100% ad-free. No ads, no pop-ups, no tracking.
See plans
Temp PostalTemp Postal
Email Security

How to Stop Spam Emails: 21 Strategies That Work in 2026

Twenty-one proven ways to stop spam email and spot phishing: filters, aliases, disposable inboxes, unsubscribe rules, DMARC checks, and breach cleanup.

By Temp Postal EditorialUpdated August 202622 min read

Spam email has not gone away in 2026 - it has changed shape. Bulk pharmaceutical and lottery-scam spam has declined as filters improved, but its place has been taken by more targeted threats: phishing that impersonates real brands, subscription-bomb attacks, and spam generated with AI tools that no longer contains the spelling errors people were taught to look for. Stopping it requires more than a single setting change.

This guide walks through 21 concrete strategies, organized from the easiest habit changes to the more technical protections that businesses and advanced users should understand. It also folds in a full phishing-detection section, because phishing and spam prevention are now the same problem in practice: almost every dangerous message that lands in an inbox is spam that is also trying to steal credentials or money, not just sell something.

Where a strategy involves reporting a message or understanding your legal protections, we cite the actual regulator and standard - the US CAN-SPAM Act and FTC guidance, the IETF's email-authentication RFCs, and the equivalent bodies in the UK, Canada, and Australia - so you can verify anything here yourself rather than take our word for it.

How to stop spam emails, step by step

To stop spam emails: (1) stop giving out your real address for signups, (2) create a disposable or alias address for anything non-essential, (3) mark every unwanted message as spam instead of deleting it, (4) unsubscribe only from senders you recognize, (5) check whether your address has appeared in a data breach, and (6) turn on your provider's strongest filter setting.

This is the condensed procedure. Each step below is expanded later in the guide with the reasoning and tradeoffs, but if you only have five minutes, doing these six things in order will remove the large majority of new spam within a week or two, because most inbox filters relearn quickly once you stop training them with inconsistent signals (deleting spam without reporting it, for example, teaches the filter nothing).

The order matters. Fixing the intake problem (step 1 and 2) before you touch filter settings (step 6) is what separates a durable fix from a temporary improvement, because filters can only act on mail that already reached your provider - they cannot stop a company from selling your address to a third party once it has it.

  • Step 1: Audit where your primary address is currently exposed - contact forms, loyalty programs, old forum signups.
  • Step 2: Replace low-trust signups going forward with a disposable or alias address.
  • Step 3: Mark unwanted mail as spam/junk, not just delete, so the filter learns the sender pattern.
  • Step 4: Unsubscribe only from legitimate senders you recall opting into; never click unsubscribe on unsolicited mail.
  • Step 5: Check your address against a breach-monitoring service and rotate any reused passwords.
  • Step 6: Enable your provider's strictest spam/phishing filter tier and review the spam folder weekly for false positives.

Key takeaways

  • Stopping intake beats filtering after the fact.
  • Consistent spam-button use retrains filters faster than manual deletion.
  • Unsubscribing is only safe on mail you actually opted into.

Why am I suddenly getting so much spam?

A sudden spam surge usually means your address was included in a data breach, sold by a company you signed up with, or harvested by a bot scraping a public page (forum post, GitHub commit, business listing) where you posted it in plain text. It is rarely a single cause, and rarely something you did in the moment the spam arrives.

Spammers do not typically guess addresses one at a time; they buy or scrape lists in bulk. A sudden jump in volume almost always traces back to one exposure event weeks or months earlier - a breach at a retailer, a data broker sale, or your address being posted publicly somewhere a scraper found it.

It is worth distinguishing volume spam (marketing you never asked for, sent to thousands of addresses at once) from targeted spam (messages referencing your name, a recent purchase, or a real account you hold). The second category is far more likely to be phishing built from breach data and deserves more caution, not less, even though it looks more 'personal' and therefore more legitimate.

  • Check haveibeenpwned.com or your password manager's breach-monitoring feature for your address.
  • Search your own name plus email address in quotes to see where it appears publicly.
  • Review recent account signups - free trials and one-off purchases are the most common leak points.

