Last updated 19 September 2026
For DNS hosting and related services operated by KumoDNS
| Policy owner | KumoDNS |
| Effective date | 24 August 2026 |
| Version | 1.0 |
| Applies to | KumoDNS.com services, customer accounts, hosted zones, DNS records, APIs and related systems |
This Acceptable Use Policy (the “AUP”) protects the security, reliability and lawful use of the KumoDNS services operated by KumoDNS (“we”, “us” or “our”). It forms part of the agreement governing each customer’s use of the Services. By creating or using an account, submitting or hosting a DNS zone, using an API, or otherwise accessing the Services, the customer agrees to this AUP and must ensure that its users, administrators, resellers, contractors and end customers comply with it.
If this AUP conflicts with the applicable service order or Terms of Service, the order of precedence stated in those documents applies. This AUP does not require KumoDNS to permit any use that creates legal, security, operational or reputational risk.
“Services” means KumoDNS authoritative DNS hosting, DNS management, control panels, APIs, nameservers, monitoring and any related products, infrastructure or support supplied by KumoDNS. “Customer Content” includes domain names, hosted-zone data, DNS records, configuration, metadata and other information submitted to or transmitted through the Services. “Abuse” means conduct prohibited by this AUP or applicable law.
A customer must not use, facilitate, direct, encourage or knowingly permit the Services to support any of the following:
Any conduct that violates applicable law, court order, regulatory direction or binding requirement; facilitates a criminal offence; threatens national security or public safety; or creates a material risk of harm to any person.
Malware distribution or command-and-control; ransomware; botnets; malicious payload delivery; exploit kits; drive-by downloads; cryptojacking; credential-stealing infrastructure; malicious fast-flux or domain-generation activity; or DNS records used to coordinate, conceal or sustain such activity.
Unauthorized access, attempted access, scanning or exploitation of systems or data; credential attacks; interception; unauthorized modification; denial-of-service or distributed denial-of-service attacks; DNS amplification or reflection; cache poisoning; deliberate query floods; or conduct intended to impair a computer, network or service.
Phishing, pharming, smishing support, business-email compromise, impersonation, fraudulent investment or e-commerce schemes, deceptive redirects, fake login or payment pages, identity theft, or any scam or misleading practice.
Unsolicited bulk communications, address harvesting, snowshoe activity, or DNS infrastructure used to send, route, authenticate or support spam or abusive messaging, including deliberately deceptive SPF, DKIM or DMARC configurations.
Child sexual abuse material, grooming, sexual exploitation of minors, or any related facilitation, linking, promotion or concealment.
Credible threats, incitement or instructions for violent crime; terrorist propaganda, recruitment or financing; or services used to facilitate trafficking, extortion or other serious harm.
Infringement or misappropriation of copyright, trade marks, patents, trade secrets or other rights; domains or records used for counterfeiting or flagrantly infringing locations; or repeated rights infringement after valid notice.
Unlawful collection, disclosure, sale, doxxing, stalking or misuse of personal data; hosting records that expose secrets or personal data without authority; or evasion of data-protection requirements.
Unlawful gambling, controlled drugs, weapons, counterfeit goods, sanctions evasion, money laundering, prohibited financial activity, or the sale or promotion of goods or services that are illegal where offered or received.
Resale or access outside the customer’s plan or authorisation; bypassing limits; probing KumoDNS systems without written permission; creating excessive or abnormal load; interfering with logging, security or abuse controls; using false identities; or concealing the responsible user from KumoDNS.
DNS hijacking, unauthorized zone transfers, malicious dangling records, deliberate rebinding, tunnelling or exfiltration without lawful authorization, deceptive internationalized-domain use, typo-squatting for abuse, or manipulation intended to misdirect users or defeat security controls.
Security testing of KumoDNS systems is permitted only with KumoDNS’s prior written authorisation and within the approved scope. Testing of systems owned by others must be lawfully authorised by those owners. A customer must not publish, exploit or retain data obtained through unauthorized testing. Good-faith vulnerability reports should be sent to Contact us. This clause does not grant a licence to test.
Reports should be submitted through KumoDNS's abuse report form. To allow a fair and efficient review, a report should include:
KumoDNS may request further information, forward a report to the customer or relevant provider, preserve evidence, or decline reports that are incomplete, abusive or not reasonably verifiable. KumoDNS does not adjudicate private disputes over domain ownership, contractual rights or trade marks and may require an order from a competent court or authority where the facts are genuinely disputed.
KumoDNS may investigate suspected Abuse and take proportionate action based on the nature, severity, evidence, recurrence, legal requirements and risk to the Services or third parties. Where reasonably practicable and safe, KumoDNS may notify the customer and allow an opportunity to remedy the issue. No advance notice is required for urgent threats, compromised accounts, ongoing crime, child-safety matters, malware, phishing, attacks, legal compulsion, or material operational risk.
Available measures include:
KumoDNS may act on a lawful notice, direction, order or request from a competent authority and may take reasonable steps to restrict access to relevant online activity. Enforcement does not limit KumoDNS’s other contractual or legal rights. KumoDNS is not obliged to monitor all DNS traffic, zones or Customer Content, but may use reasonable technical and manual measures to detect and prevent Abuse.
KumoDNS may immediately suspend, isolate or restrict a zone, record, credential, account or Service where KumoDNS reasonably believes this is necessary to protect security, service availability, customers, third parties or the public; prevent or respond to unlawful activity; comply with law; or contain a compromise. KumoDNS will seek to limit the action to what is reasonably necessary and restore service when the underlying risk has been resolved, subject to the agreement and applicable law.
Customers must cooperate promptly with reasonable investigations and remediation requests. KumoDNS may retain relevant account, configuration, security and abuse records for legitimate business, security, dispute-resolution and legal-compliance purposes, in accordance with its Privacy Policy and applicable data-protection law. Customers must not destroy or alter evidence after receiving a preservation request or becoming aware of a likely investigation or proceeding.
KumoDNS will handle personal data associated with accounts, support and abuse matters in accordance with its Privacy Policy and applicable law, including the Singapore Personal Data Protection Act 2012 where applicable. Abuse reporters should submit only information reasonably necessary for the report. KumoDNS may disclose report details to the customer or relevant third parties where reasonably necessary to investigate, remediate, protect rights, or comply with law, but may withhold information where disclosure may create risk, compromise an investigation or be prohibited.
A customer may request review of an enforcement decision by writing to KumoDNS through its appeal form within 14 calendar days, identifying the decision, relevant account or zone, grounds for review, remediation completed and supporting evidence. Unless KumoDNS agrees otherwise, an appeal does not stay the enforcement action. Reinstatement may be conditioned on verification, removal of Abuse, security remediation, payment of applicable fees, contractual assurances, or enhanced controls. KumoDNS may refuse reinstatement where risk remains material or termination is permitted under the agreement or law.
KumoDNS may update this AUP to address legal, regulatory, security, technical or service changes. Material changes will be notified in the manner stated in the Terms of Service and will take effect on the stated effective date. Continued use after that date constitutes acceptance to the extent permitted by law. The current version should be published at https://www.kumodns.com/aup.php.
| Legal operator | KumoDNS |
| UEN / registration no. | 53530479W |
| Registered address | 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051 |
| Support | Contact us |
| Abuse contact | Report abuse |