Guide Email

How to cut down the spam reaching your inbox

The filtering settings and DNS records that between them reduce most of the spam a mailbox receives.

Updated 7 min read Beginner

Spam reaching your inbox and your own mail landing in someone else's spam folder are two different problems with two different fixes. This guide covers the first — cutting down what arrives in your own mailbox. If it is your outgoing mail that is being filtered, see why your emails go to spam instead.

Turn on and tune the spam filter

Most hosting mailboxes include a spam filter that can be turned on from the email section of your control panel. If it is already on and still letting too much through, check whether its sensitivity can be adjusted — a stricter setting catches more spam but also raises the chance of catching a genuine message by mistake, so this is a balance rather than a setting to max out by default.

Check the spam folder occasionally, not obsessively

No filter is perfect. A quick look through the spam folder every week or two catches anything genuine that was misfiled, without requiring you to check it every day.

Block persistent senders

If the same address or domain keeps sending unwanted mail, add it to your mailbox's block or deny list, usually found in the same control panel section as the spam filter, or within webmail's own settings. This rejects future mail from that specific sender outright rather than relying on the general filter to catch it each time.

Use a catch-all address carefully, or not at all

A catch-all address accepts mail sent to any address at your domain, including ones you never created, which is convenient for catching typos but also means it receives every piece of spam sent to a guessed or randomly generated address at your domain. If you have one set up and are getting a disproportionate amount of spam, turning it off is often the single biggest reduction available. See creating a catch-all email address for the trade-offs either way.

Reduce how much your address is exposed

  • Avoid posting your email address in plain text on public web pages, since automated tools scan the web specifically looking for addresses to add to spam lists.
  • Use a separate address for things like online forms and sign-ups that you do not mind being sold on to other lists, keeping your main address more private.
  • Be cautious about where you enter your address when subscribing to things, since not every list is run responsibly.

Stop your own domain being used to send spam to other people

This does not reduce what lands in your inbox directly, but it closes off one route that leads back to you: if your domain lacks SPF, DKIM and DMARC records, it is easier for someone else to send spam that impersonates your address, which can in turn get replies, bounces and complaints landing back in your own mailbox. See SPF, DKIM and DMARC explained and what email spoofing is for how this works.

Never reply to spam, and be cautious about "unsubscribe" links

Replying to spam, or clicking an unsubscribe link on a message you were never actually subscribed to, usually confirms to the sender that your address is active and being read — which tends to increase the volume you receive rather than reduce it. Genuine unsubscribe links from senders you did knowingly sign up with are a different matter and generally safe to use.

If spam volume suddenly spikes

A sudden, sharp increase in spam to one specific address is sometimes a sign that address has recently appeared in a data breach at some other website you used it to sign up with, rather than anything wrong with your mailbox or hosting. There is no way to reverse this once it has happened, but tightening the spam filter and adding persistent senders to a block list, as above, is the practical response.

What this will not fix

No combination of filtering and blocking eliminates spam entirely — it is an ongoing arms race between senders and filters, and a determined sender using a fresh address each time can get through for a while before being caught. The aim here is reducing volume to a manageable level, not reaching zero.

If a specific sender is genuinely abusive rather than just unwanted marketing mail, report it through the appropriate channel rather than only blocking it locally, since that also helps get the sending source dealt with more broadly.

Filtering by rule rather than just by sender

Beyond a simple block list, most webmail and mail app interfaces support custom rules based on subject line, sender domain, or content, letting you filter out a recurring pattern of spam that a general filter has not learned to catch yet. This is particularly useful for spam sent from constantly changing addresses but with a recognisable subject pattern, where blocking one address does nothing to stop the next one.

Reviewing what your filter has already caught

Periodically checking the spam folder is not only about rescuing misfiled genuine mail — it is also a useful way to notice patterns worth acting on directly, such as a specific sender appearing repeatedly that is worth adding to a permanent block list rather than letting the filter catch it fresh each time.

Shared mailboxes need this reviewed by whoever manages them

If a mailbox is shared across a team, spam filter settings and block lists apply to the whole mailbox rather than per person. Agree who is responsible for reviewing and adjusting these settings, rather than leaving it to whoever happens to notice a problem first.

Combined, sensible filtering, a considered approach to where you share your address, and keeping your own domain properly authenticated cover most of what is realistically achievable against a problem that, industry-wide, has never been fully solved for anyone.

Related reading