Spam traps: pristine, recycled, and typo traps
Spam traps are addresses that only receive unwanted mail, run by blocklists and providers as sensors. The three types, how lists acquire them, and the defense.
A spam trap is an email address whose only purpose is to receive mail it never asked for. No human reads it, no legitimate signup produced it, and every message it receives is evidence about the sender. Blocklist operators and mailbox providers run millions of them as passive sensors, and a handful of hits can put an otherwise legitimate sender on a blocklist or into a reputation slide. Traps cannot be detected or removed from a list; they can only be kept out by the hygiene that makes their presence impossible.
The three families
Pristine traps are created as traps: seeded on websites for scrapers, planted in circulated lists, or minted on operator-controlled domains. Because they never subscribed to anything, receiving commercial mail at one proves harvesting, list purchase, or a compromised source, which is why operators weight pristine hits most heavily. Recycled traps are former real mailboxes: the provider closes an abandoned account, bounces everything for a year or more, then quietly reactivates it as a sensor. Any sender still mailing it either ignores bounces or resurrects ancient segments. Typo traps live on lookalike domains (gamil.com, yaho.com) and catch signup forms without confirmation, since the confirmation mail to a mistyped address is never clicked.
Trap types and what a hit indicts
| Feature | How it got on a list | What the hit proves |
|---|---|---|
| Pristine | Harvesting, purchased data, compromised source | Acquisition ingests addresses nobody submitted |
| Recycled | Old segment mailed past the bounce window | Bounce handling or recency discipline failed |
| Typo | Unconfirmed signup with a mistyped domain | The form lacks confirmed opt-in |
Who runs them and what a hit costs
Spamhaus operates the best-known network, feeding the SBL and its reputation data; Microsoft runs traps and reports per-IP hit counts in SNDS, the one place senders see trap evidence directly; smaller blocklists and security vendors run networks of varying quality. Costs scale with operator and family: repeated pristine hits at Spamhaus can produce listings that block delivery wherever their data is consumed, recycled hits typically erode reputation scores, and aggressive small lists escalate quickly while mattering less. In every case the response is the same order: stop the leak first, then remediate the listing.
Prevention and response
If you are hitting traps now
- 1
Pause the affected streams
Every additional hit deepens the listing you are about to remediate.
- 2
Identify the cohort
Cross-reference SNDS hit dates or blocklist evidence with campaign logs to narrow the segments and acquisition sources mailed in the window.
- 3
Quarantine, do not cleanse
Suppress the suspect cohort entirely; surgically removing traps from a bad source is guesswork, and the source is the problem.
- 4
Fix the door
The unconfirmed form, the vendor, or the resurrection bug gets fixed before volume resumes.
- 5
Then request delisting
Approach Spamhaus or other operators only after the leak is closed; premature requests get denied and burn credibility.
Prevention is the same short list this category keeps arriving at: confirmed opt-in on every acquisition path, immediate suppression on unknown-user bounces, engagement sunsetting, and never reactivating segments older than the recycled-trap window without a re-permission pass. Validation services help at the point of collection and cannot detect traps; a cleaned purchased list is still a purchased list.
Frequently asked questions
Can I find out which address is the trap?
How long until a dead address becomes a recycled trap?
Is one trap hit an emergency?
Do list cleaning services remove traps?
Key takeaways
- Traps are passive sensors: pristine hits prove bad acquisition, recycled hits prove bad hygiene, typo hits prove missing confirmation
- Spamhaus and Microsoft run the networks that matter, and SNDS is the only dashboard showing hits directly
- Traps cannot be detected or removed; the defense is confirmed opt-in, bounce discipline, sunsetting, and no ancient reactivations
- Respond to hits by pausing, quarantining the cohort, fixing the acquisition door, and only then requesting delisting
- Engagement sunsetting quietly suppresses most traps as a side effect of suppressing the silent