You have already tried the obvious things. You unsubscribed. You built filters. You marked the worst of it as spam and blocked a few senders. The mail kept coming, and some weeks it got worse. That is not a discipline problem. The tools you were handed all act on messages, and the thing generating the messages is not a message.
Here is the short version. Spam does not happen to your inbox, it happens to your address. If the idea of a separate address per site is new, what an email alias is covers the mechanism. Every tactic that sorts, hides or deletes mail after it arrives is working downstream of the actual cause, which is that one string of text has been handed to hundreds of parties and at least one of them has sold it, lost it, or been breached.
What follows is what each conventional tactic really does, exactly where it stops, and the one structural change that shifts the problem instead of tidying it. It also says the thing most spam advice avoids: you cannot un-leak an address. Nothing here, and nothing you can buy, will give you a spam-free inbox. What is achievable is a bounded, traceable trickle instead of an open-ended one, and that turns out to be worth quite a lot.
Why you get spam at all
Spam is a volume business and its raw material is address lists. Your address got onto those lists by one of a small number of routes, and probably by several at once.
- A company you gave it to was breached, and the dump was traded, merged and resold.
- A company you gave it to shared or sold it deliberately, usually under a line in the privacy policy about trusted partners.
- It was scraped from somewhere public: a forum post, a WHOIS record, a committee page, a PDF that someone uploaded years ago.
- It was guessed. If your address follows a predictable shape at a well-known domain, a generator finds it without anybody leaking anything.
- It was appended. Brokers match a name and postcode you gave one company against an email address held by another, then sell the joined record.
Once your address is in one of those files it ends up in the others. Lists get merged, cleaned, appended and resold. There is no central registry to remove yourself from, and no way to reach a copy sitting on somebody else's server. A suppression request binds the company you send it to and nobody else.
This is also why you cannot tell who leaked you. Every one of those files holds the same string. Mail arriving from a company you have never heard of carries no evidence at all about which of your hundred relationships was the source.
The unsubscribe trap: when it works, and when it just confirms a live address
Unsubscribing is genuinely effective against one category of mail: real marketing from a real company that intends to obey the rules. Large senders now have a commercial reason to honour it. Google's sender guidelines require bulk senders to support one-click unsubscribe and to keep the rate at which recipients report their mail as spam below 0.3%, with an advice line of staying under 0.1%. A sender that ignores unsubscribe requests fails that test quickly.
The safe way to unsubscribe is the one that never touches the message body. Mail from a compliant sender carries a List-Unsubscribe header, and RFC 8058 defines a companion header so your mail app can submit the request itself after you confirm. That is the unsubscribe control your provider shows next to the sender's name, not the link in the footer. Using it loads none of the sender's images, follows none of their links, and hands over no click token.
The trap is the other kind. An unsubscribe link buried in the footer of mail you never signed up for is a URL with an identifier in it, and that identifier is you. Fetching it proves that a human being read that message on a live address. On a list where most entries are dead, that promotes yours, and a confirmed-live address is worth more the next time the list changes hands.
The test is simple. Do you recognise the sender, and did you actually sign up? Does your mail app offer its own unsubscribe control, which means the sender published the header properly? If yes to both, unsubscribe and it will almost certainly work. If the mail is pure spam, do not click anything inside it, including images, which fetch a URL of their own.
One more limit is worth knowing. An honest unsubscribe binds that one sender. If they have already sold, shared or lost your address, unsubscribing stops their mail and does nothing whatsoever about the copies.
Filters: containment, not cure
Two different things get called filtering, and they fail in different ways.
The first is your provider's spam classifier, and it is genuinely good. Gmail and Outlook judge incoming mail on sending domain reputation, IP history, whether SPF, DKIM and DMARC line up, and how many recipients report that sender. It is aggregate and statistical, which is its strength: it polices senders across millions of mailboxes rather than trying to understand your personal relationship with any one list.
The second is the rules you write yourself, and those are string matching on fields the spammer controls. From address, subject line, body text. All three rotate. A rule you write today matches the wave you wrote it against and misses the next one, so the rule list grows while the hit rate falls. Anybody with a hundred hand-written filters has a hundred snapshots of old spam.
