If a site or service hosted on Dargo infrastructure is engaged in phishing,
malware distribution, credential theft, spam, CSAM, or any other activity
prohibited under this policy, email abuse@dargo.net.
Please include, at a minimum:
- The full URL (e.g.
https://foo.mydargo.com/login.html) — this is what our tooling keys off to locate the responsible device and account.
- The nature of the abuse (phishing, malware, spam, DDoS source, etc.). One line is enough.
- If you have a screenshot or a live sample, attach it — helps us distinguish targeted abuse from a false positive.
- Your name and contact if you want a status update. Anonymous reports are welcome and are acted on with the same priority.
Response commitment
- Acknowledgement within 4 business hours (US Pacific).
- First action within 24 hours. Typically the offending URL is taken offline at our edge — the URL stops serving immediately — or, if the compromise appears to span multiple apps, the entire device is paused (every subdomain on that device goes offline within seconds).
- Complete investigation within 5 business days for a legitimate report. Longer only if we need to contact the device owner and they don't respond.
Acceptable use — what's not OK
Do not use Dargo infrastructure to host or facilitate:
- Phishing — pages designed to steal credentials or payment information from visitors who think they're on a legitimate site.
- Malware distribution — hosting binaries, scripts, or exploit kits intended to run without the visitor's informed consent, or operating command-and-control endpoints for previously-installed malware.
- CSAM or other illegal-per-se content — reported to the appropriate authority and the device paused immediately, no notice.
- Bulk unsolicited email (spam) — via the built-in transactional-email service (blocked at the platform layer by per-device email quotas), via your own SMTP relay running as an app, or via third-party services that trace back to a Dargo IP.
- DDoS staging — using a Dargo device as a source or amplifier for volumetric attacks on other services.
- Cryptocurrency mining without disclosure — mining pool clients or browser-mining scripts served to visitors without an explicit consent step.
- Copyright-infringing content in a way that we receive a DMCA notice for — we honor takedowns as required by law.
- Circumventing our billing — repeated deletion + re-creation of BYOD devices to reset the free-traffic allowance, gaming the free-slot quota via multiple accounts, etc.
What Dargo does when abuse is reported
- On-call verifies the report against our records — owner, install timestamp, live proxy state — using internal tooling that resolves the reported hostname to the responsible device and user account.
- On-call chooses one of two responses:
- Surgical takedown — removes only the offending URL. The device stays online and its other apps stay served. Preferred when only one app on a multi-app device is compromised.
- Full device pause — every subdomain and custom-domain configuration removed, tunnel-user deleted. The whole device goes dark within seconds. Preferred when the device itself is compromised or the report cites unlawful content.
- The device owner is emailed a summary of what was found, what we did, and how to appeal or restore service. For a first-time surgical takedown of a compromised app, restoring service is typically a matter of the owner cleaning and redeploying the app and asking us to un-take-down the URL.
Repeat offenders
An account with two verified abuse incidents in a 90-day rolling window is subject to permanent BYOD suspension: existing BYOD devices removed, no new BYOD slots issuable.
Hardware customers with two verified incidents are subject to a mandatory operator review before further BYOD provisioning.