Why clicking unsubscribe on spam can make it worse

« Blog · By

The advice "just unsubscribe" is sometimes right and sometimes exactly wrong. It depends on who wrote — and that is usually recognisable.

The difference

With a legitimate sender — a shop you ordered from, a newsletter you subscribed to — the unsubscribe link is legally required and it works. Use it. It is the fastest route and it also helps the sender keep their list clean.

With real spam the link is something else: a test. Clicking confirms three things at once — the address exists, it is being read, and there is a human behind it who reacts to messages. Such an address is worth considerably more on the market than an unverified one. The result is usually more spam, not less.

How to tell them apart

Ask yourself first: do I know this sender? Did I order there, sign up, hold an account?

If yes, there is little against using the unsubscribe link. Further indicators of a legitimate send:

  • a complete legal notice at the foot of the message
  • the sender matches the company's domain
  • the message passes the authentication checks, visible in the header
  • there is an unsubscribe button in your mail program itself, not only in the text

If you do not know the sender, the message arrives in a language you never selected, or the unsubscribe link points at a domain unrelated to the sender: do not click.

The button hardly anyone knows about

Reputable bulk senders set a header called List-Unsubscribe. Your mail program then shows its own unsubscribe button — in Gmail and Outlook, at the top next to the sender.

This route is preferable to the link in the body: it runs through your provider, you open no third-party page, and since the large providers made it mandatory for bulk senders it works reliably. Its presence is also a good sign about the sender.

What to do with real spam instead

  1. Mark it as spam rather than deleting it. This is the most effective step. Your provider learns from it, and the rating feeds into the sender's reputation — with enough reports it affects them at every recipient.
  2. Do not reply, do not load images. A loaded image also confirms the message was opened. Why, is in our post on tracking pixels.
  3. Click nothing, not even an apparently harmless link.
  4. For persistent spam to one particular address: abandon the address if you can. Once it is on lists it does not come off — our own analysis shows address lists over ten years old still in use.

Why this is a problem at all

Anyone using the same address for every provider can only choose between tolerating spam and changing address. Anyone using a separate address per provider has a third option: switch off the affected one and keep everything else. Which variants are suitable for that we compare in a separate post.