You Signed Up for One Thing and Now Everyone Emails You

The clearest example of the whole problem, and the easiest one to diagnose.


One signup produced mail from twenty senders because the form you filled in shared your address onward โ€” usually lawfully, and usually disclosed somewhere you didn't read. Competitions, gated downloads, wifi portals and "partner offers" boxes are the common culprits. You can unsubscribe from the ones you recognise, but you can't reach the parties they shared you with, which is why the durable answer is making the next signup traceable.

How one form becomes twenty senders

The sequence is almost always the same:

  1. You fill in a form โ€” a prize draw, a discount code, a free report, a wifi login.
  2. The terms include sharing with "partners" or "carefully selected third parties". Sometimes a pre-ticked box, sometimes just a line in the terms.
  3. Your address goes to a list that's rented or sold to several buyers at once.
  4. Each buyer runs their own campaigns, and some resell again.
  5. Two to eight weeks later, mail starts arriving from companies you've never heard of.

Nothing went wrong from anyone's perspective. That's the uncomfortable part โ€” this is the system working as designed, and the FTC says as much: giving a company your address means "it might share or sell it to third parties." Source: FTC. Checked: 2026-08-19.

Working out which signup did it

With one address for everything, you're inferring. Things that help:

  • Timing. Spam that starts two to eight weeks after a specific signup is decent circumstantial evidence.
  • Theme. A burst of insurance and funeral-plan mail suggests a list sold with demographic data; crypto and gambling suggests a generic bulk list.
  • What they know. If they have your correct full name, the list came from a form you completed rather than from scraping.
  • A typo you made once. The strongest evidence available, and pure luck when it happens.

All inference. The full diagnostic

What to do now

  1. Unsubscribe from the senders you recognise. Legally required to be honoured, and once you've opted out a compliant sender may not sell your address on either.
  2. Don't click anything from senders you don't recognise. That's a liveness check, not an opt-out.
  3. Report and mark as spam rather than deleting, so the filter learns.
  4. Accept that you can't reach the downstream buyers. They never got your opt-out and have no obligation arising from it.

Making the next one different

This scenario is the single clearest argument for per-signup addresses, because the causal chain is so short and so opaque.

Enter a competition using an address only that competition was given. When mail from four unrelated companies arrives at it, you know precisely which form did it โ€” no timing analysis, no guessing. Switch that one address off and all four stop reaching you at once, without unsubscribing from any of them.

You've also learned something durable about that organisation, which is worth knowing next time they run a promotion. How to run it

Reducing it at the form

  • Un-tick "share with partners" specifically. The sender's own marketing you can unsubscribe from later; onward sharing you largely can't.
  • Fill in required fields only. Optional ones turn a cheap bulk record into a segmented, resellable one.
  • Treat competitions and free downloads as list-building, because usually they are. Enter anyway if you want to โ€” just with a burnable address.

More: the signup routine ยท newsletters you never signed up for

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started โ€” free

Keep reading