Use a disposable or temporary email address for signups

A disposable email address absorbs spam intended for your primary inbox by acting as a throwaway front door for signups, trials, and one-time downloads. Because the address expires or is never linked to your identity, spam sent to it never reaches the inbox you actually check, and a breach of that address does not expose your real one.

This is the single highest-leverage strategy on this list because it prevents exposure rather than cleaning up after it. Every signup form, gated PDF, coupon code, or Wi-Fi login form is a place your primary address can be sold, breached, or resold to list brokers. A disposable address makes that exposure irrelevant.

The tradeoff is recovery: a disposable inbox is the wrong choice for anything you need to log back into later - banking, healthcare portals, or any account with password-reset flows tied to that address. Reserve disposable addresses for one-off or low-trust interactions, and use a permanent alias (see the next section) for services you may need again.

  • Good use cases: newsletter trials, gated downloads, one-time coupon codes, forum registrations, Wi-Fi captive portals.
  • Bad use cases: banking, healthcare, tax filing, anything with account recovery you'll need in 6+ months.
  • A temporary email address you generate for a single session is one of the fastest ways to test this - try it at /temporary-email.

Key takeaways

  • Disposable addresses prevent spam at the source instead of filtering it after delivery.
  • Never use a disposable address for anything requiring long-term account recovery.

Email aliases vs. disposable addresses: which stops more spam?

Aliases (via your own domain, Apple's Hide My Email, or a provider like your email host's plus-addressing) are best when you want to keep using one address long-term but trace which company leaked it. Disposable addresses are best when you never need the inbox again. Most people benefit from using both for different purposes.

An alias forwards to your real inbox but lets you identify the source of a leak - if you sign up for a retailer as retailer@yourdomain.com and start getting spam from a different company at that alias, you know exactly who sold your data. A disposable address, by contrast, is not even connected to your real inbox, so nothing forwards and nothing to trace back - the tradeoff is you also can't recover it.

Gmail and most providers support '+' addressing (yourname+retailer@gmail.com) for free, though it is trivially stripped by list brokers who know the trick. A dedicated alias service or your own domain is harder for a spammer to normalize away.

Aliases vs. disposable addresses
ApproachTraces leak sourceReaches your inboxBest for
Plus-addressing (name+tag@gmail.com)Yes, until strippedYesCasual tracking, free
Alias service / own domainYes, reliablyYes, forwardedLong-term accounts you may reuse
Disposable/temporary inboxNoNo - separate inboxOne-off signups, trials, downloads

How do spam filters actually decide what's spam?

Modern spam filters combine sender reputation (has this domain sent spam before), authentication results (did the message pass SPF, DKIM, and DMARC checks), content analysis, and your own past behavior (what you've marked as spam or not-spam) to score each message before it reaches your inbox.

No filter is purely content-based anymore. Providers like Gmail and Outlook weight sender and domain reputation heavily, which is why a brand-new domain sending its first bulk email is far more likely to be filtered than an established one - regardless of the actual content.

This is also why training your filter matters: consistently marking unwanted mail as spam (not just deleting it) and consistently marking misfiled legitimate mail as 'not spam' both feed signal back into the model that is specific to your account, on top of the provider-wide reputation signals.

  • Sender/domain reputation - built over the sending domain's history, not just this message.
  • Authentication results - SPF, DKIM, and DMARC pass/fail (covered in a dedicated section below).
  • Content and link analysis - urgency language, mismatched display URLs, attachment types.
  • Your personal signal - what you've marked spam or not-spam historically.

Turn on your provider's strongest filter setting

Most major providers ship a default filter tier tuned to minimize false positives, not maximize spam capture. Gmail, Outlook, and Yahoo all offer a stricter setting or additional phishing protection toggle in account settings that catches more borderline messages at the cost of occasionally flagging legitimate mail.

Check your provider's settings for options like Gmail's 'enhanced safe browsing' and phishing-warning settings, or Outlook's junk-email protection level (No Automatic Filtering / Low / High / Safe Lists Only). Moving from the default to a stricter tier is usually a five-minute change with a meaningful reduction in spam volume.

