registration.
  • domain transfer.
  • domain renewal.
  • DNS.
  • web hosting.
  • shared hosting.
  • VPS.
  • VDS.
  • virtual infrastructure.
  • professional email.
  • business email.
  • Google Workspace.
  • APIs.
  • AI services.
  • control panels.
  • databases.
  • networking.
  • storage.
  • automation systems; and
  • other Hostwover Services.

3. Hostwover's Role

The technical and contractual role Hostwover performs may differ depending on the Service involved.

Hostwover may act as:

  • the direct service provider.
  • an infrastructure administrator.
  • a reseller.
  • a billing and provisioning intermediary.
  • a first-line support provider; or
  • another service-management intermediary.

Accordingly, Hostwover's ability to directly remove, suspend, modify, or otherwise mitigate a Service may vary.

4. Upstream Providers

Some Hostwover Services rely on third-party:

  • registrars.
  • registries.
  • cloud providers.
  • data centers.
  • email providers.
  • software providers.
  • distributors.
  • network operators; or
  • other infrastructure providers.

Hostwover may therefore refer or escalate an abuse report to the appropriate upstream provider where necessary.

5. No Misrepresentation of Registrar Authority

Where a domain name is supplied through an upstream registrar, Hostwover may not have direct registry-level authority over every domain status or registry operation.

In such circumstances, Hostwover may investigate the matter, communicate with the Customer, apply controls available to Hostwover, and escalate appropriate evidence to the sponsoring registrar or other responsible provider.

6. Reporting Abuse

Any person may report suspected abuse involving a Hostwover Service.

The reporter does not need to be a Hostwover Customer.

Reports should be submitted in good faith and contain enough information for the matter to be reasonably investigated.

7. Current Abuse Reporting Channel

Until Hostwover publishes a dedicated abuse address or abuse-reporting form, reports may be submitted to:

Hostwover Support

Email: [email protected]

Website: hostwover.com

When reporting by email, reporters are encouraged to use a clear subject such as:

Abuse Report – [Domain / IP / Service]

8. Dedicated Abuse Channel

Hostwover may establish a dedicated abuse address, web form, ticket category, security portal, or other reporting mechanism.

When a dedicated abuse mechanism is published, reporters should use that mechanism where reasonably possible.

9. Information to Include

An abuse report should include as much relevant information as reasonably available.

Useful information may include:

  • affected domain.
  • full URL.
  • IP address.
  • hostname.
  • email address.
  • message headers.
  • description of the suspected abuse.
  • date and time observed.
  • screenshots.
  • logs.
  • malware indicators.
  • transaction information.
  • evidence of impersonation.
  • copies of suspicious messages.
  • supporting documents; and
  • reporter contact information.

10. Full URLs

For website-related abuse, reporters should provide the full affected URL where possible rather than only the domain name.

For example, identifying a specific page or path may allow Hostwover or another responsible provider to mitigate abuse without unnecessarily affecting unrelated legitimate content.

11. Email Abuse Evidence

Reports involving spam, phishing, spoofing, or other email abuse should include, where possible:

  • complete email headers.
  • message content.
  • sending address.
  • receiving address.
  • sending IP.
  • timestamps.
  • relevant URLs; and
  • other technical information.

Screenshots alone may not contain enough technical information to investigate an email complaint.

12. Network Abuse Evidence

Reports involving network attacks should include relevant information where available, such as:

  • source IP.
  • destination IP.
  • destination port.
  • protocol.
  • timestamps.
  • timezone.
  • log excerpts.
  • packet information.
  • attack type; and
  • duration.

13. Malware Reports

Reports involving malware should identify, where possible:

  • affected URL.
  • affected domain.
  • file location.
  • file hash.
  • malware family.
  • security-vendor detection.
  • observed behavior; and
  • relevant timestamps.

14. Phishing Reports

A phishing report should, where reasonably possible, identify:

  • the phishing URL.
  • the impersonated organization or service.
  • screenshots.
  • evidence of credential collection.
  • associated email messages; and
  • other indicators supporting the report.

15. Domain Abuse Reports

Domain abuse reports should include:

  • the affected domain.
  • nature of the alleged abuse.
  • specific evidence.
  • relevant URLs.
  • timestamps; and
  • supporting technical information.

Hostwover may request additional evidence before taking domain-level action.

16. Reporter Contact Information

Reporters should provide a valid method of contact.

Hostwover may need to request:

  • additional evidence.
  • clarification.
  • confirmation; or
  • technical information.

