Skip to content
Deliverability

Spam traps: pristine, recycled, and typo traps

Spam traps are addresses that only receive unwanted mail, run by blocklists and providers as sensors. The three types, how lists acquire them, and the defense.

A spam trap is an email address whose only purpose is to receive mail it never asked for. No human reads it, no legitimate signup produced it, and every message it receives is evidence about the sender. Blocklist operators and mailbox providers run millions of them as passive sensors, and a handful of hits can put an otherwise legitimate sender on a blocklist or into a reputation slide. Traps cannot be detected or removed from a list; they can only be kept out by the hygiene that makes their presence impossible.

The three families

Pristine traps are created as traps: seeded on websites for scrapers, planted in circulated lists, or minted on operator-controlled domains. Because they never subscribed to anything, receiving commercial mail at one proves harvesting, list purchase, or a compromised source, which is why operators weight pristine hits most heavily. Recycled traps are former real mailboxes: the provider closes an abandoned account, bounces everything for a year or more, then quietly reactivates it as a sensor. Any sender still mailing it either ignores bounces or resurrects ancient segments. Typo traps live on lookalike domains (gamil.com, yaho.com) and catch signup forms without confirmation, since the confirmation mail to a mistyped address is never clicked.

Trap types and what a hit indicts

FeatureHow it got on a listWhat the hit proves
PristineHarvesting, purchased data, compromised sourceAcquisition ingests addresses nobody submitted
RecycledOld segment mailed past the bounce windowBounce handling or recency discipline failed
TypoUnconfirmed signup with a mistyped domainThe form lacks confirmed opt-in

Who runs them and what a hit costs

Spamhaus operates the best-known network, feeding the SBL and its reputation data; Microsoft runs traps and reports per-IP hit counts in SNDS, the one place senders see trap evidence directly; smaller blocklists and security vendors run networks of varying quality. Costs scale with operator and family: repeated pristine hits at Spamhaus can produce listings that block delivery wherever their data is consumed, recycled hits typically erode reputation scores, and aggressive small lists escalate quickly while mattering less. In every case the response is the same order: stop the leak first, then remediate the listing.

Prevention and response

If you are hitting traps now

  1. 1

    Pause the affected streams

    Every additional hit deepens the listing you are about to remediate.

  2. 2

    Identify the cohort

    Cross-reference SNDS hit dates or blocklist evidence with campaign logs to narrow the segments and acquisition sources mailed in the window.

  3. 3

    Quarantine, do not cleanse

    Suppress the suspect cohort entirely; surgically removing traps from a bad source is guesswork, and the source is the problem.

  4. 4

    Fix the door

    The unconfirmed form, the vendor, or the resurrection bug gets fixed before volume resumes.

  5. 5

    Then request delisting

    Approach Spamhaus or other operators only after the leak is closed; premature requests get denied and burn credibility.

Prevention is the same short list this category keeps arriving at: confirmed opt-in on every acquisition path, immediate suppression on unknown-user bounces, engagement sunsetting, and never reactivating segments older than the recycled-trap window without a re-permission pass. Validation services help at the point of collection and cannot detect traps; a cleaned purchased list is still a purchased list.

Frequently asked questions

Can I find out which address is the trap?
No. Operators never disclose trap addresses, since disclosure destroys the sensor. Evidence arrives as aggregate counts or listing notices, and remediation works at the cohort level.
How long until a dead address becomes a recycled trap?
Providers publish no schedules; the conventional window is at least 12 months of unknown-user bounces before reactivation. Treat any segment untouched for a year as contaminated until re-permissioned.
Is one trap hit an emergency?
One recycled hit on a large list is a warning shot worth investigating. Repeated hits, any pristine hit, or a resulting blocklisting is an incident that justifies pausing the affected stream.
Do list cleaning services remove traps?
No reliable service can identify pristine traps, and claims otherwise describe a leak in the trap network rather than a product. Validation catches typos and dead domains at signup; it does not launder acquisition.

Key takeaways

  • Traps are passive sensors: pristine hits prove bad acquisition, recycled hits prove bad hygiene, typo hits prove missing confirmation
  • Spamhaus and Microsoft run the networks that matter, and SNDS is the only dashboard showing hits directly
  • Traps cannot be detected or removed; the defense is confirmed opt-in, bounce discipline, sunsetting, and no ancient reactivations
  • Respond to hits by pausing, quarantining the cohort, fixing the acquisition door, and only then requesting delisting
  • Engagement sunsetting quietly suppresses most traps as a side effect of suppressing the silent
What are spam traps? Types, causes, and prevention | Inbox Theory