The cost is more false positives - legitimate mail occasionally lands in spam. Review your spam folder roughly weekly rather than never, so a missed invoice or password reset doesn't sit there unnoticed for a month.

Key takeaways

  • Default filter settings favor fewer false positives over maximum spam capture.
  • A stricter setting trades a small amount of false-positive risk for meaningfully less spam.

Should I click 'unsubscribe' on spam?

Only click unsubscribe on mail from a company you actually did business with or knowingly signed up for. On unsolicited spam or anything that looks like phishing, clicking unsubscribe can confirm your address is active and monitored, which sometimes increases the spam you receive rather than reducing it.

Legitimate marketing mail in the US is required by the CAN-SPAM Act to include a working unsubscribe mechanism and honor it within 10 business days - so for real senders, unsubscribing works and is the right move. The risk is entirely with unsolicited or spoofed mail, where the 'unsubscribe' link itself may lead to a tracking pixel or a phishing page rather than an actual opt-out.

A reasonable rule: if you recognize the sender and recall subscribing, unsubscribe. If you don't recognize the sender, mark it as spam instead and let the filter handle it - do not interact with the message at all.

  • Recognize the sender and remember opting in → unsubscribe is safe and required to work under CAN-SPAM.
  • Don't recognize the sender, or it feels off → mark as spam, do not click anything in the message.
  • List-Unsubscribe header (one-click, no page visit) is generally lower-risk than an embedded link.

What is phishing, and how is it different from ordinary spam?

Phishing is a targeted form of spam designed to steal credentials, payment details, or install malware by impersonating a trusted sender - a bank, employer, or well-known brand. Ordinary spam is usually unsolicited advertising; phishing is deception with a specific fraud goal, and it now accounts for the majority of dangerous email traffic.

The distinction matters because the response is different. Marking bulk advertising spam is largely about filter hygiene; a phishing attempt aimed at your bank login or employer credentials warrants reporting to the impersonated organization, and in serious cases to a national fraud-reporting body, in addition to marking it as spam.

Phishing comes in several forms worth knowing by name: standard phishing (mass, generic impersonation), spear phishing (personalized, using details about you), whaling (targeting executives specifically), clone phishing (a near-identical copy of a real email with a swapped malicious link), and business email compromise, where an attacker gains access to a real corporate mailbox and sends fraudulent payment requests from inside it.

Phishing variants
TypeTargetTypical hook
Standard phishingMass / anyone"Your account is suspended, click to restore"
Spear phishingA specific personReferences real details about you or your recent activity
WhalingExecutives, high-value targetsFraudulent wire transfer or authorization request
Clone phishingPrevious real-email recipientsResends a real message with the link swapped
Business email compromiseFinance/accounting staffFraudulent invoice from a compromised real account

Key takeaways

  • Phishing is spam plus a specific fraud objective - credentials, payment, or malware.
  • Business email compromise starts from a genuinely compromised account, not a spoofed one, which makes it harder to spot.

How can I tell if an email is phishing?

Look for urgent or threatening language, a sender domain that is misspelled or slightly altered, a generic greeting instead of your name, requests for passwords or payment details, and a display link whose real destination (visible on hover) does not match the text shown. Any one of these alone isn't proof, but two or more together is a strong signal.

AI-generated phishing has removed the spelling-and-grammar tell that used to be reliable, so treat polished writing as no signal at all in either direction. The more durable signals are structural: does the sender domain actually match the organization, does the link's real destination match its displayed text, and is the message asking you to do something a legitimate organization would never ask for by email (send a password, gift card codes, or urgent wire transfer)?

Hovering over a link (desktop) or long-pressing it (mobile) reveals the actual destination before you click. If the underlying URL doesn't match the brand it claims to be from, treat the message as phishing regardless of how convincing the rest of it looks.

  • Urgent or threatening language ('act now', 'account will be closed').
  • Sender domain altered subtly (e.g. a swapped letter or added hyphen).
  • Generic greeting ('Dear Customer') instead of your actual name.
  • Requests for passwords, one-time codes, or payment details via email.
  • Display text and actual link destination don't match on hover.
  • Unexpected attachments, especially executables, archives, or macro-enabled Office files.

