Mailfornet

12 email myths almost everyone believes

Email is older than the web. It was designed in the 1970s and 80s for a few thousand researchers who trusted each other, and most of what we use today is still built on top of those first ideas. We've used it for so long that we think we know how it works, but much of what we believe comes from guesses, old advice and half-remembered warnings from the IT department.

Some of these myths are harmless. Others make people careless in exactly the wrong places, or scared of things that can't hurt them. Here are twelve of the most common, and what actually happens.

Myth 1: "If I delete an email, it's gone"

Deleting an email removes your copy, and only after a while. In Gmail, deleted messages sit in Trash for 30 days. Outlook keeps a "Recoverable Items" folder for a while after that. Company mail systems are often archived for years for legal reasons.

More importantly, the recipient has their own copy, which you can't touch. So does anyone they forwarded it to. And once a message has been sent, there's no mechanism in email to reach into someone else's mailbox and pull it back.

What to do instead: write every email as if it could be read aloud in a meeting a year from now. That includes the email you're sending while angry.

Myth 2: "I can unsend an email"

Gmail's "Undo send" feels like unsending, but it's a delay. Gmail simply holds the message for 5 to 30 seconds (you choose the length in settings) before it actually leaves. Once that window closes, the email is out and nothing can bring it back.

Outlook's "Recall this message" is different, and less reliable than most people think. It usually works only when the sender and recipient are on the same company mail server, and only if the recipient hasn't opened it yet. Sent to anyone outside your organisation, a recall attempt often just produces a second email saying you tried to recall the first one, which makes people even more curious about it.

Myth 3: "The sender's name tells me who sent it"

The name you see in your inbox, like "PayPal Support" or "Your Bank", is just text that the sender typed. Anyone can put any name there. Email was built without identity checks, and the display name is still completely unverified.

What matters is the actual address, the part after the @ sign, and even that can be faked in some situations. Mail providers now run checks called SPF, DKIM and DMARC that catch most forgeries (our guide to SPF, DKIM and DMARC explains them). But the name on its own is worth nothing. In How to check if an email is real, we show how to look past it.

Myth 4: "Just opening an email can infect my computer"

This was true in the early 2000s, when some email programs would run scripts inside messages automatically. Modern email apps don't. Gmail, Outlook, Apple Mail and the major phone apps display messages without running their code, so simply opening an email is not the danger it used to be.

The real risks are what you do next: opening an attachment, clicking a link, or typing a password into a page the email sent you to. Rare "zero-click" attacks do exist, but they're expensive and aimed at specific high-value targets like journalists and politicians, not at ordinary inboxes. Keeping your phone and email app updated is the protection there.

What opening an email can do is tell the sender you opened it, which brings us to the next myth.

Myth 5: "Nobody knows when I've read their email"

Most marketing emails, and many sales emails, contain a tracking pixel: a tiny invisible image with a unique address. When your email app loads the image, the sender's server records that you opened the message, when you opened it, and often roughly where you were and what device you used.

Protection varies. Gmail loads images through its own servers, which hides your location but still reveals that you opened the email. Apple Mail's Mail Privacy Protection downloads images in the background whether you open the message or not, which makes open tracking unreliable for Apple users. If you want to block it completely, most apps have a setting to stop loading remote images automatically.

Myth 6: "Email is private, like a sealed letter"

For most of email's history, it was more like a postcard: readable by anyone who handled it along the way. Today, most mail between big providers is encrypted in transit, meaning it can't be read as it travels between servers. That's a real improvement.

But it isn't sealed at either end. Your email provider can technically read what's in your mailbox, and so can the recipient's. Your company can read your work email. Anyone who gets your password can read all of it. True end-to-end encryption, where only the sender and recipient can read a message, exists (Proton Mail, or S/MIME and PGP), but ordinary email doesn't use it.

Rule of thumb: don't send anything by email that you'd be seriously harmed by someone else reading, such as passwords, full card numbers or ID scans.

Myth 7: "Clicking unsubscribe just confirms my address to spammers"

This one is half true, and the half that's false costs people a lot of peace and quiet.

For real companies, like the shop you bought from or the newsletter you signed up for, the unsubscribe link works and is safe. In many countries it's required by law, and since 2024 Gmail and Yahoo require large senders to offer one-click unsubscribe and honour it within two days. Marking these emails as spam instead is worse for everyone, because it hurts the sender's reputation without actually removing you from the list.

For obvious junk, like pills, lottery wins or strangers asking for help moving money, don't click anything. Those senders aren't running a mailing list you can leave. Just report it as spam.

A good middle ground: use the Unsubscribe button your email app shows next to the sender's name, which works without you ever visiting the sender's website.

Myth 8: "Everything in my spam folder is spam"

Spam filters are very good, but they make mistakes in both directions, and the ones they make are often important. Verification codes, invoices, job replies and first emails from new contacts all land there regularly, because they come from senders your mailbox hasn't seen before.

Glance at the spam folder every few days, and mark real messages as Not spam. That teaches the filter, and if a verification email isn't arriving, it's the first place to check.

Myth 9: "Bcc keeps people completely hidden"

Bcc hides recipients from each other, as long as everyone behaves. The weak point is Reply All. If someone you Bcc'd hits Reply All, their reply goes to the whole visible list, and everyone discovers they were secretly copied.

For sensitive situations, forwarding the email separately is safer than Bcc. And for sending the same message to many people who shouldn't see each other's addresses, a mailing list tool is better still.

Myth 10: "A bounce means the address doesn't exist"

A bounce is a message from a mail server saying it couldn't deliver your email, and there are many reasons besides a non-existent address: the mailbox is full, the receiving server thinks your message is spam, your attachment is too big, or the server is temporarily down.

Read the error code in the bounce. Codes starting with 4 (like 421 or 450) are temporary, and the server will usually retry on its own. Codes starting with 5 (like 550 or 552) are permanent for that attempt, and the text after the code usually explains why. We go deeper into this in How email works.

Myth 11: "Dots in a Gmail address make it a different address"

For personal Gmail accounts, dots are ignored. jane.doe@gmail.com, janedoe@gmail.com and j.a.n.e.d.o.e@gmail.com all deliver to the same inbox. You can't register a second account by moving a dot, and nobody else can register "your" address with dots in different places.

This also means you can use dots and the plus sign to create variations of your own address, which is handy for filtering and for spotting who leaked your address. Our Gmail dot and plus trick guide shows how. One caveat: this only applies to @gmail.com. Company addresses on Google Workspace treat dots as real characters.

Myth 12: "Temporary email is only for scammers"

Disposable email has an image problem it doesn't deserve. Most people who use it are doing something ordinary: downloading a PDF, joining the airport Wi-Fi, reading one forum thread, or testing an app they're not sure about. They just don't want five years of marketing email in return.

It's the email version of not giving your phone number to every shop cashier who asks. What it's not good for is anything you need to keep, like accounts you'll log back into or anything involving money. Our honest guide Is temporary email safe? covers where the line is.

Why these myths survive

Most email myths come from one of two places: advice that was true twenty years ago and never got updated, or features whose names promise more than they deliver ("unsend", "recall", "private"). The underlying system still runs on the same basic rules: messages are copied, not moved; names are not identities; and privacy depends on who's holding each copy.

Once you keep those three rules in mind, most email surprises stop being surprises.