Spam is unsolicited bulk email. Phishing is a targeted attempt to steal credentials, money or data. "Junk" is just the folder your provider files suspected spam into. The first is a nuisance, the second is an attack, and the third is a label rather than a category. The distinction matters because the right response differs: unsubscribe or filter spam, never interact with phishing, and check the junk folder occasionally because it catches both plus the occasional real message.
The three terms
| Spam | Phishing | Junk | |
|---|---|---|---|
| What it is | Unsolicited bulk email | Deception aimed at stealing something | A folder label your filter applies |
| Intent | Sell you something | Steal credentials, money or data | n/a |
| Targeting | Bulk, indiscriminate | Often bulk, sometimes targeted at you specifically | n/a |
| Legal position | Regulated (CAN-SPAM, GDPR) | Criminal fraud | n/a |
| Right response | Unsubscribe if legitimate, else report | Don't interact. Report. Verify separately | Review occasionally in both directions |
| Worst case | Wasted attention | Account takeover, financial loss | You miss a real message |
Spam
Commercial mail you didn't ask for. In the US it's governed by CAN-SPAM, which is an opt-out regime: a company doesn't need your consent to email you, only to stop when asked, within 10 business days. That single design choice explains a lot about the modern inbox. Source: FTC. Checked: 2026-08-19.
Much of what people call spam is technically compliant marketing from companies that genuinely have a relationship with them โ which is why unsubscribing works more often than the folklore suggests. When it works
Phishing
A different thing wearing spam's clothes. The goal isn't a sale, it's getting you to hand over a password, a payment, or enough information to impersonate you.
Signals worth knowing:
- Urgency. Account suspended, payment failed, act within 24 hours. Manufactured time pressure is the core technique.
- A sender domain that doesn't match the brand. Check what's after the @, not the display name, which is trivially forged.
- A link whose destination differs from its text.
- Real details about you. After a breach, attackers have your name and purchase history โ so "convincing" is not evidence of legitimacy.
The rule: never act on a link in unexpected mail. Go to the company by a URL you typed yourself, or the number on your card. That single habit defeats nearly all of it.
Junk
Not a category of mail โ just where your provider files what it suspects. It contains spam, phishing, and periodically something legitimate that got misclassified, because filters fail in both directions. Why that's unavoidable
Check it occasionally. Not obsessively, but often enough that a misfiled invoice doesn't sit there for a month.
What to do with each
- Recognise the sender and it's marketing? Unsubscribe. Legally backed, and it also bars compliant companies from selling your address on.
- Never heard of them? Report as spam. Don't click anything, including the unsubscribe link โ for a non-compliant operator that's a liveness check.
- Looks like phishing? Don't interact at all. Report it to your provider and, in the US, at ReportFraud.ftc.gov. If it references a real account, check that account directly.
- Real mail in junk? Mark not-spam and add the sender to safe senders.
Where aliases fit
Per-service addresses don't stop phishing โ a convincing fake reaches any working address. What they do change is attribution: phishing arriving at an address you gave exactly one company tells you where the attacker got it, which is genuinely useful information after a breach.
More: the full guide ยท what follows a leak