This policy governs your use of TunnelNet, a service operated by Andrew Polykandriotis, doing business as MinakiLabs. It applies to every address leased through the service.
Every address we lease comes from a single block registered to us. If one address is used for abuse, the reputation of the entire block suffers. Mail providers, security vendors, and network operators frequently block whole ranges. That means one customer's misuse can break the service for every other customer, including people who have done nothing wrong.
This is the main reason this policy exists, and why we enforce it quickly.
You may not use a leased address to:
The service is inbound. Your leased address exists so that people on the internet can reach your machine; outbound traffic sourced from a leased address is not part of what the service provides.
We drop outbound connections to TCP port 25 (SMTP) sourced from any leased address. This is enforced at both of our network edges, and there is no exception process. We do not offer an email product, and one sender is enough to have the entire block listed by mail providers, which would break the service for every other customer on it.
We do not currently filter any other outbound port. If that changes, we will update this page.
Egress mode is an opt-in setting on a single device. With it on, that device’s outbound internet traffic leaves through us and arrives at its destination carrying your leased address instead of ours. It is intended for hosting: sending mail from a server that also receives it, calling APIs that whitelist by IP, and anything else that needs a stable, predictable outbound identity. It is off unless you turn it on, and turning it on requires accepting the terms in this section.
This is not an anonymity service, and you should not use it as one. Your traffic is attributable to you. The address is leased to your account, we know which account it belongs to, and we record when egress was switched on and off and by whom. If we receive a complaint we will be able to say whose traffic it was, and we will. If you want your traffic not to be traceable to you, this is the wrong product.
Outbound TCP port 25 stays blocked, including with egress mode on. There is no exception process and there is no way to buy one. If you run a mail server, egress mode gives you a stable identity for receiving mail and for relaying through a provider that accepts authenticated submission — it does not give you raw outbound SMTP. Please check that this is what you need before you buy.
You are sharing a reputation. The addresses we lease all sit inside 23.187.152.0/24, and blocklists list the /24 rather than a single address. Traffic you send affects deliverability and access for every other customer in the block. That is why the list of things we do not permit above applies with more force here, and why we act quickly.
What we record, and what we do not. We record when egress was enabled or disabled for a device, who did it, which version of these terms was accepted, and how much traffic the device sent. We do not record where you connected to, what you sent, or the contents of anything. We keep enough to answer an abuse complaint about a specific address at a specific time, and no more.
We can switch it off. If we receive a credible abuse complaint we may disable egress for a device immediately, before contacting you. That leaves the rest of your service running: your address stays yours and inbound traffic keeps working. We will tell you what we received and what we did.
We investigate. Depending on severity we may contact you first, or suspend your address immediately and contact you after. Suspension stops traffic but does not release your address; if the issue is resolved we can restore service. For serious or repeated violations we will terminate the service and release the address.
We will tell you what we received and what we did, unless we are legally prevented from doing so.
We respond to properly formed notices under the Digital Millennium Copyright Act. Our designated agent is Andrew Polykandriotis, registered with the United States Copyright Office in the DMCA Designated Agent Directory. Send notices to support@minakilabs.com.
A notice must identify the work, identify the material you say infringes it and where it is, give your contact details, and include the two statements the DMCA requires: that you believe in good faith the use is not authorised, and that the information is accurate and you are authorised to act for the owner. See Terms of Service §13 for the full text.
We forward valid notices to the customer responsible for the address, and we terminate the service of anyone who repeatedly infringes.
If an address in 23.187.152.0/24 is being used abusively, email support@minakilabs.com with the address, timestamps including timezone, and any relevant logs. We take these seriously. We reply within one business day.