Filtering also carries a cost that guides tend to skip. Every point of aggressiveness you add pushes more legitimate mail into the spam folder. Rules that delete on sight are how people miss a delivery notice, a password reset or an invoice. If you have ever found something important in Spam three weeks late, that was the price of the filtering, not a fault in it.
So here is the fair conclusion, and it argues against doing anything else. If your provider's classifier is holding the volume out of sight and you are not being harmed by it, filtering may be all you need. It costs nothing and demands no habit. What it cannot do is reduce what arrives at the server, tell you which relationship leaked you, or keep your address out of the next breach dump. It is containment, and containment is a legitimate answer to a problem you have decided to live with.
Report and block: what it really achieves
Reporting spam does two things, and only one of them is about you.
The small effect is on your own mailbox, where the classifier takes your report as one more signal. The large effect is aggregate. Complaint rate is the number that decides whether a sender gets filtered for everybody, and the thresholds are published. Your report is one vote in that. Reporting real spam is a small public good and worth the second it takes.
There is a corollary. Reporting mail you did sign up for as spam is how a legitimate newsletter gets its reputation damaged for everyone else on it. If you asked for it, unsubscribe. Keep the spam button for mail you never asked for.
Blocking is weaker than most people assume. In Gmail, blocking a sender routes their future mail to Spam. That is the entire mechanism: a per-address rule that moves mail into a folder you already ignore. It does not tell the sender anything, does not remove you from a list, and does not stop the message being accepted by the server. Bulk spam rotates sending addresses continually, so blocking one is like blocking a phone number that changes every morning.
Block a single persistent human who keeps mailing you. Do not build a strategy on it.
The pattern underneath: the address itself is the problem
Look at what unsubscribing, filtering, reporting and blocking have in common. Every one of them acts after delivery, on a message, one message at a time. The thing that stays constant underneath all of it is the address.
One address given to every party you have ever dealt with does two harmful things at once. It works as a join key, which is how separate databases become a single profile of you: the shoe shop's record, the airline's record and the breach dump all match on the same string. And it creates shared fate. Any one of those hundreds of parties can burn the address for all the others, and you have no way to know which one did.
You cannot revoke it selectively. Nothing in email lets you say stop accepting mail that originates from the company I bought trainers from in 2019. The address is on or off, and off means off for your bank as well.
And you cannot rotate it. Changing address means changing a login identity across every account you hold, updating recovery routes, and telling every human who knows you. That asymmetry is the whole problem. Acquiring your address costs a spammer almost nothing. Changing it costs you a weekend and then a year of loose ends.
Which turns the question around. The useful question is not how to filter this address better. It is why one address is carrying all of this.
The structural fix: a separate address per service, each with an off switch
The change is to stop treating your email address as your identity and start treating it as a credential you issue once per relationship. Every site, shop, newsletter and form gets an address that exists only for it, and all of them deliver into the inbox you already read. Three things follow immediately.
- Attribution. Mail arriving at an address you gave to exactly one company came from that company, or from somebody that company handed it to. No guessing.
- Scoped revocation. Switching off one address ends one relationship. Nothing else in your mail life moves.
- A real off switch. The better implementations refuse the mail during the SMTP conversation rather than accepting it and deleting it. RFC 5321 describes the 550 reply a server returns for an address it knows is not deliverable, typically with a string such as no such user. Nothing is queued, nothing bounces from your side, and list hygiene on the sender's end eventually marks the address dead.
There are several ways to get this, and they differ mostly in cost and durability.
- Plus addressing. Adding a detail part to your existing address, as in name+shop@gmail.com, is a convention supported by Gmail, Outlook and Fastmail among others, and RFC 5233 defines the Sieve test that matches on that detail part. The separator itself is left to each mail system rather than fixed by the standard. It is free and it gives you attribution. It gives you no control, because anyone can strip everything from the plus sign onwards and still reach the real mailbox, and list cleaners do precisely that. Some signup forms also reject the plus character.
- A second free account. Fine for separating one high-risk category, such as shopping, from everything else. It stops scaling at about two, because each one is another inbox to remember to check.
