Spam emails are unsolicited messages sent in bulk to many recipients at once, usually to sell something, collect personal information, or spread malware

A spam email arrives in your inbox without your permission. The sender obtained your address from a list they bought, harvested from a website, or guessed based on common naming patterns. The message is identical or nearly identical to thousands of others sent that same day. The sender does not expect most recipients to respond — they profit if even a tiny fraction do.

Spam differs from a legitimate marketing email you signed up for. When you buy from an online store and check a box to receive promotions, that is opt-in marketing. When a stranger emails you about a product you never heard of, that is spam. The difference matters because legitimate senders must include an unsubscribe link and honor removal requests within a reasonable time. Spammers ignore unsubscribe requests or do not include them at all.

Key Takeaways

  • Spam emails are bulk messages sent without your permission, usually trying to sell something or trick you into revealing personal information.
  • Spammers profit from extremely low response rates — they send millions of emails knowing that even 0.1% engagement makes money.
  • Phishing emails look like they come from banks, PayPal, or other trusted companies but are actually designed to steal your login credentials or financial data.
  • Replying to spam, clicking unsubscribe links, or opening attachments can confirm your email address is active and lead to more spam.
  • Email filters catch most spam automatically, but some still reaches your inbox because spammers constantly change tactics to evade detection.

Why spammers send millions of emails to make small amounts of money

A spammer's math is straightforward: send 10 million emails at nearly zero cost, and even a 0.01% response rate generates hundreds of responses. If 0.1% of recipients click a link to buy a product or fall for a scam, the sender makes money. The sender does not care that 99.99% of recipients delete the message unread.

The cost to send bulk email is almost nothing. Spammers use botnets — networks of hacked computers — to send messages, or they rent access to email servers in countries with weak enforcement. They harvest email addresses from data breaches, public websites, and by guessing common formats like firstname.lastname@company.com. A list of millions of addresses costs between $10 and $100 on the dark web.

The payoff comes from several sources. Some spam advertises weight loss pills, fake degrees, or counterfeit goods. Some tries to trick you into sending money or gift cards. Others steal credentials or install malware that the spammer sells access to. Because the barrier to entry is so low, even a tiny profit margin attracts thousands of spammers.

Phishing emails that impersonate banks and trusted companies

Phishing is a subset of spam designed to steal your login credentials, credit card numbers, or other sensitive data. A phishing email looks like it comes from your bank, PayPal, Amazon, or Apple, but the sender is actually a criminal. The message claims your account has been compromised, your payment method failed, or you need to confirm your identity. It includes a link that takes you to a fake website that looks identical to the real one.

When you enter your username and password on the fake site, the attacker captures it. They can then log into your real account, change your password, and lock you out. If you entered a credit card number, they have that too. Some phishing emails include attachments that install malware when opened — software that records everything you type or gives the attacker remote access to your computer.

Phishing emails often have small clues that reveal them as fake. The sender's email address might be slightly wrong — like paypa1.com instead of paypal.com. The message might have spelling errors or awkward phrasing. Links might point to a different website than the text says. But sophisticated phishing emails can fool even careful readers, so the safest approach is to never click links in unsolicited emails. Instead, go directly to the company's website by typing the address yourself or calling the number on your statement.

Why replying or clicking unsubscribe can make spam worse

When you reply to a spam email or click an unsubscribe link, you confirm that your email address is active and monitored by a real person. Spammers sell this information to other spammers or use it to target you with more messages. Your address becomes more valuable because it has been verified.

Legitimate companies honor unsubscribe requests because they are required to by law. Spammers ignore them. Some spam includes a fake unsubscribe link that does nothing except confirm your address is good. Others include a link that installs malware when clicked. The safest approach is to delete spam without engaging with it at all — do not reply, do not click unsubscribe, do not open attachments.

How email filters catch spam before it reaches your inbox

Email providers like Gmail, Outlook, and Yahoo use filters that analyze incoming messages and sort them into folders. These filters look for patterns that spammers use: bulk sending, suspicious links, requests for personal information, and known spam signatures. Messages that match these patterns go to a spam or junk folder instead of your inbox.

Filters also check the sender's reputation. If an email address or domain has been reported by many users as spam, the filter learns to treat future messages from that sender as suspicious. Some filters use machine learning — they analyze millions of emails to recognize new spam tactics that humans have not seen before.

No filter is perfect. Some spam still reaches your inbox because spammers constantly change their tactics. They use new domains, slightly different wording, and tricks like inserting random characters or spaces to evade detection. Some legitimate emails get caught by filters by mistake — this is called a false positive. Most email providers let you mark messages as spam or not spam to train the filter over time.

Common types of spam and what they are trying to do

Promotional spam advertises products or services: weight loss supplements, casino sites, cheap medications, counterfeit designer goods. The sender knows most recipients will ignore the message, but enough people buy to make it profitable.

Advance-fee scams ask you to send money upfront to receive a larger payment later. A common version claims you have inherited money from a distant relative or won a lottery you never entered. Another says you need to pay a fee to unlock a bank account or claim a prize. The money you send goes to the scammer and you receive nothing.

Romance scams build a fake relationship with you over weeks or months, then ask for money for an emergency or to travel to meet you. The scammer uses photos stolen from social media and a fabricated story. Once you send money, the scammer disappears.

Tech support scams claim your computer is infected with malware and ask you to call a number or read software to fix it. The "tech support" is actually a scammer who will charge you hundreds of dollars for fake repairs or use the software to steal your information.

What to do when spam reaches your inbox

Delete the message without opening attachments or clicking links. Most email providers have a spam or junk button — use it to move the message out of your inbox and train the filter. Do not reply, do not click unsubscribe, and do not engage with the sender in any way.

If a spam email looks like it comes from a company you use — your bank, your email provider, a store where you shop — do not click any links in the email. Instead, go directly to the company's website by typing the address yourself or calling the number on your statement or card. Ask them whether they sent the message. Legitimate companies want to know about phishing emails that impersonate them.

If you accidentally clicked a link or opened an attachment, change your password for that account when ready. If you entered financial information, contact your bank or credit card company. If you think your computer is infected, run a scan with your antivirus software or take it to a technician.

Frequently Asked Questions

Is it safe to open a spam email if I do not click any links?

Opening and reading a spam email is usually safe. The danger comes from clicking links, opening attachments, or replying. Some emails can execute code just by being opened, but this is rare and most email providers block it. Deleting without opening is the safest approach, but reading a spam message alone will not harm your computer.

Why do spammers use my name in the email if they do not know me?

Spammers buy lists that include names along with email addresses. These lists come from data breaches, public records, or websites where you entered your information. Seeing your name makes the email feel personal and more trustworthy, which increases the chance you will respond. It does not mean the spammer knows anything about you beyond what is on the list.

Can I get in trouble for reporting spam to my email provider?

No. Reporting spam helps your email provider improve its filters and protects other users. Email providers encourage users to mark spam and phishing emails. There is no penalty for reporting, and the sender will not be notified that you reported them.

What if the spam email is from someone I know?

Your contact's email account may have been hacked. Do not click links or open attachments. Instead, contact the person through another method — a phone call or text message — and ask whether they sent the email. If they did not, tell them their account has been compromised so they can change their password and notify their contacts.

Do I need to buy antivirus software to stay safe from spam?

Most computers come with built-in antivirus protection — Windows Defender on Windows, and similar tools on Mac and Linux. These are sufficient for most users. Paid antivirus software offers additional features, but the main defense against spam is caution: do not click unknown links, do not open unexpected attachments, and do not reply to unsolicited emails.