How to Stop Spam Emails (and Why Clicking "Unsubscribe" Can Make It Worse)
Most people deal with spam the same way: scroll to the bottom, find the small grey "Unsubscribe", click it.
For one category of email, that click makes things worse.
Sort the mail into three piles first
Get this right and everything else is easy.
1. Marketing you actually signed up for.You bought something, made an account, and now they email you weekly. This mail is subject to CAN-SPAM in the US and GDPR in the EU, which require a working opt-out that gets honored within a reasonable window.
→ Unsubscribe freely.
2. Mail from a sender you've never heard of.You have no memory of this company. Your address was almost certainly bought from a breach dump or scraped. For this pile, the "unsubscribe" link at the bottom does one thing reliably: it confirms a human reads this mailbox.
The result isn't less mail. Your address gets flagged as active, resold at a higher price, and the volume goes up.
→ Don't click. Mark as spam.
3. Phishing dressed up as your bank, a delivery service, or the IRS.→ Click nothing, including unsubscribe. Report and delete.
The test: can you remember signing up? Yes → unsubscribe. No → report as spam.
Gmail
Use the unsubscribe button at the top, not the one in the body.
The "Unsubscribe" Gmail shows next to the sender at the top of a message is not the same as the link at the bottom. The top one reads the List-Unsubscribe header and sends the opt-out request on your behalf — you never open the sender's link, so you don't confirm the click or load a tracking pixel.
The link in the message body goes straight to their server, where it can be logged.
"Report spam" beats "delete" by a lot. Deleting moves one message. Reporting trains the filter, so the next one never reaches you. That extra click compounds.
Bulk cleanup uses filters. Search from:annoying-domain.com, select all, then create a filter that deletes future mail from them. Far faster than one at a time.
Useful search: just search unsubscribe to list every marketing email you're receiving. Most people are shocked by the count.
iPhone / iCloud Mail
The "Unsubscribe" banner at the top of a message works the same way Gmail's does — standard header, safe to use.
Block a sender: open the message → tap the sender's name → Block this Contact. Future mail from that address goes to Junk.
If you have iCloud+, Hide My Email is one of the best tools here. Generate a random forwarding address when you sign up for something new; if it starts attracting spam, deactivate that one address instead of changing your real one.
⚠️ One catch: keep a record of which service got which hidden address. Deactivate it and that service can no longer reach you — including for password resets.
Outlook
Outlook has a feature the others don't: Sweep. Select a message, hit Sweep, and you can delete every message you've ever received from that sender in one action — and set a rule to auto-delete future ones. It's the fastest way to clear a backlog.
Yahoo
Settings → More Settings → Filters, then build rules by sender. Yahoo's filter limits are generous, so don't be shy about creating several.
Find out who leaked your address
This is the part that actually fixes the problem.
Method 1: plus-addressing (works in Gmail, iCloud, and Outlook)
Sign up as [email protected]. Mail still lands in your normal inbox. The day that address starts getting spam, you know exactly which company leaked it — and you can block just that alias.
Start doing this with every new signup and within a year you'll have a precise record of who can be trusted.
(A few sites reject the plus sign. Use your plain address for those.)
Method 2: Have I Been Pwned
Enter your address at haveibeenpwned.com and it lists the known breaches your email appeared in. Recognize a site on that list and you've found your source.
While you're there: if you reused a password on any of those sites, change it now.
Longer-term habits
Use a disposable address for one-off signups. Downloading a single PDF, reading one gated article — use a temporary mailbox and throw it away. But never use one for a service you plan to keep; when the mailbox expires, so does your ability to recover the account.
Leave optional fields blank. Only the ones marked * are required. The less you hand over, the less is exposed when that company is eventually breached.
Keep a "junk" mailbox. One address for newsletters, coupons and signup confirmations; a separate one for real people and services that matter.
Three things not to do
Don't reply, not even with "STOP". That's another way of confirming the address works.
Don't load images. Marketing mail routinely embeds tracking pixels that fire the moment images render. Gmail and Apple Mail proxy or block these by default — don't override it on a message you don't trust.
Don't post your address as plain text on a public page. Scrapers harvest exactly that. Use a contact form, an image, or a name [at] domain [dot] com format.
The one-line version
Remember signing up → unsubscribe. Don't remember → report as spam. That single rule handles about eighty percent of it; plus-addressing handles the rest by telling you where the leaks come from.
Email, password manager and breach-check tools are in our Tools category. Related: How to Cancel Subscriptions on iPhone and Where the Cancel Button Hides.
Mail app interfaces shift between versions. Paths here were checked in September 2026; labels may differ slightly, but the hierarchy is stable.