New phishing techniques to know in 2026

Beyond classic email phishing, watch for QR-code phishing ('quishing') embedded in messages, AI-written phishing with no grammatical tells, and telephone-oriented attack delivery (TOAD), where a phishing email is followed by a phone call from someone posing as the company to 'verify' the suspicious message and pressure you into acting.

QR codes in email bypass link-scanning tools that check URLs in text, because the destination is only readable after scanning. Treat an unexpected QR code in an email the same way you'd treat an unexpected link: verify the sender independently before scanning.

TOAD attacks are effective specifically because the phone call feels like confirmation rather than a second attack - never use a phone number provided in the suspicious email or the follow-up call itself; look up the organization's number independently.

  • Quishing: malicious QR codes replacing traditional links to dodge URL scanners.
  • AI-generated phishing: no longer identifiable by poor grammar or spelling.
  • TOAD (telephone-oriented attack delivery): a follow-up phone call reinforcing a phishing email.

Understanding SPF, DKIM, and DMARC

SPF, DKIM, and DMARC are the three IETF-standardized mechanisms that let a receiving mail server verify a message actually came from the domain it claims to be from. SPF authorizes sending servers by IP, DKIM cryptographically signs the message, and DMARC tells receivers what to do when a message fails both - and lets domain owners see who is spoofing them.

SPF (RFC 7208) publishes a DNS record listing which mail servers are authorized to send for a domain. DKIM (RFC 6376) attaches a cryptographic signature to outgoing mail that receivers can verify against a public key in DNS, proving the message wasn't altered in transit and genuinely originated from that domain's signing key. DMARC (RFC 7489) ties the two together and publishes a policy - monitor, quarantine, or reject - for what receiving servers should do with mail that fails both checks, plus a reporting address for abuse visibility.

For individuals, the practical relevance is that mail failing these checks is exactly the profile of a spoofed sender, and most modern filters weight authentication failures heavily. For anyone who runs a domain and sends email from it - even a small business - implementing all three is one of the most effective anti-spoofing steps available, and increasingly a requirement for reliable inbox placement at Gmail and Yahoo.

Email authentication standards
StandardRFCWhat it verifies
SPFRFC 7208Which mail servers are authorized to send for a domain
DKIMRFC 6376Cryptographic proof the message wasn't altered and came from the signing domain
DMARCRFC 7489Policy for handling SPF/DKIM failures, plus abuse reporting

Key takeaways

  • A message failing SPF, DKIM, and DMARC is the technical signature of a spoofed sender.
  • Domain owners should implement all three, not just SPF - DMARC is what actually enforces a policy.

How can I check if a domain has DMARC set up correctly?

Use a free DMARC lookup tool (or the command `dig TXT _dmarc.example.com`) to view the domain's published policy. A properly configured domain will show a DMARC record with a `p=` tag set to quarantine or reject, not `p=none`, which only monitors without enforcing anything.

A `p=none` policy means the domain owner is only collecting reports, not instructing receivers to reject failing mail - so its presence alone doesn't guarantee protection. This matters if you're evaluating whether a business email you received is likely genuine: a domain with no DMARC record at all, or one stuck at `p=none` for years, is easier to spoof convincingly.

This check is more useful for security teams and IT admins evaluating vendor or partner domains than for everyday inbox users, but it's a quick way to sanity-check whether a company that claims to take security seriously has actually enforced anti-spoofing on its own domain.

Regular email hygiene habits that reduce spam over time

Monthly subscription audits, tiered email addresses (primary, secondary/shopping, disposable), and consistently reporting spam instead of deleting it compound over months into a measurably cleaner inbox. None of these are one-time fixes - they are habits that need to repeat.

A tiered system - one address for people who need to reach you personally, a secondary address for online shopping and subscriptions you might want to keep, and disposable addresses for everything else - keeps any single leak contained to one tier instead of your whole digital life.

A monthly ten-minute audit of active subscriptions catches services you forgot you signed up for, which are both a spam source and, if breached later, a source of your data circulating for years without your knowledge.

