Legal
Acceptable Use Policy
A shared free namespace only works if it stays trustworthy. This page is the short version of what gets a subdomain suspended.
Updated 1 Jan 2025
01Encouraged uses
- Personal sites, portfolios, blogs and documentation.
- Open-source project pages and demos.
- Development, staging and preview environments.
- Self-hosted applications you run for yourself or a small group.
- Service verification records and certificate challenges.
02Never permitted
- Phishing, credential harvesting, or any page that imitates a login screen for a service you do not operate.
- Distributing malware, ransomware, spyware, stealers, cryptominers or exploit kits.
- Command-and-control infrastructure, botnet coordination, or hosts used to stage attacks.
- Impersonating a company, government body, financial institution or individual.
- Spam infrastructure, including redirect chains, link farms and doorway pages.
- Child sexual abuse material. This is reported to the relevant authorities without exception.
- Content that is illegal where it is hosted or where it is served, including material inciting violence or terrorism.
- Copyright or trademark infringement, including pirated software, media and course material.
- Fraud of any kind: fake shops, advance-fee schemes, fraudulent investment or crypto offerings.
- Using DNS records to conceal the true destination of malicious traffic.
03Technical restrictions
- MX records are unavailable — the platform does not offer mail hosting.
- NS records are unavailable — delegating a subtree to an external nameserver would place records beyond our validation.
- Private, loopback, link-local, multicast and reserved IP addresses are rejected as A and AAAA targets by default.
- Automated or scripted registration is prohibited. Bot protection and rate limits apply to search, registration and reports.
- Do not attempt to register a name outside the subdomain you own, or to bypass name scoping.
- Do not create records solely to consume platform resources.
04Naming rules
- Names that impersonate a well-known brand, bank, government service or security function are reserved and cannot be registered.
- Names that could mislead a visitor into believing they are on an official page of this platform are reserved.
- Offensive names, and names chosen to harass a person or group, are not permitted.
- Attempting to work around the reserved list with lookalike characters or minor variations is treated as a breach of this policy.
05How reports are handled
- Anyone can report a subdomain — no account is needed.
- Reports are triaged by category; phishing and malware are treated as urgent.
- An administrator reviews the evidence and records their findings against the report.
- Where abuse is confirmed the subdomain is suspended, which deletes its DNS records so it stops resolving immediately.
- The account owner is notified at the email address on their account and may appeal.
- Reports found to be unfounded are rejected with a note, and no action is taken against the owner.
06Consequences
- First, minor breach: notice and a request to remediate.
- Serious breach, or no response: the subdomain is suspended.
- Phishing, malware or illegal content: immediate suspension without prior notice.
- Repeated or deliberate breaches: account termination, and the GitHub identity is recorded to prevent immediate re-registration.
07Reporting abuse
Use the abuse report form, or email abuse@itdev.eu.cc. Include the exact subdomain, what you observed, and any evidence such as a URL or screenshot. Reports with concrete evidence are actioned considerably faster.