You can't un-breach an address, so the goal shifts from prevention to containment. Change the password for the breached service and anywhere you reused it, turn on two-factor authentication, keep the spam filter working, and expect unwanted mail at that address indefinitely. Then make the next breach cheaper: give each service its own address, so a future leak exposes something nobody else holds and can be switched off on its own.
First, separate the two problems
A breach creates two distinct risks and they need different responses.
Account risk is the serious one and it's time-sensitive. If credentials were exposed and you reused that password anywhere, those other accounts are at risk right now. This has nothing to do with spam and everything to do with getting to the passwords before someone else does.
Spam risk is the annoying one and it's permanent. Your address is now in a dataset that will be traded indefinitely. There is no action that removes it.
Deal with account risk first. It's the one where speed matters.
The immediate steps
- Change the password at the breached service.
- Change it anywhere you reused it. This is the step that matters most and the one most often skipped. Credential-stuffing — trying a leaked pair against hundreds of other sites — is the standard follow-up to any breach.
- Turn on two-factor authentication on anything financial, anything with payment details stored, and your email account itself, which is the reset route for everything else.
- Check what else is exposed. Run your address through a breach service to see whether this is the only one.
- Watch for phishing that references the breach. A breach with your name and purchase history attached makes for convincing targeted mail. Treat anything urgent-sounding about the breached company with suspicion, and reach the company through a URL you typed yourself.
Then, the spam
Realistic expectations first: it will increase, it may take weeks or months to start, and it will not stop entirely. Leaked lists get resold repeatedly, so mail can arrive from operators who have no idea where the data originated.
What genuinely helps:
- Mark everything as spam rather than deleting it. That trains your provider's classifier, which is the main lever you have on volume.
- Unsubscribe from legitimate senders only. For a company operating lawfully this works and is legally required. For an operator using a breach dump, clicking anything confirms the address is live and read — which raises its resale value. How to tell them apart.
- Block domains, not just addresses. Bulk senders rotate the local part constantly; blocking the domain is more durable.
- Report it. The FTC takes reports at ReportFraud.ftc.gov.
Should you abandon the address?
Migrating an address means updating every account that uses it, each with its own settings page and confirmation email, and any account whose reset goes to the old address becomes a support ticket. It's a serious undertaking.
It's also structurally pointless on its own. A fresh address handed to the same several hundred organisations ends up in exactly the same state, a few years later.
If the address is genuinely unusable and you're going to migrate anyway, migrate to a setup where the new address never gets handed out directly — each service gets its own instead. Then it's a one-off, not something you repeat every five years.
Making the next one cheaper
This breach cost you a password rotation and permanent spam at one address. That's the price when every company holds the same address.
With a different address per service, the same breach costs you one address. The leaked list contains something no other company holds, so it can't be matched against your other accounts. The spam that follows arrives at an address that identifies its own source. And you switch it off, which stops the mail without needing the breached company, the buyers of the list, or anyone else to cooperate.
It doesn't prevent breaches — nothing you do prevents someone else's security failure. It changes what a breach costs you, which is the part within your control.
More: a unique email address for every website · why am I getting so much spam · the full guide