Security & abuse
Our policy, how to report abuse, and reserved names.
Policy
Subdy names must not be used for phishing, malware distribution,
botnet C2, or impersonating other services. New subdomains are
screened automatically (Google Safe Browsing + an LLM classifier that
stores only a category label and risk score — never your page content).
A human reviews every flag; enforcement is suspended → frozen →
banned depending on severity, with e-mail notice and an appeal
address.
Report abuse
Seen a *.subdy.io name doing something harmful? Report it at
subdy.io/abuse or e-mail abuse@subdy.io
with the URL and a short description. We acknowledge within 24 hours
and act on confirmed phishing/malware within one business day (faster
for active credential-harvesting).
Reserved names
Infrastructure and brand labels can't be registered: www, api,
mail, ns1, ns2, mcp, docs, admin, status, well-known
brand names, and similar. The
availability check returns
"reason": "reserved" for them — pick another name.
Responsible disclosure
Found a vulnerability in Subdy itself? Mail security@subdy.io. We
don't run a paid bounty yet, but we credit reporters and fix fast.
Please don't test against other users' names.