DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

Spammers Did Not Hack Your Inbox. Here Is Where Your Address Came From

Spammers do not hack your inbox. I run AliasFleet, an email-alias service built on one address per site. You cannot stop the harvesting. You can make what they harvest useless. The addresses come from places you already gave it: breached databases, public pages they scrape, brokers who sell it, and automated guessing.

The leak that fed a thousand lists

Start with the big one: breaches are probably the largest single supply line, and the one you can check for yourself. Have I Been Pwned currently lists 1,042 breached websites holding 17,845,048,963 compromised addresses. Those are not hypothetical numbers. They are files that were stolen, packaged, and traded.

The breach makes the news. The resale market is the actual supply line. When a site is breached, the customer database rarely ends up in one pair of hands. It gets copied, sold, and resold until it lands with spam operators who want exactly one column: the email address. A 2016 How-To Geek walkthrough of spammer methods called this likely the way most spammers find addresses. A breached address is known-active. Somebody typed it into a signup form once.

The uncomfortable corollary: your address can be on a spam list because of a site you used in 2012 and forgot. The dump does not expire. Addresses get re-traded for years, which is why one breach keeps producing junk long after the company involved has moved on.

How do leaked databases reach spammers?

A stolen customer file is copied and sold through criminal markets, and each buyer resells or trades it onward. Within months, the same list of email addresses sits with many spam operators, each running their own campaigns. That is why one breach turns into junk from different directions over a long stretch of time. If your address is in one of those files, our breach-response guide covers the passwords, the phishing, and the lockdown steps in order.

The crawler that reads the open web

Before breached databases existed, there were bots. Harvester programs crawl web pages, forums, mailing-list archives, and Usenet posts, pulling out anything shaped like an email address. The technique is old enough to have a documented taxonomy: harvesters look for mailto: links, staff directories, professional society membership lists, and comment sections where people write "email me at".

The craftier variant never touches a public page. Direct marketers take a name and street address from their records, then search the web for a matching email address, a practice called e-pending. And when you fill in a form on some sites, the data is sold to spammers through a web service or HTTP POST the moment you submit, with the revenue shared with the site owner. The harvesting literature calls these the best emails spammers can get, because the address is fresh and the person just proved they buy whatever the form was for.


The US CAN-SPAM Act of 2003 made it illegal to send commercial email to addresses obtained by automated harvesting from sites that post a notice saying they will not give, sell, or transfer addresses. Bots are only clearly illegal against sites that said no, so most harvesters aim at the sites that never bothered.

The WHOIS well is mostly dry now: registration data got redacted under privacy rules, so the bots moved on to forums and breaches instead.

What is an email harvester?

An email harvester is a crawler built for one pattern: the shape of an email address. It walks public pages the way Google does but keeps only the addresses. Posting yours in plain text anywhere public, in a forum signature or a mailto link, is the fastest way to feed one.

The brokers who never met you

Then there is the legal version, which is bigger than all of this. Data brokers buy and assemble profiles from places you would never connect to your inbox: store loyalty programmes, warranty cards, magazine subscriptions, sweepstakes entries, public records. Then they sell those profiles, and the buyers sell them on.

The industry's catalogue is the giveaway. The FTC's 2014 study of the data broker industry found companies selling audience segments built on sensitive inferences, pregnancy, diabetes, and high cholesterol among them. The FTC chair at the time, Edith Ramirez, put it this way:

The extent of consumer profiling today means that data brokers often know as much, or even more, about us than our family and friends.

The scale is the part that stays with me. One of the nine brokers in the study held 1.4 billion consumer transactions and 700 billion data elements; another added three billion new data points every month; and seven of the nine were passing data to another broker in the study, so your address can move through three or four companies before the first spam arrives, and none of them ever met you.

This is where enforcement has actually bitten. In 2016 the FTC settled charges against LeapLab and its partners for buying loan applications from payday-loan sites and selling 95 percent of them, at about fifty cents each, to entities with no legitimate need for the data. The applications held names, addresses, phone numbers, employers, Social Security numbers, and bank account numbers. The order carried a $5.7 million judgment and a $4.1 million default judgment. Across the Atlantic, the UK's ICO published an enforcement notice against Experian in October 2020 after a two-year investigation found all three big credit-reference agencies profiling people for direct marketing without their knowledge, a practice the ICO called "invisible processing". Experian was ordered to fundamentally change its marketing data business or face fines up to £20 million or 4 percent of global turnover. The pressure is still current: in May 2026 the FTC moved to permanently bar data broker Kochava from selling precise location data without explicit consent, ending a case it filed in 2022.

What do regulators actually do about brokers?

They fine the worst offenders and write rules the rest ignore slowly. The FTC has banned brokers from selling location data without consent and punished brokers that fed data to scammers. The UK's ICO forced Experian to rebuild its marketing data business. Real enforcement, but slow. And it never pulls your data back from lists already sold.

The guesser that never stops

The fourth method needs nothing from you at all. A directory harvest attack fires thousands of guesses at a mail server: every combination of common first names, surnames, and initials at one domain. It works because of a quirk in how mail servers answer. The server rejects mail to addresses that do not exist during the SMTP session, so every address the server accepts is confirmed real. The technique is documented plainly: pure brute force is impractical beyond five or six characters (every 8-character combination is nearly three trillion guesses), but dictionary guessing against common names is cheap, and the validated lists get sold between spammers.

This is mostly a corporate problem. It works best against companies with standard address formats, the first.last@company.com pattern. Against a personal address with no predictable pattern, the hit rate drops; there is nothing systematic to guess. But it is the purest illustration of the whole piece: nobody stole anything. They knocked on doors until one opened.

The four supply lines, side by side

Supply line Where your address was What you can do about it
Breached databases A site you used, maybe years ago Check HIBP; change any reused passwords
Harvester bots Public pages, forums, mailto links Never post the address in plain text
Data brokers Loyalty cards, warranty forms, public records Opt out where offered; contain the blast radius
Directory guessing Any provider domain, tried automatically Little directly; a unique address per site blunts it

So which of the four feeds your inbox the most? Nobody can say. There is no public measurement of the split, so be suspicious of anyone who quotes you a percentage for your spam. They are guessing.

Stop feeding the lists your real address

You cannot stop any of this. You cannot un-breach the database, un-scrape the forum, un-sell the broker file, or un-guess the address. Every defensive article that pretends otherwise is lying to you. What you can change is what the harvesters take home.

An email alias is a separate forwarding address that exists for one relationship. Hand every site its own address, and the supply lines above all break the same way: the breached database now holds an address good for one shop and nothing else, and a scraped forum post names an address you can switch off in seconds. The broker file points at the one site that handed it over. The guessed address was never yours. Our leak-tracing guide walks through the mechanism: the To field names the source the moment spam arrives.

The honest caveat, because there is always one: this does not scrub the past. The address you have used everywhere for a decade is already in the dumps and the broker files, and no product reaches back in time. Our spam-spike diagnostic is the piece for that address. What aliases do is stop the next diagnosis problem from ever existing: every new signup gets a traceable address, every future spike names its source, and every noisy sender gets a one-click kill switch. Setting one up takes about two minutes, and the one-address-per-site habit is the whole system.

Spammers will keep harvesting. They have four supply lines and no reason to stop. The move is to stop giving them an address worth having. One per site. Traceable. Switchable. Yours.

Top comments (0)