SPAM AND INBOX OVERLOAD
Why Your Inbox Fills With Spam: How Your Address Leaks in the First Place
By AUTHOR NAME · September 6, 2026 · 12 min read
THE SHORT VERSION
|
“How did they get my email?” is a better question than it sounds, because it has actual answers. Spam doesn’t materialise out of the ether, and it isn’t punishment for carelessness. Your address travelled from you to a list through a specific, identifiable route — usually one of eight — and knowing which ones matter changes what you should do about it.
Start with the scale, because it explains the economics.
| 51.8% | of global email traffic was spam in 2025 by Statista’s tracking — somewhere around 195 billion junk messages a day. At that volume, addresses aren’t targeted. They’re inventory. |
Nobody chose you. Your address is one row in a file with several million other rows, bought for a trivial sum, and the sender’s economics work even if almost everyone ignores it. Here is how your row got into that file.
This is the largest single source, and the most important thing about it is that it involves no mistake on your part. You gave an address to a legitimate business; that business was compromised; your address is now in a file being traded.
The scale is difficult to overstate. Have I Been Pwned, the breach-notification service, indexes billions of compromised accounts drawn from thousands of incidents, and single dumps have been enormous — one address list found circulating among spam operators in 2017 held over 711 million entries by itself.
Breach data doesn’t stay in its original form, either. It gets merged. Addresses from a dozen separate incidents are combined into “combo lists” that are more valuable than any component, because an address appearing in several breaches is demonstrably real and demonstrably active.
This route has grown sharply and is poorly understood outside security circles.
Credential-stealing malware — infostealers — infects a machine and vacuums up whatever it can reach: saved browser logins, session cookies, autofill data, address books. The output, called a stealer log, is bundled with thousands of others and traded.
| 56.3M | unique email addresses, alongside 124 million unique passwords, in a single corpus of accumulated stealer logs added to Have I Been Pwned in June 2026. |
The detail that matters most: the infected machine doesn’t have to be yours. If a colleague, a client or a relative had your address saved in their browser or address book and their laptop was infected, your address is in a stealer log — and no amount of care on your part would have prevented it.
Automated harvesters crawl the web looking for one thing: text matching the shape of an email address. They follow links from page to page, and the more sophisticated ones use search queries to find pages likely to contain addresses before crawling them, which is considerably more efficient than wandering.
Anywhere your address appears in public is fair game — a contact page, a forum post from 2014, a conference attendee list, a PDF someone uploaded, a code repository, a committee minute. Advanced scrapers also pull surrounding context, so a harvested address can arrive on the list with a name and an organisation attached, which makes it worth more.
Once collected, that data goes to spam campaigns, phishing operations, or straight onto a market to be sold.
You can do everything right and still leak, because your address doesn’t only live in your own accounts.
It sits in the contact lists of everyone who has ever emailed you. When one of those accounts is breached, or one of those phones runs an app that asks to “find your friends” and uploads the whole address book, your address goes with it — attached to your real name, and often to a relationship graph showing who you know.
This is the channel people most often overlook, and it’s the reason a brand-new address can start receiving spam without you having used it anywhere questionable.
Not every leak is a failure. Some are the business model.
Privacy policies routinely reserve the right to share data with “partners,” “affiliates” or “selected third parties.” Co-registration forms sign you up to several lists from one tick box. List rental — where a company sends a message on a third party’s behalf to its own subscribers — is a mature industry. None of this requires a breach, and in most cases you agreed to it, in the sense that the sentence appeared in a document you didn’t read.
This is worth separating from criminal spam, because the remedy is different: for legitimate senders, unsubscribing genuinely works.
Data brokers exist to merge fragments into profiles. An address from a breach, a purchase record, a loyalty scheme, a public register and a survey response become one row describing a person, which is then licensed onward.
Your email address is unusually valuable to this industry because it’s stable and unique — a better joining key than a name, which repeats, or an address, which changes. It’s also why the same address reused across services quietly does more work for the profile-builders than any other single data point you supply.
The least sophisticated route still functions. Spammers generate plausible local parts — first names, common surnames, info, contact, admin, hello — and fire them at a domain to see which are accepted.
Anyone with a memorable address at a small or personal domain gets some traffic this way without ever having disclosed it. It’s brute force, it’s cheap, and at scale a low hit rate is perfectly acceptable.
The last one explains a pattern people notice and misread: spam gets worse after they engage with it.