Reports submitted anonymously may still be reviewed if sufficient evidence is provided.

17. Confidentiality Requests

A reporter may ask Hostwover to avoid unnecessarily disclosing the reporter's identity to the affected Customer.

Hostwover will consider reasonable confidentiality requests.

However, Hostwover cannot guarantee confidentiality where disclosure is:

  • legally required.
  • necessary to fairly investigate a complaint.
  • necessary to establish a legal claim; or
  • required by an upstream provider.

18. Receipt of Reports

Hostwover may send an automated or manual acknowledgment confirming receipt of an abuse report.

An acknowledgment means only that the report has been received.

It does not mean that:

  • the allegation has been verified.
  • a policy violation has occurred.
  • Hostwover accepts the reporter's legal position; or
  • a particular enforcement action will be taken.

19. Case Creation

Hostwover may create an internal abuse case or ticket for a report.

The case may contain:

  • report details.
  • supporting evidence.
  • investigation notes.
  • Customer responses.
  • technical findings.
  • provider communications.
  • mitigation actions; and
  • case status.

20. Duplicate Reports

Multiple reports concerning substantially the same activity may be consolidated into a single investigation.

Hostwover does not necessarily provide a separate investigation for every duplicate submission.

21. Automated Reports

Hostwover may receive automated abuse notifications from:

  • security vendors.
  • malware databases.
  • blocklists.
  • threat-intelligence services.
  • infrastructure providers.
  • email providers; or
  • automated monitoring systems.

Automated detection may be considered as evidence but does not automatically establish a violation in every case.

22. Proactive Detection

Hostwover may investigate suspected abuse identified through its own:

  • monitoring.
  • security systems.
  • fraud controls.
  • infrastructure alerts.
  • provider notifications; or
  • technical analysis.

An external complaint is not required before Hostwover may act on clearly identified abuse.

23. Initial Assessment

Hostwover may initially assess:

  • whether the reported Service is associated with Hostwover.
  • whether Hostwover can identify the relevant Customer.
  • whether the report contains sufficient evidence.
  • the seriousness of the alleged activity.
  • whether immediate harm appears likely.
  • whether an upstream provider must be involved; and
  • what technical action is available.

24. Abuse Classification

Hostwover may classify reports into categories including:

  • DNS abuse.
  • phishing.
  • malware.
  • botnet activity.
  • spam.
  • email abuse.
  • network attack.
  • server compromise.
  • fraud.
  • intellectual property.
  • unlawful content.
  • privacy or personal-data abuse.
  • domain-registration data complaint.
  • account compromise.
  • security vulnerability; or
  • other abuse.

25. Priority Assessment

Hostwover may prioritize investigations according to risk.

Factors may include:

  • immediacy of harm.
  • number of potential victims.
  • evidence strength.
  • active credential theft.
  • ongoing malware delivery.
  • active attacks.
  • risk to children.
  • infrastructure stability.
  • financial harm.
  • recurrence.
  • upstream-provider deadlines; and
  • legally binding requirements.

26. Critical Abuse

Certain reports may require immediate or accelerated action.

Examples may include:

  • active phishing.
  • ransomware.
  • active malware distribution.
  • botnet command-and-control.
  • significant DDoS attacks.
  • child sexual abuse material.
  • serious account compromise.
  • credible threats of imminent harm.
  • major fraud operations; or
  • significant infrastructure compromise.

27. Immediate Protective Measures

Where reasonably necessary, Hostwover may take protective measures before completing a full investigation.

Such measures may include:

  • restricting outbound email.
  • blocking ports.
  • temporarily blocking traffic.
  • disabling a website.
  • isolating a server.
  • restricting network connectivity.
  • suspending credentials.
  • temporarily suspending a Service; or
  • escalating to an upstream provider.

28. Proportionality

Hostwover seeks to use enforcement measures reasonably proportionate to the abuse involved.

Where practical, Hostwover will consider whether the abuse can be stopped without unnecessarily disrupting legitimate:

  • websites.
  • email.
  • subdomains.
  • applications.
  • users.
  • data; or
  • other services.

29. Collateral Damage

Hostwover may consider potential collateral damage before taking broad enforcement action.

For example, where a legitimate domain has been compromised and only a specific website component is malicious, suspension of the entire domain may affect unrelated email, websites, subdomains, and legitimate users.

Hostwover may therefore choose a narrower mitigation method where appropriate and technically possible.

30. Compromised Versus Malicious Services

Hostwover may distinguish between:

  • a Service intentionally operated for abusive purposes; and
  • a legitimate Service compromised by an attacker.

