"Auto-Block on Leak" is a confident name, and we want to be upfront about how much of it is shorthand. The feature does not watch breach dumps, monitor paste sites, or know that your address has turned up in a stolen database. What it watches is spam arriving at one of your aliases, and it acts when the volume crosses a line.
A burst of spam at an address that was quiet last week is evidence the address is circulating, and often the reason an address starts circulating is that it leaked. But evidence is not proof, and a feature page that blurs the two is not worth your trust. So here is exactly what auto-block does: the trigger, the threshold, the email you get, and the places it does not reach.
If the underlying idea is new to you, an alias is a forwarding address that stands in for your real one, and we cover the basics separately. Auto-block is something an ordinary mailbox cannot do at all: when one address goes bad, you shut that one door and keep the rest of the house.
The trigger, precisely
Every message sent to a shared-domain alias (an address ending in @yeymail.com) goes through our spam checks during the SMTP conversation, the short exchange in which the sending server offers a message and ours decides whether to accept it. Some messages are rejected as spam at that stage: refused during delivery, never accepted and then filtered into a folder. Each of those rejections is recorded against the alias it was addressed to.
When a new spam rejection arrives, the system counts the rejections recorded for that alias over the previous 60 minutes. The count includes every rejection recorded in that window. At ten, the alias is switched off automatically. The check only runs when a spam rejection arrives, so a quiet alias is never re-examined, and if the alias is already disabled, nothing further happens.
"Switched off" means what the manual kill switch means. Later mail is refused during the SMTP conversation itself: the sending server is told there is no such address, nothing is queued, and nothing is filtered into a folder for you to sift through. (Refusing a recipient on the spot is ordinary SMTP behaviour, not a trick.) The alias is not deleted, and you can re-enable it at any time from the dashboard.
Why it is opt-in, and off by default
Switching an address off refuses all mail, including legitimate mail. A password reset, a dispatch notification, a message from a real person: while the alias is off, each is turned away at the door. That is the right trade for some addresses and the wrong one for others, and we are not willing to make it for you silently. So the feature ships off, and stays off until you turn it on.
The addresses worth enabling it for are the ones where a spam flood matters more than the odd lost message: the alias you gave a forum you no longer read, the one attached to a shop you bought from once. The alias your bank writes to is a different case, because losing one legitimate message there could cost you more than any quantity of spam. Auto-block is a tool for the perimeter, not the vault.
The email you get
When auto-block fires, two things happen. An entry is recorded in your activity view, and we send you an email. Its subject line is "We auto-disabled [alias] (spam burst)", with the actual address in place of the brackets. The body tells you how many rejections we saw in how many minutes, and that you can re-enable the alias from the dashboard if this was a mistake.
That last line is there deliberately. Ten rejections in an hour is a strong signal, but it is a threshold, not a verdict, and you know things about the address that we do not. If you are expecting something important through it, switch it back on, take the noise, and turn it off again once the message lands. Nothing was deleted in the meantime.
What it does not cover: your own domains
Auto-block applies only to aliases on the shared yeymail.com domain. It does not cover aliases on a custom domain you own, and the reason is mechanical rather than commercial. The watcher that records spam rejections only watches shared-domain addresses, so for a custom-domain alias the trigger data simply does not exist. There is no count to reach ten, because nothing is counting.
On your own domain the tools are the manual kill switch, which works on every alias you have, and catch-all block rules. If you run a catch-all domain, a block rule does the same job by hand: once an address starts drawing fire, you block it yourself rather than waiting for anything to trigger. Not automatic, but precise, and you choose the moment.
What a spam burst usually means
The pattern is distinctive. An alias that received a message or two a week starts drawing a stream of junk from senders you have never dealt with. It means the address is circulating: it is on a list it was not on before. How it got there varies. The UK's National Cyber Security Centre notes that criminals use contact details exposed in breaches to make phishing messages look legitimate, and Have I Been Pwned separately indexes spam lists, collections of personal data aggregated from many sources and used for targeted spam.
So a burst is often the visible symptom of a leak. But the feature cannot see the cause, only the symptom. It infers from volume, and a burst can also follow a scraped web page or a traded marketing list. If you want to know whether the address appears in a known breach, check it against Have I Been Pwned and act on the results. And the alias itself often answers the next question, because if you only ever gave it to one site, you know who leaked it.
The smoke alarm and the decision
Auto-block is the smoke alarm; the manual kill switch is the decision. The alarm reacts to one specific signature, ten spam rejections against a shared-domain alias inside an hour, and it reacts whether you are at your desk or asleep. The kill switch is yours to pull on any alias, on any domain, for any reason: an address you are done with, a sender you want gone, a leak you read about before the spam started.
Both do the same thing when thrown. Mail is refused at the door during the SMTP conversation, the sender is told there is no such address, and nothing is queued or filtered. The kill switch is never paywalled and keeps working after you cancel, and re-enabling either one is a single control in the dashboard.
If we could honestly call this feature "auto-block on proof of leak", we would. We cannot, because we do not see a leak directly. What we can see is your alias's mail, at our own front door, in real time. Ten spam rejections in sixty minutes is that door being hammered. The feature closes it, tells you it did, and leaves the reopening to you.