← Back to the blog

How do spammers get your email address? 6 harvesting methods

Spammers don't usually guess your address out of thin air, and in most cases you didn't make any obvious mistake either. Address harvesting is an established, semi-automated process built on a handful of standard techniques — and once you see how spammers get your email address, the fixes stop being superstition and start being a checklist. This piece is the mechanics behind the leaks summarized in why am I suddenly getting spam?: six concrete ways an address moves from private to "on a list," and what actually blocks each one.

Scraping bots crawl anything public

The oldest and still most common method is automated scraping. Bots crawl websites, forums, comment sections, business directories and social media profiles around the clock, pattern-matching for anything that looks like name@domain.tld. Public HTML is the main target, but harvesters also comb domain WHOIS records, PDF documents, and even code repositories where a developer's address sits in a commit history or a config file. If an address has ever appeared in plain text anywhere a bot can reach, assume it has been collected. Our guide to avoiding spam covers the practical side of this — never publishing a real address in public HTML, and using a contact form or an obfuscated format instead.

Dictionary and brute-force guessing

Not every targeted address was found — many are guessed. Spammers run automated "directory harvest" attempts against large providers and company mail servers, trying common patterns like info@, admin@, firstname.lastname@ and short dictionary words, then noting which ones the receiving server accepts instead of bouncing. Company addresses are especially exposed because the naming pattern (first.last@company.com) is usually predictable from the first employee you find. This is why a short, common local part attracts spam even if you never leaked it anywhere — it was never a secret to guess in the first place.

Data breaches and stolen databases

When a service you signed up for gets hacked, the leaked database — often address plus password hash, sometimes far more — doesn't stay with the attacker. It gets sold, traded and eventually dumped on forums where anyone can download it. A single breach can hand spammers a large batch of confirmed, real addresses at once, which is why breach-sourced spam tends to arrive in waves rather than a slow trickle. If you want to check whether one of your addresses is in a known breach and what to do next, email found in a data breach? walks through the response step by step.

List trading and email append services

Addresses gathered by any of the methods above rarely stay with whoever collected them first. A secondary market resells and rents lists between marketers and spammers, and "list cleaning" services test which addresses on an old list are still alive — those verified-active addresses become the most valuable, because they're proven to reach a real human. "Email append" services go a step further: given a name and a mailing address or phone number, they search matching databases to attach an email address that was never given to that company directly. None of this requires you to have made a mistake — it only requires that your address exists somewhere in the trading ecosystem at all.

Malware, hacked accounts and careless permissions

Some harvesting happens through people you know rather than anything you did. Malware that infects a contact's computer, or a webmail account that gets phished, typically exfiltrates the entire address book in one pass — which is how an address that was never posted anywhere public still ends up on a list. Overly broad permissions granted to shady browser extensions or mobile apps work the same way, quietly reading contacts or inbox contents in the background. There is little you can do about someone else's compromised address book, but keeping your own accounts secured with unique passwords and two-factor authentication — the same habits covered in email found in a data breach? — limits how much damage a breach on your end can spread to others.

Cut off what you can control

You can't stop bots from scraping the web or breaches from happening, but you can control how much of your real address is actually exposed to any of these methods:

  1. Stop typing your real address into one-time forms. Every signup, download gate and coupon popup is a potential future leak. For anything you'll only interact with once, use a free temporary address instead — it receives the confirmation mail and then stops existing, so it can't be scraped, guessed, breached or traded later.
  2. Tag ongoing signups with plus addressing or an alias. For accounts you do want to keep, a unique tag per sender — covered in Gmail plus addressing and other alias tricks — tells you exactly which harvesting event caused new spam.
  3. Never publish your bare address in public HTML. Use a contact form or an obfuscated format instead — scraping bots can only collect what they can read.
  4. Use unique passwords and 2FA everywhere. It won't stop your address from being harvested, but it stops a harvested address from turning into a full account takeover.

None of these methods require an unlucky mistake on your part — that's exactly why the fix isn't vigilance, it's exposure control. The fewer forms that ever see your real address, the fewer harvesting techniques have anything to work with. Next time a site only needs to confirm you can receive one email, generate a free temporary address instead of feeding another database — no signup, gone in 10 minutes. More on the mechanics of spam and privacy is in the FAQ.

Create a free temporary email address now →