Spam Email: What It Is and How to Stop It

Affiliate disclosure: Some links on this page are affiliate links. We may earn a commission if you sign up for a service through one of these links. Read our full affiliate disclosure.

Spam email is unwanted bulk email sent to large numbers of people at once. You receive it because your address has been exposed, collected or guessed at some point. You cannot stop spam completely, but filtering, blocking and protecting your address can cut how much reaches your inbox dramatically.

What is spam email?

Spam email is unsolicited bulk email. This means the recipient did not ask for it and the sender distributes the same or a substantially similar message to many people. The content can vary. Some spam email promotes products, services, competitions or questionable investments. Other messages contain scams, harmful attachments or links to fake websites. Junk email means broadly the same thing. Some providers use “Spam” as the name of the folder where unwanted messages are stored. Others, including Outlook, call it the “Junk Email” folder. Spam email is not automatically the same as phishing. Phishing is a deceptive message designed to steal information, money or access to an account. Spam email is defined mainly by being unsolicited and sent in bulk. The two can overlap. A phishing campaign may send the same deceptive email to thousands of people, making it both phishing and spam email. However, an unwanted bulk advertisement may be spam email without being a phishing attempt.

Why am I getting spam emails?

Receiving spam email usually means that your address has reached a mailing list, database or automated sending system. This can happen even when you have been careful. It does not always mean that you recently gave your address directly to the sender. The address may have passed through several organisations or databases before the message reached you.

Your address was exposed in a data breach

A data breach happens when information held by an organisation is accessed, stolen or exposed without authorisation. Email addresses are commonly stored alongside names, usernames and other account details. If that information is exposed, the addresses may be used to send unwanted email or convincing phishing messages. You can check whether your address has appeared in known data breaches using the free service Have I Been Pwned. It searches publicly catalogued breaches, so a match tells you your address was exposed somewhere and points to which accounts to secure. A clear result is reassuring but not a guarantee, since not every leak, sale or scrape is recorded there. Changing your email password is important if a password was also exposed. However, changing the password does not remove the address from lists that already contain it. The address itself can still receive spam email.

A company sold or shared your address

When you give an email address to a shop, app, competition, newsletter or online service, the organisation may store it in a customer or marketing database. Some companies share information with related businesses, advertising partners or other third parties. Others may sell contact information where local laws and their stated privacy practices allow it. This is one reason an address can begin receiving unfamiliar marketing messages after it was used on an otherwise genuine website. Checking a site’s privacy policy can help you understand whether it says contact information will be shared.

Your address was scraped from a public page

Scraping is the automated collection of information from websites. Programs can scan public pages for text that looks like an email address. An address published on a personal website, business directory, forum, social media profile or public document can therefore be collected without anyone contacting you first. Once collected, it may be added to a marketing list, sold or used directly in a bulk email campaign.

Your address was guessed

A spammer does not always need to find a published copy of your address. Automated systems can generate possible addresses by combining common names, initials, words and domain names. They may try addresses such as firstname.lastname@example.com, contact@example.com or info@example.com. This is sometimes called a directory harvest attack. The sender tests combinations to discover which addresses exist and then uses or sells the valid results.

You entered it on an untrustworthy website

A suspicious website, fake competition or misleading sign-up form may collect email addresses deliberately. The site may use the address itself, pass it to another operator or add it to a list. Even a legitimate-looking form can be risky if the organisation does not clearly explain who operates it or how the information will be used. These causes point to an important limitation. Filtering deals with spam email after someone already has your address. Protecting the address before it is collected can prevent some of those messages from starting.

How to stop and block spam email

You cannot guarantee that no unwanted message will ever reach your account. You can still reduce how much reaches your inbox and improve how your provider handles future messages.

Mark the message as spam email or junk email

Use your email provider’s reporting control instead of simply deleting an unwanted message. In Gmail, select the message and use Report spam. Gmail moves the message to the Spam folder. Google also receives a copy and may analyse it to help identify unwanted email and abuse. In Outlook, select the message and use Report, Report Junk or the equivalent option shown in your version of Outlook. You can normally classify it as junk email or phishing. Reporting gives the provider feedback about messages that reached the inbox. Microsoft says its filtering systems learn from known threats and user feedback. Gmail says reported messages may be analysed to help protect users. This does not mean that one report will immediately stop every similar message. It provides more useful information than deleting the email without reporting it.

Block repeated senders

Blocking is useful when unwanted messages repeatedly come from the same address. In Gmail, open the message, select the additional options menu and choose Block followed by the sender’s name. Future messages from that address should go to the Spam folder. In Outlook, select or right-click the message and choose Block sender, or add the address to the blocked senders list. Future messages from that address are normally directed to the Junk Email folder. Blocking is not always the same as rejecting the email before delivery. In Gmail and many versions of Outlook, the message can still reach your account but is moved out of the inbox automatically. Blocking also applies to the address being used at that time. It is less effective when unwanted messages arrive from constantly changing addresses. Continue reporting those messages as spam email or junk email rather than building an unnecessarily long list of individual senders.

