Why Am I Suddenly Getting So Much Spam? How to Find the Leak
Spam does not arrive at random. A sudden flood usually traces to one of four causes, and one of them is an attack designed to bury a fraud alert in your inbox.
Spam volume does not drift upward at random. If your inbox was manageable a month ago and is now unusable, something specific happened to your address, and there are only four realistic candidates: a breach published it, a company sold it, a scraper harvested it, or someone is deliberately flooding you.
The last one matters more than its share of cases suggests, because a subscription bomb is not spam in the ordinary sense. It is a smokescreen, and the thing it hides is usually a fraudulent purchase confirmation in the same inbox.
Some baseline is unavoidable. Kaspersky put spam at 47.27% of all email sent worldwide in 2024, and Statista's tracking puts it around 45.6% of total traffic — roughly half of global mail, permanently. The useful question is not why spam exists but what changed for you. This guide works through the four causes, how to tell them apart, and what actually reduces the flow. Our complete guide to avoiding spam covers the long-term hygiene.
Key takeaways
- A sudden spam spike almost always has a specific cause: a breach that published your address, a list sale, a scrape, or a deliberate subscription bomb.
- If the flood is hundreds of newsletter confirmations at once, stop and check your bank and shopping accounts. That pattern is used to bury a fraud-confirmation email.
- Spam is roughly half of all global email traffic, so some baseline is unavoidable — the question is what changed, not why spam exists.
- Unsubscribe from real marketing, but never from obvious spam: on genuine spam it only confirms a live address. Mark it as spam instead, which trains the filter.
- The durable fix is upstream. Stop giving a permanent address to low-trust forms, and the next breach has nothing of yours to publish.
Cause 1: your address was in a breach
This is the most common explanation for a spike that starts abruptly and never subsides.
The scale involved is easy to underestimate. More than 1.7 billion individuals had personal data compromised in 2024, a 312% increase in victim notices over 2023, with 80% of breaches caused by cyberattacks. Breached address lists circulate, get merged with other dumps, and are resold for years. Your address does not need to have been valuable — it needs to have been present.
The signature is distinctive. Breach-driven spam arrives from many unrelated senders at once, in poor English or several languages, often addressing you by a name format that matches one specific old account. Phishing attempts referencing a service you genuinely used years ago are a strong signal, because the attacker knows the pairing of your address and that service.
Check which breaches include you. Have I Been Pwned indexes the public dumps and tracks over 17.5 billion compromised accounts across 998 breached websites. If your address appears, assume it is permanently in circulation — there is no way to withdraw it. Change any password reused across those services, and enable two-factor authentication wherever the account still matters.
Cause 2: someone sold or shared your address
The second pattern is quieter and more legal. A company you gave your address to shared it with "carefully selected partners", a phrase that appears in a great many privacy policies you agreed to.
The signature here is that the mail is competent. Real companies, correct spelling, working unsubscribe links, products vaguely adjacent to something you once bought. It is unwanted marketing rather than fraud, and it tends to arrive in waves as the list changes hands.
You can often identify the source if you tagged your addresses — mail arriving at a tag you gave to exactly one retailer names the leaker precisely. Without tagging, the timing is the clue: think about what you signed up to shortly before the wave started.
The remedy for this category is the unsubscribe link, and it has legal weight. Under CAN-SPAM, senders must honour an opt-out within 10 business days and cannot require you to provide anything beyond an email address to do it. Since February 2024, Google's sender guidelines require bulk senders to support one-click unsubscribe using List-Unsubscribe headers alongside a visible in-body link, which is why Gmail now shows an unsubscribe button next to many marketing messages. Use it — for legitimate marketing only. Our guide to unsubscribing properly covers the details.
Cause 3: your address was scraped or guessed
Addresses posted publicly get harvested. A contact page, a forum profile, a GitHub commit, a conference attendee list, a PDF, a WHOIS record — crawlers collect from all of them continuously, and an address only has to appear once.
Guessing works too. Common formats at a known domain are enumerated cheaply, which is why firstname.lastname patterns at company domains attract spam that never resulted from any signup.
The signature is generic mail addressed to no one in particular, arriving at an address you never used to register anything. Business addresses in a predictable format get this most.
