Legal

Acceptable Use Policy

A shared free namespace only works if it stays trustworthy. This page is the short version of what gets a subdomain suspended.

Updated 1 Jan 2025

01Encouraged uses

  • Personal sites, portfolios, blogs and documentation.
  • Open-source project pages and demos.
  • Development, staging and preview environments.
  • Self-hosted applications you run for yourself or a small group.
  • Service verification records and certificate challenges.

02Never permitted

  • Phishing, credential harvesting, or any page that imitates a login screen for a service you do not operate.
  • Distributing malware, ransomware, spyware, stealers, cryptominers or exploit kits.
  • Command-and-control infrastructure, botnet coordination, or hosts used to stage attacks.
  • Impersonating a company, government body, financial institution or individual.
  • Spam infrastructure, including redirect chains, link farms and doorway pages.
  • Child sexual abuse material. This is reported to the relevant authorities without exception.
  • Content that is illegal where it is hosted or where it is served, including material inciting violence or terrorism.
  • Copyright or trademark infringement, including pirated software, media and course material.
  • Fraud of any kind: fake shops, advance-fee schemes, fraudulent investment or crypto offerings.
  • Using DNS records to conceal the true destination of malicious traffic.

03Technical restrictions

  • MX records are unavailable — the platform does not offer mail hosting.
  • NS records are unavailable — delegating a subtree to an external nameserver would place records beyond our validation.
  • Private, loopback, link-local, multicast and reserved IP addresses are rejected as A and AAAA targets by default.
  • Automated or scripted registration is prohibited. Bot protection and rate limits apply to search, registration and reports.
  • Do not attempt to register a name outside the subdomain you own, or to bypass name scoping.
  • Do not create records solely to consume platform resources.

04Naming rules

  • Names that impersonate a well-known brand, bank, government service or security function are reserved and cannot be registered.
  • Names that could mislead a visitor into believing they are on an official page of this platform are reserved.
  • Offensive names, and names chosen to harass a person or group, are not permitted.
  • Attempting to work around the reserved list with lookalike characters or minor variations is treated as a breach of this policy.

05How reports are handled

  • Anyone can report a subdomain — no account is needed.
  • Reports are triaged by category; phishing and malware are treated as urgent.
  • An administrator reviews the evidence and records their findings against the report.
  • Where abuse is confirmed the subdomain is suspended, which deletes its DNS records so it stops resolving immediately.
  • The account owner is notified at the email address on their account and may appeal.
  • Reports found to be unfounded are rejected with a note, and no action is taken against the owner.

06Consequences

  • First, minor breach: notice and a request to remediate.
  • Serious breach, or no response: the subdomain is suspended.
  • Phishing, malware or illegal content: immediate suspension without prior notice.
  • Repeated or deliberate breaches: account termination, and the GitHub identity is recorded to prevent immediate re-registration.

07Reporting abuse

Use the abuse report form, or email abuse@itdev.eu.cc. Include the exact subdomain, what you observed, and any evidence such as a URL or screenshot. Reports with concrete evidence are actioned considerably faster.