A compromised Customer may be given an opportunity to secure the affected system where doing so can reasonably mitigate the threat.

31. Customer Notification

Where appropriate, Hostwover may notify the Customer of an abuse report.

The notice may include:

  • the affected Service.
  • nature of the allegation.
  • relevant evidence.
  • required corrective action.
  • requested response.
  • deadline, if applicable; and
  • consequences of failing to respond.

32. Notice Is Not Always Required

Hostwover may take action without prior Customer notice where reasonably necessary because of:

  • urgent security risk.
  • active phishing.
  • malware.
  • DDoS attacks.
  • serious fraud.
  • risk of evidence destruction.
  • provider instructions.
  • legal requirements.
  • risk to third parties; or
  • other urgent circumstances.

33. Customer Response

Customers receiving an abuse notice should respond promptly.

A useful response may include:

  • confirmation that the issue has been investigated.
  • explanation of the cause.
  • evidence that abusive content was removed.
  • confirmation that credentials were changed.
  • evidence that vulnerable software was patched.
  • relevant logs.
  • proof of authorization; or
  • other corrective action.

34. Remediation

Hostwover may request that the Customer take measures such as:

  • remove malicious files.
  • disable compromised accounts.
  • patch software.
  • change passwords.
  • rotate API keys.
  • update firewall rules.
  • stop abusive processes.
  • remove phishing content.
  • correct DNS configuration.
  • terminate abusive End Users.
  • secure mailboxes; or
  • otherwise eliminate the source of abuse.

35. Remediation Deadlines

Where appropriate, Hostwover may establish a deadline for corrective action.

The deadline may vary depending on:

  • severity.
  • urgency.
  • type of abuse.
  • continuing harm.
  • technical complexity.
  • upstream-provider requirements; and
  • Customer cooperation.

Hostwover does not guarantee a fixed remediation period for all abuse categories.

36. No Universal Response-Time Guarantee

Different abuse cases require different levels of investigation.

Hostwover therefore does not promise that every report will be resolved within the same fixed period.

Cases involving imminent or significant harm may receive higher priority than routine or incomplete complaints.

37. Continuing Harm

Where harmful activity continues while an investigation is underway, Hostwover may increase enforcement measures before the investigation is formally closed.

38. Failure to Respond

Failure to respond to a legitimate abuse request may result in:

  • further technical restrictions.
  • suspension.
  • escalation to an upstream provider.
  • termination; or
  • other action permitted by applicable agreements.

39. Repeat Abuse

Repeated abuse associated with the same Customer, Service, infrastructure, domain, or account may result in stronger enforcement.

Hostwover may consider a Customer's prior abuse history when determining appropriate action.

40. Intentional Abuse

Where evidence indicates that a Service was intentionally purchased, configured, or operated for prohibited abuse, Hostwover may take stronger or immediate action.

Such activity may include intentionally operating:

  • phishing infrastructure.
  • malicious botnets.
  • malware distribution systems.
  • attack infrastructure.
  • fraudulent websites; or
  • spam operations.

41. DNS Abuse

For domain-related investigations, Hostwover may treat the following categories as DNS abuse where applicable under relevant domain-industry requirements:

  • malware.
  • botnets.
  • phishing.
  • pharming; and
  • spam when used as a delivery mechanism for another applicable DNS-abuse category.

42. DNS Abuse Versus Website Content

Not every complaint concerning content on a website constitutes DNS abuse.

Complaints involving:

  • defamation.
  • ordinary copyright disputes.
  • contractual disputes.
  • political content.
  • commercial disputes.
  • trademark disputes; or
  • other website-content issues

may require different procedures from technically defined DNS abuse.

43. Actionable DNS Abuse Evidence

For domain abuse, Hostwover will consider whether available information provides sufficient evidence to reasonably investigate and determine the nature of the reported activity.

Evidence may include:

  • full URLs.
  • screenshots.
  • malware results.
  • technical indicators.
  • phishing evidence.
  • DNS records.
  • nameserver information.
  • account information.
  • provider reports; and
  • relevant publicly accessible content.

44. Incomplete DNS Reports

An incomplete report is not necessarily ignored.

Where reasonably practicable, Hostwover may:

  • review available information.
  • request additional evidence.
  • inspect relevant publicly accessible information.
  • review technical information available to Hostwover; or
  • refer the matter to the appropriate upstream registrar or provider.