  • Primary address: only people you know and accounts you can't afford to lose.
  • Secondary address: online shopping, subscriptions you might renew.
  • Disposable address: everything else, especially anything you'll use once.
  • Monthly audit: review active subscriptions and unsubscribe from anything unused.

Business email compromise: protecting a company inbox, not just a personal one

Business email compromise (BEC) happens when an attacker gains real access to a corporate mailbox - often through a prior phishing success - and uses it to send fraudulent, convincing payment or data requests from inside a trusted account. Preventing it requires a callback-verification policy for payment changes, not just spam filtering.

Because BEC messages come from a genuinely compromised account, they pass SPF, DKIM, and DMARC and look identical to normal correspondence from that person. Content filtering alone cannot catch it - the defense is procedural: any request to change a payment destination, wire funds, or share sensitive data should be confirmed by phone using a number looked up independently, never a number or reply provided in the email itself.

Organizations should also apply the same authentication and 2FA practices to shared or departmental mailboxes as they do to individual accounts, since these are common BEC entry points and are often under-secured relative to executive accounts.

Key takeaways

  • BEC mail passes all standard authentication checks because it comes from a real, compromised mailbox.
  • Callback verification on a number you look up independently is the actual defense, not spam filtering.

Do temporary email services actually cut down on phishing exposure?

Yes, indirectly: using a disposable address for low-trust signups reduces the number of companies holding your real address, which reduces the pool of potential future breaches your primary inbox could be exposed through. It does not protect you from phishing sent to accounts you already hold under your real address.

The mechanism is exposure reduction, not detection. A temporary inbox will not identify a phishing email any better than a permanent one - the same red flags apply. What it does is shrink the number of places your long-term address exists, which over years measurably reduces how often it appears in a breach, because it was simply never given out in the first place.

It also creates a useful signal: if a disposable address created solely for one website starts receiving phishing attempts, you know precisely which company leaked or sold it, information you would not have if you'd used your primary address for the same signup.

Reporting phishing and spam: US rules and where to report

In the US, unsolicited commercial email is regulated by the CAN-SPAM Act, enforced by the FTC, which requires accurate headers, no deceptive subject lines, and a working unsubscribe link honored within 10 business days. Report phishing emails by forwarding them to reportphishing@apwg.org and to the FTC at reportfraud.ftc.gov.

CAN-SPAM applies to commercial email, not to fraud or phishing specifically - phishing is prosecuted under separate wire-fraud and computer-fraud statutes, but the reporting channel for the message itself is the Anti-Phishing Working Group (APWG), a coalition that aggregates phishing reports from ISPs, banks, and security vendors. Forwarding a suspicious message to reportphishing@apwg.org contributes it to blocklists used across the industry.

For consumer fraud broadly - including phishing that led to financial loss - the FTC's reportfraud.ftc.gov intake feeds directly into law enforcement referral networks. This is distinct from simply marking a message as spam in your inbox, which only affects your own filter.

  • Phishing emails → forward to reportphishing@apwg.org
  • Consumer fraud / financial loss → file at reportfraud.ftc.gov
  • Commercial spam violating CAN-SPAM (no working unsubscribe, forged headers) → report to the FTC as above

Reporting phishing and spam in the UK, Canada, and Australia

The UK routes phishing reports through the NCSC at report@phishing.gov.uk and fraud through Action Fraud. Canada enforces its Anti-Spam Legislation (CASL) with the CRTC and takes phishing reports through the Canadian Anti-Fraud Centre (CAFC). Australia regulates spam under the Spam Act 2003 and takes reports through Scamwatch, run by the ACCC.

Each country's reporting path feeds a national blocklist and fraud-intelligence system, and using the correct one for your region gets the report to people who can actually act on it, rather than a generic inbox. If you operate a temporary or disposable email tool for users in multiple regions, it's worth linking each region to its own reporting authority rather than defaulting everyone to the US process.

