How to stop email spam (and work out who leaked your address)
Most advice about spam starts and ends with "click unsubscribe". That is worth doing, but it treats the symptom. The volume of junk arriving in your inbox is mostly a function of how widely your address has been distributed, and that is something you can control going forward even if you cannot undo it.
First, understand how your address got out
An address leaks through a small number of well-worn routes. Knowing which one applies changes what you should do about it.
- You gave it to someone who sold it. Entirely legal in many places if it was buried in the terms you accepted. This is the most common route by a wide margin.
- A company you trusted was breached. Address lists are one of the first things taken and among the easiest to sell on.
- It was scraped. Posting an address in plain text on a public forum, a CV, or a personal site will get it harvested.
-
It was guessed. Common patterns like
firstname.lastname@at a known company domain are generated in bulk and mailed on spec.
Reduce what you already get
Unsubscribe from legitimate senders only
If the mail comes from a real company with a real product, the unsubscribe link works, because ignoring it exposes them to penalties in most jurisdictions. Use it without hesitation.
If the mail is obvious junk — a lottery you did not enter, a pharmacy, a crypto windfall — do not click anything in it at all. For those senders the unsubscribe link is a delivery confirmation: it tells them a human read the message, which makes your address more valuable, not less. Mark it as spam and move on.
Use the spam button rather than delete
Deleting junk teaches your provider nothing. Reporting it feeds a classifier that improves for you specifically and, at large providers, contributes to a sender reputation that affects everyone. It is a few seconds better spent.
Turn off remote image loading
Marketing mail almost always contains a tracking pixel — a transparent one-pixel image on the sender's server. Loading it reports that the message was opened, when, and roughly where from. Every major mail client can block remote images by default, and doing so removes a signal that marks your address as actively read.
Check where you have been exposed
Breach notification services let you enter an address and see which known breaches included it. If yours appears in several, the address is circulating widely and no amount of unsubscribing will fix it. That is the point at which moving important accounts to a fresh address is the rational move.
Stop the next wave
This is where the real gains are. The principle is simple: stop giving the same address to everyone.
Keep a private address genuinely private
Pick one address for the accounts that matter — bank, employer, government services, domain registrar, password manager recovery. Never type it into a signup form for anything else. Never post it publicly. Its value comes entirely from its narrow circulation.
Use a disposable address for anything one-off
A whitepaper download, a discount code, a forum you will post in once, a wifi portal, a trial you will not renew — none of these need to know how to reach you in five years. A temporary address receives the confirmation mail, you do what you came to do, and the inbox deletes itself. Whatever that sender does with the address afterwards is no longer your problem.
Use aliases for accounts you want to keep
When you need the account long-term but still want isolation, an alias that forwards to your real inbox is the better tool. Give a different alias to each service. If one starts sending junk, you know exactly who leaked it, and you can switch that alias off without touching anything else. We compare the two approaches in detail in disposable addresses versus aliases.
Do not publish a plain-text address
If you need a contact address on a public page, use a form, or an address you are willing to abandon. Scrapers are relentless and cheap to run.
What does not work
- Replying to ask them to stop. Same problem as clicking unsubscribe on junk: it confirms a human is reading.
- Blocking individual senders. Sending addresses are disposable and rotate constantly. You will block them all day.
- Elaborate obfuscation like "name [at] domain [dot] com". Scrapers parsed that pattern many years ago. It only inconveniences humans.
A realistic expectation
You will not reach zero. An address that has been in circulation for a decade will keep attracting junk regardless of what you do, and the only complete fix is a new address with disciplined hygiene from day one. What you can achieve quite quickly is a large reduction in new sources, which is what stops the problem getting worse.
The habit worth building is small: before typing your real address into any form, ask whether that sender needs to reach you next year. If the answer is no, give them a disposable one.