A live, attended address is worth far more than an unverified one, so spam operators work to distinguish the two. Invisible tracking pixels report that a message was opened. Unsubscribe links in criminal mail frequently exist to confirm a human is reading, not to remove you. Both signals promote your address from “possible” to “confirmed” — and confirmed addresses get sold at a premium, to more senders.
THE UNSUBSCRIBE RULE This is not an argument against unsubscribing. It’s an argument for telling two cases apart. A sender you recognise — a shop, a service you signed up to — is bound by rules requiring a working opt-out, and unsubscribing is the right move. Mail from a sender you’ve never heard of should be marked as spam and left alone: don’t click, don’t reply, don’t load remote images. |
| ROUTE | PREVENTABLE? | WHAT GENUINELY HELPS |
|---|---|---|
Company breach | No | A distinct address per service, so one breach exposes one relationship |
Stealer malware | No | Nothing at your end if the infected machine is someone else’s |
Scraping | Partly | Don’t post your address publicly; use a contact form or a throwaway |
Others’ address books | No | Compartmentalisation only — you can’t audit other people’s phones |
Legitimate sharing | Partly | Decline optional marketing consent; use an alias you can switch off |
Data brokers | Partly | Break the joining key — stop reusing one address everywhere |
Guessing | Partly | Less predictable local parts on personal domains |
Confirming you’re live | Yes | Block remote images by default; never interact with unknown senders |
Only one row is fully within your control. That’s the real finding, and it points at the answer.
Spam has a ratchet quality that people find genuinely puzzling until they see the mechanism.
An address, once leaked, cannot be un-leaked. The list has already been copied. It will be merged with other lists, resold, re-traded, and re-merged, and there is no authority you can appeal to and no copy you could locate to delete. Every subsequent leak adds your address to more files without ever removing it from the earlier ones.
So the arithmetic only runs one way: the number of lists containing a long-held address rises over time and never falls. This is why the honest advice is not “clean up your inbox” but “stop feeding the ratchet.”
Given that most routes are outside your control, the only durable strategy is to make each leak cheap.
If one address goes to every service you use, a single breach anywhere exposes the address that reaches all of them — and joins your record across every list it already appears on. If a different address goes to each service, that same breach exposes exactly one relationship, tells the buyer nothing about the rest of your life, and can be switched off.
THE PRACTICAL ARRANGEMENT Your real address for banking, government, employment and medical accounts. An alias per service for accounts you intend to keep, so any one of them can be cut off individually. A disposable inbox for one-time codes, downloads and sign-ups you’ll never revisit. The effort is a few seconds per sign-up; the payoff is that no single leak can contaminate everything. |
It’s also worth knowing that this is a slow fix rather than a switch. Existing lists carry your current address permanently. What changes is the rate at which new lists acquire it — and over a couple of years, that’s the difference between an inbox that gets steadily worse and one that stabilises.
How did spammers get my email address?
Almost always through one of a small number of routes: a breach at a company you signed up with, credential-stealing malware on someone’s computer, automated scraping of pages where your address appears publicly, another person’s compromised or uploaded contact list, deliberate sharing and sale, aggregation by data brokers, or plain guessing at common addresses on a domain.
Does clicking unsubscribe make spam worse?
It depends who sent it. For a legitimate business, unsubscribing works and is correct. For an actual spammer, the link often exists to confirm a human read the message, which makes your address more valuable. Unsubscribe from senders you recognise; mark the rest as spam without interacting.
Can I stop my email address from leaking?
Not entirely — several routes are outside your control. What you can control is how much damage each leak does. If a different address goes to every service, one leak exposes one relationship instead of your whole identity.
What are stealer logs?
The harvest of credential-stealing malware: files scraped from infected computers containing saved logins, cookies and addresses, then bundled and traded. One corpus added to Have I Been Pwned in June 2026 held 56.3 million unique email addresses and 124 million unique passwords. The infected machine need not be yours — only someone’s who had your address.
Why does spam never stop once it starts?
Because a leaked address can’t be recalled. Once a list exists it’s copied, merged, resold and re-traded indefinitely, and no mechanism exists to withdraw an entry from copies you can’t see. That’s why the durable fix is compartmentalisation rather than cleanup.
The uncomfortable finding in that table is that six of the eight routes don’t depend on anything you did. You cannot prevent a company from being breached, a stranger’s laptop from being infected, or an app on someone else’s phone from uploading a contact list with your name on it.
What you can decide is how much a single address is worth to whoever ends up holding it. One address used everywhere is a master key to your entire online life, and every leak hands over another copy. A different address per context is a set of keys that each open one door — and any of them can be thrown away the moment it stops being useful.