There is not much remediation available here, because you cannot un-publish an address that has been crawled. What you can do is stop adding new exposure: avoid posting addresses in plain text publicly, and use a separate address for anything that will appear on a public page.
Cause 4: a subscription bomb — check your bank now
This one is different in kind, and it is the reason to read a sudden flood carefully rather than just deleting it.
The pattern is unmistakable: hundreds or thousands of newsletter confirmations, account-verification emails, and mailing-list welcomes arriving within minutes or hours. They are real messages from real organisations. Your address has been submitted to a large number of signup forms by a script.
The purpose is concealment. While your inbox is buried under confirmations, an attacker who has compromised a payment method or an account is counting on the genuine alert — an order confirmation, a shipping notice, a password-change notification — being lost in the noise or missed entirely.
If this is happening, treat it as an active incident rather than a spam problem. Check your bank and card statements immediately. Check recent orders on Amazon and any retailer holding your card. Check for password-change and new-device notifications on your main accounts. Search your inbox for terms like "order", "receipt", "confirmation", and "password" to surface the real message hiding among the noise, and secure the affected account before you start cleaning up.
Do not mass-delete the flood until you have searched it. The evidence you need is inside it.
What actually reduces the flow
Once you know the cause, the response is short.
Mark spam as spam rather than deleting it. The FTC's guidance is direct: mark it as spam or junk, which trains the filter and helps you avoid phishing links, and if mail continues more than 10 business days after you opted out, report it at ReportFraud.ftc.gov. Deleting teaches your provider nothing.
Never unsubscribe from obvious spam. On legitimate marketing the link is a legal obligation and works. On genuine spam it is a confirmation that a human read the message, which raises your value on the lists you are already on. The test is simple: do you recognise the sender, and did you ever have a relationship with them?
Enable two-factor authentication on the accounts tied to your main address, because breach-driven spam usually travels with credential-stuffing attempts against the same address.
Then fix the upstream problem, which is the only step that changes your baseline. Most addresses leak because they were handed to low-trust forms — a download gate, a one-off trial, a store that wanted an email for a receipt. Use a disposable inbox for those and the equation changes: when that site is breached or sells its list, the address it holds no longer exists, so there is nothing to deliver to you. Your permanent address stays with the people who need it. See our guide to signing up without giving your real email for the practical patterns.
A sudden spam spike is a symptom with a short list of causes. Breach exposure produces many unrelated senders and phishing that references old accounts. A list sale produces competent marketing with working unsubscribe links. Scraping produces generic mail at an address you never registered anywhere. And a flood of newsletter confirmations in minutes is not spam at all — it is cover for fraud, and it warrants checking your bank before anything else.
Spam is roughly half of global email and always will be, so the goal is not zero. The goal is to stop feeding the lists: mark spam rather than deleting it, unsubscribe only from senders you recognise, turn on two-factor authentication, and stop giving a permanent address to forms that have no reason to keep one.
Frequently asked questions
Sources
- Kaspersky Securelist, Spam and phishing in 2024 (opens in new tab) (2025)
- Statista, Global spam volume as percentage of total e-mail traffic (opens in new tab) (2024)
- HIPAA Journal (citing ITRC 2024 Annual Data Breach Report), More Than 1.7 Billion Individuals Had Personal Data Compromised in 2024 (opens in new tab) (2025)
- Have I Been Pwned, Have I Been Pwned — Pwned Websites Database (opens in new tab) (2025)
- Federal Trade Commission (Consumer Advice), How To Get Less Spam in Your Email | Consumer Advice (opens in new tab) (2024)
- Google Workspace Admin Help, Email sender guidelines - Google Workspace Admin Help (opens in new tab) (2024)
- Federal Trade Commission, CAN-SPAM Act: A Compliance Guide for Business | Federal Trade Commission (opens in new tab) (2024)
Recommended privacy tools
Independent privacy tools that complement a disposable inbox.
ProtonMail
Swiss end-to-end encrypted email. Zero-access encryption means even Proton cannot read your messages.
Learn MoreTutanota
German encrypted email, open-source and GDPR-native, with encrypted subject lines and an encrypted calendar.
Learn MoreMalwarebytes
Real-time protection against malware, ransomware, and malicious sites. Cleans infections other scanners miss.
Learn More