How to Stop Spam Before It Starts
Search for spam advice and you'll mostly find the same list: unsubscribe links, filters, a "report spam" button. All of that helps after a message has already reached your inbox. Far less gets written about the earlier decision — whether your real address ends up on a list at all — which is actually the bigger lever, because a message you never receive doesn't need filtering.
Where mailing lists actually come from
Very little modern spam is random. Most of it traces back to an address you typed into a form at some point: an ebook download, a store checkout, a conference registration, a "get 10% off" popup. The company either emails you directly forever after, or — less innocently — sells or shares the list with partners. Multiply that by every form you've filled out in the last five years, and the pattern becomes obvious: your inbox isn't randomly targeted, it's the sum of every place you've handed your address over.
The core idea: match the address to the commitment
Not every form deserves your real email. A useful habit is to sort what you're signing up for into three tiers, and use a different kind of address for each:
- Genuine, ongoing relationships — your bank, your employer, people you correspond with. These go to your real, primary inbox, always.
- Services you'll use repeatedly but want to compartmentalize — online stores, subscriptions, tools you rely on. An alias per service (see our guide on temp email vs. aliases) works well here: mail still reaches you, but you can identify and cut off any single source if it starts misbehaving.
- Everything else — one-time downloads, forums you're only half-committed to, trials you're evaluating, any form that's clearly just a gate in front of content. This is where a temporary address earns its keep: it satisfies the form, and the resulting mail never has a chance to reach anywhere you actually check.
Reading a signup form before you fill it in
A few seconds of skimming tells you a lot about which tier a form belongs in. Watch for pre-checked boxes agreeing to marketing email, vague language like "our partners," and forms that ask for an email before showing you anything of substance. None of these are dealbreakers, but they're a signal that the address you provide is likely to end up doing more than just confirming a signup.
A quick checklist worth running through before you type your real address into anything:
- Is there a marketing-consent checkbox, and is it pre-checked?
- Does the privacy policy (if you skim it) mention sharing data with "partners" or "affiliates"?
- Is the form asking for an email before showing you any actual content, or after?
- Do you expect to want anything from this company again in the next month?
If two or more of those point the wrong way, that's a reasonable signal to reach for a disposable address instead of your real one.
Why your address is worth something to begin with
It helps to understand why this happens at all. A verified, actively-checked email address is a genuine asset in online advertising — it's a direct line to a real person that doesn't depend on an algorithm or a platform's goodwill the way social media reach does. Data brokers and marketing platforms buy and sell lists of these addresses, often bundled with whatever behavioral data was collected alongside the signup (what you bought, what page you were on, what device you used). None of this requires anything sinister on the company's part; it's simply the default business model for a huge share of "free" online services, and it's exactly why a disposable address — one that was never going to be actively checked past its one-time purpose — is worth so little to that same economy.
Why "unsubscribe" doesn't always work
Legitimate senders are generally required, under laws like CAN-SPAM in the US or GDPR-derived rules in the EU, to honor an unsubscribe request. Plenty do it properly. But a meaningful share of marketing email comes from senders operating in a grayer zone — list brokers, lead-generation outfits, or companies who've simply decided the fine for ignoring unsubscribe requests is cheaper than losing a marketing contact. For those senders, clicking "unsubscribe" can do nothing at best, and at worst confirms to a scraper-run list that your address is actively read by a real person, making it more valuable to sell onward rather than less. This is exactly why prevention matters more than most people assume: it sidesteps a category of sender that filtering and unsubscribing were never going to reliably solve anyway.
The "legitimate interest" loophole
Many companies build marketing consent into the transaction itself rather than asking separately — buy one product, and you're automatically opted into a newsletter under the banner of "legitimate business interest," a real (if commonly stretched) provision in data protection law that lets companies email existing customers about related products without a separate opt-in. It's not illegal, but it means "I only gave them my email to complete an order" and "I agreed to receive marketing" have become functionally the same thing on a lot of checkout pages. Reading the checkout page for a pre-ticked marketing box, or the absence of any opt-out at all, tells you which category a given purchase falls into before you commit your real address to it.
Auditing what's already in your inbox
If your primary inbox is already noisy, a focused ten-minute pass helps more than it seems like it should: search for "unsubscribe" and skim what comes up. For each sender, ask whether you actually remember signing up, and whether you still care about hearing from them. Senders you don't remember are worth a real unsubscribe attempt (or a filter straight to trash if the link doesn't work); senders you do remember but no longer care about are worth actually clicking through. This won't fix a list-broker problem, but it clears out the honest majority of senders who do respect the request, which is usually most of the actual volume.
A different kind of spam: breach-driven
Not all unwanted email traces back to a signup you made. If your address was exposed in a data breach at any company you've ever used — and given how common breaches have become, this is more likely than not for anyone with an email address more than a few years old — that address can end up on lists you never opted into at all. Tiered addressing helps here too, just retroactively: an address exposed by a breach at one specific service is easy to identify and abandon if it was never reused anywhere else, versus a primary address exposed by a breach, which is far harder to walk back once it's out.
What this doesn't fix
This approach reduces new spam from services you interact with going forward — it does nothing for lists your address is already on from years of past signups. For that, filtering, unsubscribing, and occasionally changing your primary address are still the right tools. Think of tiered addresses as stopping the leak, not draining what's already in the tank.
A simple rule to keep
Before typing your real email into anything, ask: will I actually want mail from this in a month? If the honest answer is no, that's exactly the case a disposable address was built for.
Keep your inbox out of the next mailing list.
Create an address