Unsubscribe from senders you recognise

Use unsubscribe controls when the message comes from a real organisation that you recognise. This may include a newsletter you joined, a shop you have used or a service where you knowingly selected marketing emails. Gmail and Outlook can display their own unsubscribe controls for supported mailing lists and subscriptions. In Gmail, an Unsubscribe option may appear beside the sender’s name. Outlook.com also has a subscriptions area where recognised subscriptions can be managed. Unsubscribing from a genuine list tells the legitimate mailing system to stop sending marketing messages. It may take a short period for existing scheduled messages to end. Do not use the unsubscribe link inside a suspicious message from an unknown sender. That link may not be a real mailing-list control.

Do not reply to suspicious messages

Do not reply to spam email, even to ask the sender to stop. A reply tells the receiving system that the address exists, is monitored and belongs to someone willing to interact. This can make the address more useful to the sender. Use the provider’s report and block controls instead. These actions can be taken without starting a conversation with the sender.

Do not click links or open attachments

Links in suspicious messages may lead to fake sign-in pages, malware downloads or websites designed to collect personal information. Do not use contact details contained in the message to check whether it is genuine. Visit the organisation’s official website independently or use contact information you already trust. Unexpected attachments should also remain unopened. A file can be presented as an invoice, delivery notice, document or account warning while containing harmful software.

Avoid loading images in suspicious email

Images in email are sometimes loaded from an external server when the message is opened. A sender can use an invisible image called a tracking pixel to record that the message was viewed. This can reveal that the address is active. Email tracking pixels can also record information such as the approximate opening time and the software used to display the message. Gmail may withhold images when it considers a sender or message suspicious. Outlook also has controls that prevent automatic picture downloads. If an email looks suspicious and the images have not loaded automatically, do not choose to display them. Report or delete the message instead. Check your spam and junk folders occasionally Filters can make mistakes. A genuine account notification, receipt or message from a new sender can sometimes be classified as junk email. Check the folder occasionally before permanently deleting its contents. When a legitimate message has been filtered incorrectly, use Not spam in Gmail or Not junk in Outlook. This gives the provider corrective feedback and returns the message to the inbox.

The unsubscribe trap

The word “unsubscribe” does not automatically make a link safe. A genuine company maintains a mailing list linked to your address. Its unsubscribe control changes your subscription settings so that future marketing messages should stop. A spammer has no reason to respect that request. A fraudulent unsubscribe link may simply open a webpage controlled by the sender. Requesting that webpage can confirm that the individual copy of the message reached a working address. That confirmation can make the address more valuable. It may remain on the current list, be targeted again or be included in other address collections. Unsubscribe when you recognise the organisation, remember signing up or creating an account, and the sender’s address and domain match the real organisation. The content should also be consistent with the relationship you already have with it. Use Report spam, Report junk or Block sender when you do not recognise the sender, the message contains suspicious claims, or the unsubscribe link is part of the email itself and you cannot establish that the sender is genuine. A familiar logo is not enough. Phishing messages can copy the names, branding and appearance of real companies. When available, the unsubscribe control built into Gmail or Outlook is preferable to searching through the body of a questionable message. However, the message must still be treated cautiously if you do not recognise why you received it.

How to get less spam email in the first place

Filtering, reporting and blocking manage unwanted messages after your address has been exposed. A stronger long-term approach is to limit where your main email address is used.

Keep your main address private

Reserve your main address for people and services you trust. Avoid posting it openly on websites, forums and public profiles where automated tools can collect it. Where an address must be published, consider using a separate contact address rather than the one connected to important personal accounts. Be selective when a website asks for an email address. Check who operates the service and why the address is required. A newsletter, competition or download should not automatically receive the address you use for banking, account recovery or private correspondence.

Use email aliases

An email alias is an additional address that delivers messages to your existing inbox. You can give different aliases to different services without publishing your main address. If one alias begins receiving unwanted email, you may be able to filter, disable or replace it without changing the address used for everything else. Aliases can also help identify where an address was exposed. If an alias used with only one organisation begins receiving unrelated messages, that tells you which address reached another mailing system.

Use masked or hide-my-email addresses

A masked address is a generated forwarding address used in place of your real address. Messages sent to it are forwarded to your normal inbox without revealing the destination address to the website. Using a different masked address for each sign-up limits the effect of a data breach or an organisation sharing its contact list. The exposed service has the mask, not the main address. If the mask begins receiving junk email, forwarding from that individual address can be disabled. Your main mailbox and the addresses used for other accounts can remain unchanged. Some private email providers include aliases, masked addresses or similar privacy tools. These features do not make all incoming email private and they cannot remove an address from lists that already contain it. Their practical benefit here is limiting how often the main address is disclosed. You cannot eliminate spam email completely. Addresses can be leaked, shared, scraped or guessed despite reasonable precautions. Consistently reporting junk email, blocking repeated senders and protecting your main address can still reduce how much unwanted email reaches your inbox.

EmailExplained.com
Logo