Regional legislation also differs meaningfully in scope: CASL in Canada is broader than CAN-SPAM, requiring express or implied consent before sending most commercial electronic messages at all, not just an opt-out mechanism after the fact. The Australian Spam Act 2003 similarly requires consent, identification of the sender, and a functional unsubscribe facility.

  • United Kingdom: report@phishing.gov.uk (NCSC); fraud via Action Fraud. See /uk/temp-mail for UK-specific guidance.
  • Canada: Canadian Anti-Fraud Centre (CAFC); spam enforcement under CASL via the CRTC. See /ca/temp-mail.
  • Australia: Scamwatch (ACCC); spam enforcement under the Spam Act 2003. See /au/temp-mail.
  • United States: reportphishing@apwg.org and reportfraud.ftc.gov under CAN-SPAM. See /us/temp-mail.

Key takeaways

  • Reporting to the correct national body matters more than reporting volume - it feeds real blocklists and fraud intelligence.
  • Consent requirements differ significantly: CASL and the Australian Spam Act require opt-in consent; CAN-SPAM only requires an opt-out.

Mobile-specific spam and phishing risks

Phishing links are harder to inspect on mobile because there's no mouse-hover preview, screen space hides full URLs, and SMS/email previews often truncate sender addresses. Long-press a link before tapping to reveal its destination, and treat unexpected app-install prompts or QR codes in mobile email with the same suspicion as desktop links.

Mobile mail clients frequently show only a display name, not the full sender address, unless you tap to expand it - always expand and check the actual address before trusting a message that appears to be from a known contact or brand.

Because mobile browsers render pages differently, a phishing site optimized for mobile can look more convincing on a phone than the same page would on a desktop browser with more visible chrome (address bar, security indicators).

  • Tap to expand the sender's full address rather than trusting the display name.
  • Long-press links to preview the destination before tapping.
  • Be skeptical of unexpected app-install or 'update required' prompts inside an email.

Common myths about spam filters and unsubscribing

Common myths include: that spam filters catch everything (they don't - sophisticated phishing regularly bypasses them), that unsubscribing always reduces spam (it can increase it from illegitimate senders), and that a well-written, error-free email is automatically safe (AI tools have eliminated grammar as a reliable tell).

No spam filter, however advanced, achieves 100% accuracy - vendors avoid publishing precise catch rates because they vary enormously by mailbox, sender mix, and time period, and any specific percentage claim you see quoted online should be treated skeptically unless it cites a named, dated study.

The 'unsubscribe makes it worse' myth is only half-true: it's accurate for illegitimate senders (who use the click to confirm your address is live) and false for CAN-SPAM-compliant legitimate senders (who are legally required to honor it). The skill is telling the two apart, which is why the sender-recognition rule earlier in this guide matters more than a blanket policy either way.

Frequently confused terms: spam, phishing, and malware email

Spam is unsolicited bulk email, regardless of intent. Phishing is a subset of spam (or sometimes a single targeted message, not bulk at all) designed to steal credentials or money through deception. Malware email delivers malicious software, typically via an attachment or a link to a drive-by download, and often overlaps with phishing as the delivery vector.

These categories overlap in practice - a phishing email that also carries a malicious attachment is both phishing and a malware vector - but distinguishing them helps you choose the right response. Spam alone: mark as spam. Phishing: mark as spam and consider reporting to APWG or your national body. Malware attachment: do not open it under any circumstances, even 'to check', and report it the same way as phishing.

  • Spam: unsolicited bulk mail, usually advertising.
  • Phishing: deception aimed at stealing credentials, payment info, or access - can be bulk or highly targeted.
  • Malware email: delivers malicious software via attachment or linked download, often combined with phishing.

Frequently Asked Questions

What is the fastest way to stop spam emails?

Stop giving out your primary address for new signups and switch to a disposable or alias address immediately. This doesn't clean up existing spam, but it stops new sources from being added, which is the highest-leverage single change most people can make in a day.

Does marking an email as spam actually help?

Yes. Marking a message as spam (rather than just deleting it) trains your provider's filter on that sender pattern, both for your account and, at scale, for the provider's broader reputation scoring of that sender or domain.

Is it safe to unsubscribe from spam emails?