45. DNS Abuse Mitigation

Potential DNS abuse mitigation may include:

  • notifying the Customer.
  • requiring website remediation.
  • disabling hosting.
  • disabling malicious DNS records where within Hostwover's control.
  • escalating evidence to the sponsoring registrar.
  • requesting registrar action.
  • requesting registry involvement.
  • suspending related Services where contractually permitted; or
  • another proportionate mitigation.

46. Registrar Escalation

Where domain-level action requires the sponsoring registrar, Hostwover may forward the report and relevant evidence to that registrar.

The registrar may independently determine the appropriate action under its own:

  • policies.
  • contractual obligations.
  • registry requirements; and
  • applicable law.

47. Registry Escalation

Certain cases may ultimately require involvement from the applicable domain registry.

Hostwover may coordinate through the registrar or other appropriate provider rather than contacting the registry directly in every case.

48. Registry and Registrar Decisions

Hostwover cannot guarantee that a registrar or registry will:

  • suspend a domain.
  • remove a hold.
  • restore a domain.
  • transfer a domain.
  • disclose registration information; or
  • take another requested action.

Such entities may independently evaluate the available evidence.

49. Domain Suspension

Where domain suspension is warranted and available, suspension may affect:

  • websites.
  • email.
  • subdomains.
  • APIs.
  • applications; and
  • other services using the domain.

For this reason, domain-level suspension may not always be the first mitigation used for a compromised but otherwise legitimate domain.

50. False Registration Information

Reports alleging materially inaccurate domain registration data may be handled separately from technical abuse reports.

Hostwover may request verification or escalate the matter to the sponsoring registrar as appropriate.

51. Hosting Abuse

Reports concerning content or applications hosted through Hostwover may be reviewed against:

  • the Acceptable Use Policy.
  • Acceptable Use Agreement.
  • Web Hosting Agreement.
  • VPS Agreement.
  • VDS Agreement.
  • applicable law; and
  • provider requirements.

52. VPS and VDS Abuse

Customers with administrative or root access remain responsible for securing their environments.

When a VPS or VDS is compromised, Hostwover may request the Customer to:

  • investigate.
  • remove malicious processes.
  • rotate credentials.
  • patch vulnerabilities.
  • secure exposed ports; and
  • provide evidence of remediation.

53. Network Attacks

Hostwover may take immediate network-level action where infrastructure is being used for:

  • DDoS attacks.
  • brute-force activity.
  • unauthorized scanning.
  • botnet activity.
  • network exploitation; or
  • comparable attack traffic.

54. Outbound Abuse

Hostwover may restrict outbound connectivity where necessary to stop active abuse.

Depending on the circumstances, this may include temporary restrictions affecting:

  • SMTP.
  • specific ports.
  • protocols.
  • IP addresses.
  • applications; or
  • an entire server.

55. Inbound Attacks

Reports that a Hostwover Customer is merely receiving an attack are not treated as abuse by that Customer.

Hostwover may separately assist with defensive or mitigation measures where supported by the applicable Service.

56. Spam Complaints

Hostwover may investigate reports that its Services are being used to distribute unsolicited bulk communications.

Evidence may include:

  • email headers.
  • sending IPs.
  • complaint rates.
  • bounce rates.
  • mailing-list practices.
  • authentication configuration.
  • provider reports; and
  • Customer explanations.

57. Compromised Email Accounts

Where an email account appears compromised, Hostwover may temporarily restrict sending while the account is secured.

Customers may be required to:

  • change passwords.
  • terminate active sessions.
  • remove forwarding rules.
  • review connected applications.
  • enable multi-factor authentication where supported; and
  • inspect affected devices.

58. Email Reputation Protection

Hostwover may act where abusive email threatens shared:

  • IP reputation.
  • domain reputation.
  • mail-server reputation.
  • deliverability; or
  • service availability.

Protecting shared email infrastructure may require temporary restrictions before the full investigation is completed.

59. Phishing Through Email

Where email and web infrastructure are jointly used for phishing, Hostwover may apply mitigation to multiple associated Services where reasonably necessary.

60. Google Workspace Abuse

Google Workspace is operated by Google.

Where a Google Workspace subscription purchased through Hostwover is involved in suspected abuse, Hostwover may:

  • assist with initial investigation.
  • notify the Customer.
  • restrict reseller-managed functionality where available.
  • escalate the issue through the relevant provider channel; or
  • direct the Customer to appropriate Google controls.

Google may independently enforce its own terms and policies.

61. Intellectual Property Complaints

Reports alleging copyright, trademark, or other intellectual property infringement should contain enough information to identify:

  • the protected work or right.
  • the allegedly infringing material.
  • the location of the material.
  • the rights holder or authorized representative.
  • supporting evidence; and
  • reporter contact information.

