dxAuth Abuse Reporting
Reporting channel and response framework for sign-in, email, application-registration, and security abuse.
Reporting channel
- 1.1
Report sign-in abuse, unwanted auth emails, phishing, impersonation, suspicious registered apps, brute force attempts, or security concerns to abuse@doxanh.dev.
- 1.2
General contact: contact@doxanh.dev.
Report contents
- 2.1
Include the application name or domain, the email address receiving unwanted sign-in messages if it is yours to provide, approximate time, relevant headers or screenshots if safe, and your contact email.
Potential enforcement actions
- 3.1
doxanh may suppress or rate-limit abusive sign-in attempts, block risky domains or recipients, disable an application, revoke sessions, preserve records, or escalate severe abuse to providers or authorities where appropriate.
Prohibited uses
- 4.1
dxAuth must not be used for phishing, spam, credential theft, deceptive sender identity, harassment, malware, account enumeration, or attempts to bypass technical, legal, or platform restrictions.
Response framework
- 5.1
Final service-level targets should be set before production. Suggested internal targets are to acknowledge high-risk abuse reports within 1 business day, review urgent safety or security reports as soon as practicable, and document action taken in operational records.