Only if you recognize the sender and remember opting in. Legitimate senders in the US must honor unsubscribe requests under CAN-SPAM. On unrecognized or suspicious mail, unsubscribing can confirm your address is active - mark it as spam instead.

Can a temporary email address stop spam completely?

No single tool stops spam completely. A temporary or disposable address prevents new exposure by keeping your primary inbox out of low-trust signup forms, but it doesn't clean up spam already sent to an address you've used for years.

How do I know if a link in an email is safe?

Hover over the link (or long-press on mobile) to see its real destination before clicking. If the underlying URL doesn't match the brand or organization the email claims to be from, treat it as unsafe regardless of how the email looks.

What should I do if I already clicked a phishing link?

If you didn't enter any information, run a malware scan and monitor accounts. If you entered a password, change it immediately from a different device, enable two-factor authentication, and check for unauthorized changes like new forwarding rules.

What is SPF, DKIM, and DMARC in simple terms?

They're the three technical standards that let email servers verify a message really came from the domain it claims. SPF checks the sending server, DKIM checks a cryptographic signature, and DMARC sets the policy for what happens when a message fails both checks.

Why did a legitimate email end up in my spam folder?

This is usually a false positive from aggressive filtering, often triggered by a new sending domain, a link-shortening service in the body, or content patterns common to marketing email. Check your spam folder periodically and mark misfiled mail as 'not spam' to correct the filter.

How often should I audit my email subscriptions?

Roughly once a month. A short review of active newsletters and marketing subscriptions catches forgotten signups before they compound into meaningful spam volume, and helps you notice if an unfamiliar sender has appeared without your knowledge.

Where do I report phishing emails in the US?

Forward phishing emails to reportphishing@apwg.org, which feeds industry-wide blocklists. For fraud involving financial loss, file a report at reportfraud.ftc.gov, which is run by the Federal Trade Commission.

Where do I report phishing in the UK?

Forward suspicious emails to report@phishing.gov.uk, run by the National Cyber Security Centre (NCSC). For fraud that resulted in financial loss, report separately to Action Fraud.

Where do I report spam or phishing in Canada?

Report phishing and fraud to the Canadian Anti-Fraud Centre (CAFC). Unsolicited commercial email that violates Canada's Anti-Spam Legislation (CASL) can also be reported to the CRTC's Spam Reporting Centre.

Where do I report spam or phishing in Australia?

Report scams and phishing to Scamwatch, run by the Australian Competition and Consumer Commission (ACCC). Spam that violates the Spam Act 2003 can also be reported directly to the ACMA.

Is AI-generated spam harder to detect?

Yes, because it eliminates the spelling and grammar errors that were once a reliable warning sign. Detection now needs to rely on structural signals instead - sender domain accuracy, authentication results, and whether the request itself is something a legitimate sender would actually make.

What is business email compromise (BEC)?

BEC is when an attacker gains real access to a corporate mailbox and sends fraudulent requests, often for wire transfers or sensitive data, from inside a genuinely trusted account. It passes standard authentication checks because the account itself is real, which makes it harder to catch with filtering alone.

Do businesses need SPF, DKIM, and DMARC even if they're small?

Yes. Major providers like Gmail and Yahoo increasingly require these for reliable inbox placement, and without them, it's trivial for someone to spoof your domain and send phishing that appears to come from your company.

What's the difference between phishing and ordinary spam?

Spam is unsolicited bulk email, usually advertising. Phishing is deception specifically designed to steal credentials, payment details, or install malware by impersonating a trusted sender - it can be sent in bulk or targeted at a single person.

Can I stop spam by changing my email address entirely?

It works, but it's a last resort - you lose account recovery continuity everywhere the old address is registered. Auditing where the address is exposed and switching future signups to aliases or disposable addresses usually solves the problem without starting over.

Sources & further reading

Related Reading

Explore the blog

Put It Into Practice

After reading the strategy, the fastest next step is to test the workflow with a real disposable inbox. That makes the comparison practical instead of theoretical and helps you see whether the verification flow, delivery speed, and privacy tradeoffs fit your use case.

Chat on WhatsApp