62. No Automatic Determination of Ownership

Hostwover is not a court and does not ordinarily adjudicate complex ownership disputes.

Where competing parties present legitimate claims requiring legal determination, Hostwover may require them to use appropriate:

  • court proceedings.
  • domain dispute procedures.
  • arbitration.
  • registrar processes; or
  • other established mechanisms.

63. Trademark and Domain Disputes

Ordinary disputes regarding entitlement to a domain name may need to be resolved through applicable domain dispute-resolution procedures or courts.

Submitting an abuse complaint does not automatically transfer ownership of a domain.

64. Copyright Complaints

Hostwover may investigate adequately documented copyright complaints concerning content hosted through Services under Hostwover's control.

Where the content is hosted by another provider, Hostwover may direct the reporter to the appropriate hosting provider.

65. Illegal Content

Reports alleging illegal content may require additional legal context.

Hostwover may request:

  • identification of the applicable law.
  • jurisdiction.
  • court order.
  • authority request.
  • legal documentation; or
  • other supporting information

where the illegality of the material is not readily apparent.

66. Clearly Unlawful or Dangerous Material

Where material presents an immediate and clear risk, Hostwover may take action without waiting for a final court determination where such action is permitted or required.

67. Child Sexual Abuse Material

Hostwover has zero tolerance for child sexual abuse material and unlawful sexual exploitation of children.

Suspected cases may receive immediate priority.

Hostwover may:

  • restrict affected Services.
  • preserve relevant information where legally permitted or required.
  • escalate to providers; and
  • report suspected activity to appropriate authorities where required or permitted by law.

68. Evidence Handling

Persons reporting highly sensitive or illegal material should not unnecessarily redistribute such material to Hostwover.

Where possible, reporters should provide:

  • URLs.
  • identifiers.
  • hashes.
  • lawful screenshots where appropriate; or
  • other evidence sufficient to locate the material

without unnecessarily transmitting prohibited material itself.

69. Fraud Reports

Reports involving fraud should identify the allegedly fraudulent activity and include relevant:

  • URLs.
  • transaction details.
  • screenshots.
  • payment evidence.
  • impersonated organizations; and
  • communications.

Hostwover may take technical action but does not guarantee recovery of money lost to fraud.

70. Payment Disputes Are Not Automatically Abuse

A commercial disagreement between a Hostwover Customer and its own customer does not automatically constitute platform abuse.

Hostwover may decline to adjudicate ordinary contractual or refund disputes that do not involve a violation of Hostwover policies or applicable law.

71. Law-Enforcement Requests

Law-enforcement and government requests must be submitted through an appropriate legal or official channel.

Hostwover may verify the authenticity and authority of a request before responding.

72. Emergency Government Requests

Hostwover may give expedited consideration to authenticated government or law-enforcement requests involving an imminent risk to life, safety, or significant harm.

73. Legal Process

Hostwover will respond to valid legal process in accordance with applicable law.

The existence of an abuse report alone does not require Hostwover to disclose confidential Customer information.

74. Customer Information

Hostwover will handle Customer information in accordance with:

  • applicable law.
  • the Hostwover Privacy Policy.
  • applicable provider requirements; and
  • valid legal process.

75. Data Preservation

Hostwover may preserve relevant records where:

  • required by law.
  • required by valid legal process.
  • reasonably necessary to investigate serious abuse.
  • necessary to defend legal rights; or
  • required by an upstream provider.

Preservation does not necessarily mean that information will be disclosed.

76. Information Sharing With Providers

Hostwover may share relevant information with an upstream provider where reasonably necessary to:

  • investigate abuse.
  • mitigate abuse.
  • maintain a Service.
  • respond to provider requests.
  • protect infrastructure; or
  • comply with contractual requirements.

Only information reasonably relevant to the purpose should be shared where practicable.

77. Threat Intelligence

Hostwover may use or provide technical indicators necessary to investigate or prevent abuse, such as:

  • malicious IP addresses.
  • domains.
  • URLs.
  • file hashes.
  • attack patterns; and
  • malware indicators.

Such activity will be subject to applicable law and Hostwover's Privacy Policy.

78. Upstream Abuse Complaints

Hostwover may receive abuse complaints directly from infrastructure providers concerning Customer Services.

Such complaints may include deadlines or required mitigation steps.

Customers must reasonably cooperate where Hostwover forwards a legitimate upstream abuse notification.

