Why Am I Getting So Much Spam All of a Sudden?

Sudden spam spikes have a small number of causes. Here's how to work out which one you're dealing with.


A sudden jump in spam almost always means your address recently moved onto a new list. The usual causes are a breach at a company you used, a company selling or sharing your address, your address being scraped from somewhere public, or your having signed up for something that shared it onward. Volume climbs because lists get resold: once one operator has your address and sees it accept mail, it spreads to others.

Why it arrives in a wave rather than a trickle

The pattern people describe is almost always the same — nothing for years, then thirty messages a day appearing within a fortnight. That shape is a clue, because it tells you something discrete happened rather than something gradual.

Lists are traded in bulk. When your address lands in one, it doesn't stay in one. It gets resold, merged into larger sets and used by multiple operators, each running their own campaigns. One event, many senders, all starting at roughly the same time.

There's a second accelerant: engagement. Some senders track opens and clicks. An address that shows signs of a live human reading the mail is worth more than a dead one, so it gets promoted into better lists and resold at a higher price. This is the honest reason not to click links in spam — not that clicking is dangerous in itself, but that it confirms you exist.

The six realistic causes

1. A company you used was breached

The most common single cause, and the one you had no control over. You may not hear about it for months. Checking your address against a breach-notification service is a reasonable first step.

2. A company shared or sold it

Entirely legal in many cases and more common than people assume. The FTC's own consumer guidance states it plainly: "When you give a company your email address, it might share or sell it to third parties." Source: FTC, How To Get Less Spam in Your Email. Checked: 2026-08-19.

Note this is not a breach and nothing went wrong from the company's perspective. It's a business model.

3. It was scraped from somewhere public

Any address published in plain text gets harvested — a forum post, a GitHub commit, a conference attendee list, a PDF, a WHOIS record, a "contact us" page. Automated crawlers do nothing else all day.

4. It was guessed

Common patterns at large providers get hit by dictionary attacks. If your address is a plain first-name-dot-surname at a major provider, you will receive spam that required no leak at all.

5. You signed up for something that shared it

Competitions, free downloads, discount codes and "partner offers" checkboxes are frequently list-building exercises. The prize is real; so is the onward sharing, usually disclosed somewhere in the terms.

6. A broker aggregated it

Data brokers combine records from many sources and sell the compiled result. Your address may arrive on a list having never been leaked by any single company in a way you'd recognise. See data brokers explained.

Can you tell which one it was?

Honestly: usually not, if you use one address for everything. The message gives you very little. Sender addresses are forged routinely, and the content is designed to reveal nothing about where the list came from.

Things that occasionally help:

  • Check breach databases. A recent breach at a company you used is strong circumstantial evidence.
  • Look at what the spam is about. Sudden insurance and funeral-plan mail suggests a list sold with demographic data attached. Crypto and gambling suggests a generic bulk list.
  • Check whether the greeting knows your name. Spam that has your correct full name came from a list with more than just an address on it — that's a leak from somewhere you gave real details.

All of this is inference. The only way to get a definite answer is to have given each company a different address in the first place — which is the subject of how did this company get my email address?

What to do now

  1. Don't click anything in the spam — including unsubscribe links on mail from senders you've never dealt with. For an operator that ignores the law, that link is a liveness check.
  2. Do unsubscribe from senders you recognise. Legitimate companies are legally required to honour it. In the US, CAN-SPAM requires the request to be honoured within 10 business days, and once you've opted out the sender may not sell or transfer your address. Source: FTC, CAN-SPAM Compliance Guide. Checked: 2026-08-19.
  3. Mark the rest as spam rather than deleting it. That trains your provider's filter.
  4. Report it. The FTC takes reports at ReportFraud.ftc.gov.
  5. Change your habit for new signups. Nothing above reduces the number of parties holding your address. Only this does.

Will it settle down on its own?

Partly, and slowly. Some campaigns end, some lists go stale, and consistently marking mail as spam improves your filtering. What doesn't happen is the address being removed from circulation. Once it's in the trade it stays there, which is why the durable fix is at the address level rather than the message level.

The full set of options is in how to stop spam emails.

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started — free

Keep reading