Documentation
Sign inGet started

Abuse and compliance

Bird is shared infrastructure. Abuse controls protect recipients, customer accounts, and the reputation that helps legitimate messages reach their destination.
The Acceptable Use Policy governs what you can send. The acceptable use summary is a plain-language guide. This page explains the controls you may encounter when using Bird.

Monitoring and enforcement

Bird collects account, payment, authentication, and messaging signals for trust and safety review. Depending on the issue and channel, Bird may reject an action, place an account under review, or suspend access for a policy violation.
Enforcement is distinct from a health classification. For example, the Throttled label in email health reports deliverability risk. It does not reduce your sending rate or pause email. API rate limits are also separate: they return a structured error and may include Retry-After.
When Bird restricts an action, use its API error or dashboard notice to identify the cause. Follow the supplied remediation or contact support with the request ID.

Controls you encounter directly

Some controls are visible because they protect public or high-risk actions:
  • CAPTCHA on sensitive account flows. Password signup and some account-recovery actions require a challenge before Bird processes the request.
  • Authentication throttling. Repeated failed sign-ins and invalid API-key attempts are rate-limited by source.
  • SMS passcode country allowlist. One-time passcodes over SMS can be sent only to supported countries. An unsupported destination returns a 422 error.
  • Per-recipient and per-target limits. Passcode sends are capped per recipient address, and verification attempts are capped per recipient set, to reduce automated abuse. See Verify abuse guardrails.
These controls are specific and observable. Do not infer a general account restriction from an unrelated health label or rate-limit response.

Your responsibilities

Send only content that complies with the law, Bird's policies, and channel-provider rules. Keep evidence of consent, honor opt-outs, secure your credentials, and investigate unexpected changes in traffic or recipient feedback.
Each channel has its own requirements. The email abuse and compliance guide covers suppressions, health signals, and sender actions for email.

Next steps