79. Upstream Deadlines

Where an upstream provider imposes a deadline, Hostwover may require Customer remediation before that deadline.

Failure to respond may result in suspension where necessary to prevent upstream termination or wider infrastructure impact.

80. Provider-Directed Suspension

An upstream provider may suspend or restrict infrastructure independently of Hostwover.

Where this occurs, Hostwover may assist the Customer but cannot guarantee immediate restoration.

81. Verification of Reports

Hostwover may independently verify allegations before enforcement where reasonably possible.

Verification may include:

  • inspecting publicly available URLs.
  • reviewing DNS data.
  • reviewing system information available to Hostwover.
  • checking logs.
  • reviewing email headers.
  • consulting reputable security sources; or
  • requesting Customer information.

82. False Positives

Security systems and third-party reports may occasionally identify legitimate activity incorrectly.

Hostwover may consider evidence provided by the Customer showing that a report is inaccurate.

83. Customer Appeals

A Customer who believes an abuse action was incorrect may contact Hostwover Support and provide relevant evidence.

An appeal should include:

  • affected Service.
  • case or ticket reference.
  • explanation of the dispute.
  • supporting evidence; and
  • remediation already performed, if applicable.

84. Appeal Does Not Automatically Restore Service

Submitting an appeal does not automatically reverse a suspension or restriction.

Hostwover may maintain protective measures while the matter is reviewed where continued operation presents a meaningful risk.

85. Restoration

A suspended Service may be restored where Hostwover reasonably determines that:

  • abuse has stopped.
  • remediation is sufficient.
  • security has been restored.
  • provider requirements are satisfied.
  • outstanding verification is complete; and
  • restoration does not create unacceptable risk.

86. Conditional Restoration

Hostwover may restore a Service subject to conditions such as:

  • password resets.
  • software updates.
  • malware removal.
  • network restrictions.
  • email restrictions.
  • monitoring.
  • configuration changes; or
  • Customer commitments to prevent recurrence.

87. No Guarantee of Restoration

Certain serious or repeated violations may result in permanent termination.

Hostwover is not required to restore a Service where continued use would violate:

  • applicable law.
  • provider requirements.
  • Hostwover policies; or
  • contractual obligations.

88. Repeat-Offender Handling

Repeated serious violations may result in:

  • increased restrictions.
  • refusal of new orders.
  • non-renewal.
  • permanent suspension.
  • account termination; or
  • escalation to providers.

89. Abuse Evasion

Hostwover may associate and restrict related accounts or Services where reasonably supported by evidence that they are being used to deliberately evade an abuse enforcement action.

90. Account-Wide Action

Hostwover will not automatically apply account-wide sanctions for every single-service incident.

However, account-wide action may be appropriate where:

  • abuse is widespread.
  • multiple Services are involved.
  • the Customer is intentionally operating abusive infrastructure.
  • repeated violations occur; or
  • continued account access creates significant risk.

91. Preservation of Legitimate Data

Where technically feasible and legally appropriate, Hostwover may attempt to avoid unnecessary destruction of legitimate Customer data during temporary mitigation.

This does not guarantee data preservation or recovery.

Customers remain responsible for maintaining appropriate backups.

92. Suspension and Billing

Suspension caused by abuse does not automatically:

  • cancel the Service.
  • cancel a billing commitment.
  • waive outstanding charges.
  • extend the Service term; or
  • create a refund entitlement.

Applicable billing and refund rules remain governed by the relevant Hostwover agreements and policies.

93. Termination

Serious, repeated, deliberate, or unresolved abuse may result in Service or account termination.

Termination may occur where permitted by applicable agreements, provider requirements, and law.

94. Reporting to Authorities

Hostwover may report suspected unlawful activity to appropriate authorities where:

  • required by law.
  • legally permitted and reasonably necessary.
  • necessary to address a serious security threat; or
  • otherwise appropriate under applicable obligations.

95. No Duty to Provide Investigation Details

Hostwover may be unable to disclose all details of an abuse investigation to a reporter or Customer.

Reasons may include:

  • privacy.
  • security.
  • confidentiality.
  • provider restrictions.
  • legal privilege.
  • ongoing investigations; or
  • law-enforcement requirements.

96. Reporter Updates

Where appropriate, Hostwover may inform the reporter that:

  • the report was received.
  • additional information is needed.
  • the report was reviewed.
  • action was taken; or
  • the matter was referred to another provider.

Hostwover may not disclose confidential details regarding the affected Customer.

