# What you can send with Prontuno

Prontuno is designed exclusively for transactional email: messages that are necessary to complete or document a user’s action, account activity, purchase, or use of a service.

## Allowed transactional email

- Password resets and sign-in verification codes.
- Account alerts and security notifications.
- Order confirmations, receipts, and shipping updates.
- Invoices, statements, and billing notices.
- Service notices directly related to a user’s account or action.
- Support case confirmations and replies.

The primary purpose of the message must be transactional. Keep promotional content out of operational email.

## Prohibited email

- Marketing or promotional email, even when recipients opted in.
- Newsletters, product announcements, and advertising campaigns.
- Cold outreach or unsolicited bulk email.
- Messages sent to purchased, scraped, rented, or third-party lists.
- Messages that violate applicable anti-spam, privacy, or consumer-protection laws.
- Any attempt to hide the true sender, purpose, or destination of a message.

Use a dedicated marketing email provider for campaigns, newsletters, promotions, lead outreach, and audience broadcasts.

## Avoid mixed-purpose messages

A receipt that mainly confirms a purchase is transactional. A receipt dominated by coupons, unrelated product recommendations, or promotional calls to action can become a marketing message.

Keep transactional templates focused on the event the recipient expects. If marketing content is optional, send it separately through an appropriate provider and honor the recipient’s consent and preferences.

## Recipient and list requirements

- Send only to the address connected to the underlying account, request, or transaction.
- Validate addresses at collection time and correct obvious typos.
- Do not retry permanent bounces.
- Respect suppressions and applicable user notification preferences.
- Protect recipient data and share it only with systems required to deliver the service.

## Protect your sending account

- Enable two-factor authentication.
- Use separate API keys or SMTP credentials for each application.
- Store secrets outside source code and rotate exposed credentials immediately.
- Monitor email logs, bounce rates, suppressions, and webhooks.
- Remove team access that is no longer needed.

## Enforcement

Policy violations can result in sending being disabled for a domain or team and may lead to account suspension. If you are unsure whether a use case is transactional, contact [support@prontuno.com](mailto:support@prontuno.com) before sending.

This guide is a practical summary. The [Terms of Service](https://prontuno.com/terms-of-service/) and [Privacy Policy](https://prontuno.com/privacy-policy/) govern your use of Prontuno.
