How spammers get your email address
One of the most frustrating things about spam is the feeling that you did nothing to deserve it. You never gave your address to a Nigerian prince, a crypto platform or a pharmacy in a country you've never visited. So how did they get it?
The answer is that email addresses leak in many quiet ways, and a spammer only needs one of them. Here are the nine most common routes, roughly in order of how much spam they cause.
1. Data breaches
This is the biggest source by far. Every time a website's user database is stolen, the email addresses in it end up on lists that are sold, shared and eventually published. Over the years, breaches have been merged into giant compilation lists with billions of addresses.
You don't need to have used the breached site recently. An account you made in 2014 for a forum you've forgotten can still leak your address today. See how to check if your email was in a breach.
2. Companies selling or sharing your data
Some companies make money by selling or "sharing" customer lists with partners, often permitted by a line in the privacy policy that nobody reads. Contests, sweepstakes, free trials, quizzes and "enter your email to see your results" pages are the usual suspects. Once on these lists, an address passes through data brokers and marketers, and eventually reaches less scrupulous senders.
3. Scraping websites
Automated programs crawl the web around the clock, collecting anything that looks like name@domain.com. They read business websites, forums, comment sections, online CVs, public documents, social media profiles and code repositories. If your address is written in plain text anywhere public, it's been collected.
Tricks like writing "name [at] domain [dot] com" stop some of the simpler scrapers, but modern ones decode them easily. A contact form is more effective.
4. Guessing
Spammers don't always need to find your address; sometimes they simply guess it. A dictionary attack sends mail to common name combinations at popular domains: john.smith@, jsmith@, johnsmith1985@ and so on, and keeps the addresses that don't bounce.
For company domains, it's even easier. If one address is sara.malik@company.com, every other employee's address follows the same pattern. Shared addresses like info@, sales@ and admin@ get guessed on every domain that exists.
5. Other people's contact lists
Your address sits in the contact lists and old emails of everyone you've ever written to. If one of those people's computers or email accounts gets infected or hacked, malware can harvest every address it finds and send it to spammers, or use the hacked account to send spam directly to you. This is why spam sometimes appears to come from a friend.
6. Chain emails and big Cc lists
Every time someone forwards a joke, petition or chain letter with dozens of addresses visible in the To or Cc fields, all of those addresses travel with it. After a few forwards, the message contains a list of hundreds of addresses, and it only takes one recipient with an infected computer for the list to escape. (It's also why Bcc exists; see our email myths article for where Bcc falls short.)
7. Apps that ask for access to your contacts or inbox
Some apps ask to read your contacts or your email "to find your friends" or to "organise your inbox". Most do what they say. Some keep more than they need, and some sell the data. Every app with access to your contacts has a copy of everyone's addresses, including yours in other people's phones.
8. Domain and business registrations
Registering a website domain used to publish your email address in a public database called WHOIS, and it's still visible for some domain types and registrars. Business registers, trade directories and app store developer listings can also show contact addresses publicly, and scrapers read all of them.
9. You confirmed it yourself
Finally, some spam is a test. A sender with an unverified list sends a message and waits to see if anyone reacts. Replying, clicking a link, or loading the images (which can contain an invisible tracking pixel) tells them the address is real and actively read. Verified addresses are worth more, and get sold on.
How to protect your address
You can't get your address back from a list once it's out. But you can control what happens next, and make your future addresses much harder to spread.
- Keep your main address for people and important accounts only. Banks, work, family, government.
- Use aliases for everything else you want to keep. A Gmail alias like
you+shopname@gmail.comshows you exactly which company leaked or sold your address, and makes it easy to filter. - Use a temporary address for one-time sign-ups. Contests, downloads, Wi-Fi portals and trials get a disposable address that deletes itself. It can't be sold, scraped or leaked later, because it no longer exists.
- Don't publish your address in plain text. Use a contact form on your website.
- Use Bcc when emailing groups, and remove old addresses from messages before forwarding.
- Don't react to spam. No replies, no clicks. Just report it.
- Turn off automatic image loading in your email app if you want to avoid tracking pixels.
- Review app permissions for your contacts and email every few months.
For what to do about spam that's already arriving, see How to stop spam emails, and if the amount suddenly jumped, Why am I suddenly getting so much spam?