- Masking built into something you already pay for. Apple's Hide My Email in iCloud+, Fastmail's masked email, Firefox Relay, DuckDuckGo Email Protection and Proton Pass all generate per-site addresses that forward to a real inbox. If you are already inside one of those ecosystems, start there before you buy anything new.
- Your own domain. Route addresses on a domain you control, through a mail host or a routing layer such as Cloudflare Email Routing. This is the most durable option, because you own the namespace: if the provider disappoints you, the addresses move with you.
- A dedicated alias service. Several exist, including SimpleLogin and addy.io. They differ on price, on whether replying needs setup, and on what happens to your addresses if you stop paying, which is the question worth asking first.
Whichever you pick, check two things before you commit, because they are what separates a system you keep from one you abandon in three weeks.
First, replies. If an address can only receive, then the first time a shop answers your support question you will reply from your real address and undo the whole exercise. Find out whether replying as the alias is automatic or whether it needs per-address setup in your mail client.
Second, the exit. Read what happens to your addresses if you stop paying or the service shuts down. Addresses that stop working take your accounts with them, because they are the recovery route. That is the strongest argument for using a domain you own.
And the honest caveat. This is a per-signup habit. It costs a few seconds at every form, forever, and a browser extension that generates the address in place is usually the difference between a habit that survives and one that does not. If you know you will not keep it up, do not spend money on it. Free filtering suits you better than a system you stop using in April.
Killing an address that is already burned
Suppose one address is already ruined. It is in the dumps, it collects forty pieces of junk a day, and you want out. The mistake here is silent abandonment. An address you stop reading but leave switched on is the worst of both states, because it keeps accepting mail while you stop noticing the password reset that lands on it.
Do it in this order.
- Inventory first. Search the mailbox for welcome, verify your email, your receipt, password reset and confirm your account. That search is your account list, and it will be longer than you expect.
- Move the accounts that can lock you out, before anything else. Bank, tax, phone, domain registrar, and the recovery address on your main email account itself.
- Update recovery and two-factor routes as you go. This is the step people skip, and skipping it means you never actually left: the burned address is still the master key to everything.
- Give each moved account its own new address rather than one shared replacement. Otherwise you are rebuilding the same single point of failure with a fresher string.
- Tell the humans separately. Contacts do not need a per-relationship address, they need to know where you are now.
- Leave the old address receiving for six to twelve months, routed into a folder rather than the inbox, and check it weekly. Forgotten accounts surface slowly.
- Then switch it off, ideally by refusing mail rather than by deleting the mailbox. A deleted mailbox can at some providers be reissued later, which hands your leftover password resets to a stranger.
This takes an evening for the accounts that matter and then a slow trickle for a year. There is no faster version, and any service claiming to do it for you is either just changing your forwarding or lying.
Honest expectations for an old address you cannot abandon
Now the part most spam guides will not tell you. You cannot un-leak an address. Every copy already made stays made. There is no product, free or paid, that can reach into a broker's file or a traded breach dump and delete you, and anyone advertising that is selling a fiction.
Data removal services are a partial and real exception, but understand what they are. They file deletion requests with brokers who operate where the law grants a right to erasure. That works at the legitimate end of the market, does nothing about criminal dumps, and has to be repeated, because brokers re-acquire.
So for the address you have to keep, set the expectation properly. What improves is not the volume of what already exists. It is the growth rate.
- The line flattens, because you stop adding new signups to that address.
- Provider filtering keeps most of the existing flow out of sight, which it was already doing.
- New spam becomes diagnostic. Anything arriving on a per-service address names its own source before you finish reading it.
- The total becomes bounded by how many addresses you have issued, rather than by how many copies of one address exist in the world.
That is what for good can honestly mean here. Not zero. Spam stops being an open-ended condition of owning an inbox and becomes a list of specific, identifiable, switchable-off sources, plus one legacy address that you keep on a leash.
And a genuine argument against doing any of this. If your address has been in circulation for fifteen years, the classifier holds it, and you have largely stopped noticing, then doing nothing is a defensible choice and no guide should talk you out of it. The change pays off forwards, not backwards. It is worth starting for the next fifteen years of signups, not for the last fifteen.