subdy docs

Security & abuse

Our policy, how to report abuse, and reserved names.

Policy

Subdy names must not be used for phishing, malware distribution, botnet C2, or impersonating other services. New subdomains are screened automatically (Google Safe Browsing + an LLM classifier that stores only a category label and risk score — never your page content). A human reviews every flag; enforcement is suspended → frozen → banned depending on severity, with e-mail notice and an appeal address.

Report abuse

Seen a *.subdy.io name doing something harmful? Report it at subdy.io/abuse or e-mail abuse@subdy.io with the URL and a short description. We acknowledge within 24 hours and act on confirmed phishing/malware within one business day (faster for active credential-harvesting).

Reserved names

Infrastructure and brand labels can't be registered: www, api, mail, ns1, ns2, mcp, docs, admin, status, well-known brand names, and similar. The availability check returns "reason": "reserved" for them — pick another name.

Responsible disclosure

Found a vulnerability in Subdy itself? Mail security@subdy.io. We don't run a paid bounty yet, but we credit reporters and fix fast. Please don't test against other users' names.