97. Case Closure

Hostwover may close an abuse case when:

  • the abuse is resolved.
  • sufficient mitigation has occurred.
  • the report is unsupported.
  • the report is outside Hostwover's control.
  • the matter is referred to the responsible provider.
  • required information is not supplied.
  • the issue is determined not to violate Hostwover policies; or
  • another appropriate resolution is reached.

98. Reopening Cases

Hostwover may reopen a case if:

  • abuse recurs.
  • new evidence becomes available.
  • a provider requests further action.
  • the Customer fails to maintain remediation; or
  • circumstances materially change.

99. False or Malicious Complaints

Reporters must not knowingly submit materially false claims for the purpose of:

  • harming another person.
  • disrupting a legitimate website.
  • pressuring a business.
  • interfering with a domain.
  • harassing a Customer; or
  • manipulating Hostwover's enforcement process.

100. Abuse of the Reporting System

Hostwover may restrict communications from persons who repeatedly misuse the abuse-reporting process through:

  • threats.
  • spam.
  • automated flooding.
  • intentionally false reports; or
  • other abusive conduct.

Legitimate reports will not be rejected merely because a reporter previously submitted a complaint that could not be substantiated.

101. Security Research

Security researchers who discover vulnerabilities affecting Hostwover systems should disclose them responsibly and privately.

Reports should contain enough information to allow Hostwover to reproduce and evaluate the issue.

102. Security Research Limitations

Security research must not intentionally:

  • access unrelated Customer data.
  • destroy information.
  • cause material service disruption.
  • retain unnecessary personal information.
  • conduct social engineering against Hostwover personnel; or
  • exploit a vulnerability beyond what is reasonably necessary to demonstrate the issue.

103. Responsible Disclosure

Hostwover may establish a separate Vulnerability Disclosure Policy or security reporting program.

Until such a policy is published, security reports may be sent through Hostwover Support.

104. Recordkeeping

Hostwover may retain reasonable records concerning abuse reports and responses.

Records may include:

  • reporter information.
  • affected Services.
  • evidence.
  • communications.
  • technical findings.
  • mitigation actions.
  • escalation records.
  • timestamps; and
  • case outcomes.

105. Retention

Abuse records may be retained for a period reasonably necessary for:

  • security.
  • recurrence detection.
  • provider compliance.
  • legal obligations.
  • dispute resolution.
  • fraud prevention; and
  • protection of Hostwover's legal rights.

Retention will be subject to applicable law and the Hostwover Privacy Policy.

106. Internal Access

Access to abuse-case information may be limited to personnel, contractors, or providers who reasonably need the information for:

  • investigation.
  • security.
  • support.
  • compliance.
  • legal review; or
  • technical mitigation.

107. Automated Decision Support

Hostwover may use automated tools to assist in:

  • threat detection.
  • spam detection.
  • fraud analysis.
  • malware detection.
  • network monitoring.
  • prioritization; or
  • abuse classification.

Where reasonably practicable, significant enforcement may include human review where automated findings are uncertain or require contextual judgment.

108. No Monitoring Guarantee

Hostwover does not guarantee that it will proactively detect every instance of abuse.

Customers remain responsible for the security and lawful use of their Services.

109. Customer Monitoring Responsibility

Customers operating servers, websites, applications, or email systems should maintain appropriate security monitoring based on the nature of their Service.

110. Service-Specific Agreements

Abuse investigations may also be governed by relevant Hostwover agreements including:

  • Domain Registration Agreement.
  • Domain Transfer Agreement.
  • Domain Renewal & Expiration Agreement.
  • Web Hosting Agreement.
  • VPS Agreement.
  • VDS Agreement.
  • Professional Email Agreement.
  • Google Workspace Agreement.
  • Acceptable Use Agreement; and
  • Acceptable Use Policy.

111. Conflict With Specific Requirements

If a product-specific agreement or mandatory provider requirement establishes a more specific abuse-handling obligation, that requirement will apply to the relevant Service to the extent of the conflict.

112. Upstream Provider Terms

Nothing in this Policy prevents an upstream provider from independently exercising rights available under its own:

  • terms.
  • acceptable-use rules.
  • registrar agreement.
  • registry agreement.
  • security policies; or
  • legal obligations.

113. No Legal Determination

Hostwover's enforcement decision is an operational decision concerning use of its Services.

It does not necessarily constitute a legal determination that:

  • a person committed a crime.
  • a civil claim is valid.
  • intellectual property is infringed.
  • a party owns a disputed asset; or
  • a reporter's allegations are legally proven.

114. Good-Faith Decisions

Hostwover may make reasonable good-faith decisions based on information available at the time of investigation.

