DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

Why You Are Suddenly Getting So Much Spam Email

Last Tuesday your inbox was quiet. This morning it is forty junk emails deep and you changed nothing. That is the lens I read this through: I run AliasFleet, an email-alias service built so one site's spill stays on one address. A spike like that is not bad luck and not the background hum getting louder. Something moved your address, and your job is to find out what.


A sudden flood of newsletters can be a smokescreen. Attackers run your address through thousands of signup forms at once, a trick called subscription bombing, and the flood hides one email they do not want you to see: an order confirmation on a stolen card, a password reset, a sign-in alert. Search your whole inbox, Spam and Trash included, for order, receipt, password, and sign-in before you delete anything. Leave Me Alone's guide walks through the exact search terms.

Some context first, because the scale makes the point. Around 392.5 billion emails move every day in 2026, and more than 160 billion of them are spam, roughly 45% of all traffic. Kaspersky's 2025 telemetry put the figure at 44.99%. Almost all of it never reaches you: Gmail alone blocks nearly 15 billion unwanted emails a day, and services like Spamhaus sit between most of the internet's mail and your inbox.

So when spam starts arriving in volume, the background did not get louder. A new supply line opened. Somewhere, your address went somewhere it had not been before. There are three usual suspects.

A breach you never heard about

This is the first place to look, because it is the easiest to check and the most common cause of a sudden jump. Breaches surface in batches: one customer database gets traded, several spam operators buy it, and within weeks each runs their own campaigns. One breach turns into months of rising junk from different directions.

Here is the uncomfortable part. You probably were not told. Most people learn about breaches involving their own data months late, or never. The company emails the address on file and it lands in spam, or the notice goes out in corporate language nobody finishes reading. Sometimes the breach is just disclosed quietly, and the stolen dump does the talking instead.

The check takes two minutes. Have I Been Pwned holds 1,039 breached websites and 17,837,635,527 compromised addresses as of today. Type in your address and it lists every known breach that contains it. While you are there, turn on its breach notifications, so next time you hear about it from Troy Hunt's database instead of from the spammer.

How do I check whether a breach is behind my spam spike?

Enter your address at Have I Been Pwned and note the dates. A breach dated within the last few months is your leading suspect. Enable the Notify Me alerts so the next leak reaches you directly. One honest limit: a clean result only rules out known breaches, because quiet sales and brand-new dumps take time to surface.

Someone sold or shared your address

If Have I Been Pwned comes back clean, the next suspect is the data broker market. Brokers buy, collect, and assemble profiles from places you would never connect to your inbox: store loyalty programmes, warranty cards, magazine subscriptions, sweepstakes entries, public records. Then they sell those profiles to marketers, and marketers sell to more marketers.

The FTC's study of the industry found brokers operating, in its words, with a fundamental lack of transparency. One broker in the study held 1.4 billion consumer transactions and 700 billion data elements; another adds 3 billion new data points every month. Seven of the nine brokers studied had shared data with another broker in the study. Your address can move through three or four companies before the first spam arrives, and none of them ever had your consent in any form you would recognise.

Broker spam has a signature. It is weirdly well-targeted marketing: the adverts know your rough income bracket, your neighbourhood, the fact you own a dog. It arrives from companies you have never heard of, selling things adjacent to your actual life. That precision is the broker's product working as designed.

Can I prove a broker sold my address?

Probably not. There is no public ledger of broker sales and no company in the chain discloses its customer lists, so anyone claiming proof is selling something. What you can do is infer: well-segmented marketing from strangers, no breach on record, content that mirrors your offline purchases. Inference is enough to act on. It is not proof.

A signup you forgot about

The third suspect is the boring one, which is why people miss it. A free trial from March that you cancelled and forgot. A newsletter you read twice in 2023, now arriving daily. A store account created for a single order. Companies sell to other companies, mailing lists merge when companies get bought, and a quiet subscription becomes a loud one without asking you first.

Graymail is the polite name for it: mail you technically agreed to, once, that turned into a daily drip. The pattern is distinctive. It starts as welcome emails, then promotions, then "we miss you" win-backs, then partner offers you never signed up for. It does not arrive all at once, which is why it feels sudden: you notice it on the day it crosses your annoyance threshold, not the day it began.

Map your own history. Search your inbox for "welcome" and "confirm your subscription" and you will get a rough census of every mailing list you ever joined. The ones you do not recognise are the ones to deal with first.

Should I click unsubscribe in a spam email?

It depends on who sent it. Unsubscribe links from a real company you signed up with are fine, and large senders are now required to honour them within two days. In obvious scam mail, do not engage: no reply, no link, no unsubscribe. Use your mail app's mark-as-spam button instead. It trains your provider's filter and tells the sender nothing. (Clean Email's breakdown makes the same distinction.)

Read the symptoms like a diagnosis

What you are seeing Most likely cause Check first
Junk arrives in a flood, all at once Subscription bomb (or a breach dump being worked) Search for the hidden email: order, receipt, password, sign-in
Spam from companies you never heard of, well-targeted Data broker sale Search your address for public listings; reduce broker exposure
A known site's promotions got aggressive Forgotten signup or a merged list Search "welcome" in your inbox; unsubscribe or block
Classic scams: fake deliveries, crypto, "account closed" A breached address circulating Have I Been Pwned and its Notify Me alerts
Your address shows up on breach after breach It has been everywhere for years See the next section

One thing I will say plainly: I do not know which of the three is most common, and neither does anyone else. Nobody can see inside your inbox, so anyone quoting a percentage for your spike is guessing. The table above is how to think, not a statistic.

Make the next spike name its source

Here is the part the diagnosis is missing. You found the likely cause, but you cannot name the exact company. Your one address has been in hundreds of databases for years. No tool can retroactively trace a broker sale, and even a breach listing only names the dump, not who sold it on.

Per-site aliases fix the attribution, not the past. Give every website its own forwarding address and the next spike carries its source in the To field. Junk arrives addressed to storename@, and only one store ever had that address. The diagnosis takes five seconds. Our leak-tracing guide walks through the mechanism.

The alias does more than diagnose: pausing it silences that sender completely, without touching anything else in your life. No unsubscribe maze, no filter rules, no waiting on a broker to honour a removal request. The free tier covers 10 active aliases, enough for the split most people need: banking, shopping, social, news. Our guide to using aliases tells you where to point them first, and the docs explain the mechanics behind the forwarding itself.

Will aliases stop the spam I am already getting?

No. The addresses already in dumps and broker lists keep getting mail, and no product reaches back in time to scrub them. What aliases do is stop the next diagnosis problem: every new signup gets a traceable address, every future spike names its source, and every noisy sender gets a one-click kill switch.

For the spam you already have, mark it, block the sender, tighten your filter. For everything from today on, give each site its own address and you never play detective again.

If you want the full playbook for when your address turns up in a breach, our breach-response guide covers the passwords, the phishing, and the lockdown steps. And if you have never used an alias before, this definition is the starting point. Your inbox went from quiet to forty deep for a reason. Now you know how to find it, and how to make the next one introduce itself.

Top comments (0)