New evidence may result in modification of a previous decision.

115. Emergency Action

Hostwover reserves the right to take emergency action when reasonably necessary to protect:

  • Hostwover infrastructure.
  • Customers.
  • End Users.
  • upstream providers.
  • external networks.
  • third parties.
  • public safety; or
  • the integrity of the Services.

116. Changes to this Policy

Hostwover may update this Abuse Handling Policy to reflect:

  • changes in Hostwover Services.
  • changes in abuse patterns.
  • security developments.
  • domain-industry requirements.
  • provider requirements.
  • changes in applicable law.
  • operational experience; or
  • improvements to Hostwover's abuse processes.

117. Material Changes

Where required by applicable law, Hostwover will provide reasonable notice of material changes.

118. Continued Use

Continued use of Hostwover Services after an updated version becomes effective constitutes acceptance of the updated Policy where legally permitted.

119. Relationship With the Acceptable Use Policy

The Hostwover Acceptable Use Policy primarily defines conduct that is permitted or prohibited.

This Abuse Handling Policy primarily explains how suspected violations are:

  • reported.
  • evaluated.
  • investigated.
  • escalated.
  • mitigated; and
  • resolved.

120. Relationship With the Acceptable Use Agreement

The Hostwover Acceptable Use Agreement provides contractual rights and responsibilities associated with acceptable use and enforcement.

This Abuse Handling Policy provides the operational process supporting those contractual provisions.

121. Relationship With the Terms of Service

This Policy forms part of Hostwover's legal and operational framework.

Where incorporated or referenced by the Hostwover Terms of Service or a product agreement, Customers agree to cooperate with the abuse-handling procedures described in this Policy.

122. Severability

If any provision of this Policy is found invalid or unenforceable, the remaining provisions will continue to apply to the maximum extent permitted by law.

123. No Waiver

Failure by Hostwover to exercise an enforcement right in one case does not waive its ability to exercise that right in another case.

124. Language

Hostwover may provide translations of this Policy.

Where legally permitted and unless Hostwover expressly states otherwise, the English version will control in the event of a material inconsistency between translations.

125. Definitions

For this Policy:

"Abuse" means activity that violates the Hostwover Acceptable Use Policy, Acceptable Use Agreement, applicable product terms, provider requirements, or applicable law.

"Abuse Report" means a notice alleging suspected abuse involving a Hostwover Service.

"Customer" means a person or entity purchasing, controlling, administering, accessing, or using a Hostwover Service.

"DNS Abuse" means the applicable categories of abuse recognized under relevant domain-industry contractual requirements, including malware, botnets, phishing, pharming, and spam when used as a delivery mechanism for another applicable category.

"Mitigation" means action reasonably intended to stop, restrict, prevent, or disrupt abusive activity.

"Reporter" means a person or entity submitting an Abuse Report.

"Service" means a product, subscription, domain, hosting service, server, email service, API, AI functionality, software service, infrastructure component, or other service supplied through Hostwover.

"Upstream Provider" means a registrar, registry, cloud provider, network provider, email provider, software provider, distributor, data center, or other third party involved in providing a Hostwover Service.

126. Abuse Handling Principles

Hostwover's abuse process is guided by the following principles:

  1. credible abuse reports should be reviewed.
  2. serious threats should receive appropriate priority.
  3. evidence should be considered before enforcement where reasonably practicable.
  4. mitigation should be proportionate to the circumstances.
  5. unnecessary collateral damage should be avoided where reasonably possible.
  6. compromised legitimate systems should be distinguished from intentionally abusive systems where possible.
  7. upstream providers should be involved when they are better positioned or contractually required to act.
  8. Customers should be given an opportunity to remediate when appropriate.
  9. emergency threats may require immediate action.
  10. repeat abuse may justify stronger enforcement.
  11. confidential Customer information should not be unnecessarily disclosed; and
  12. records should be maintained where reasonably necessary for security, compliance, and investigation purposes.

127. Contact

To report suspected abuse or ask questions concerning this Policy:

Hostwover Support

Email: [email protected]

Website: hostwover.com

When submitting an abuse report by email, please use a clear subject such as:

Abuse Report – [Domain / IP / Service]

Do not send passwords, private keys, full payment-card numbers, or other unnecessary authentication secrets with an abuse report.

128. Effective Date

This Abuse Handling Policy becomes effective on the date shown above and applies to abuse reports and investigations involving Hostwover Services from that date forward.

END OF ABUSE HANDLING POLICY