It’s Monday morning and the complaint queue is already full. Customers are forwarding scams that slipped through, and someone wants to know why a phishing email landed in the CEO’s inbox.
Spam isn’t slowing down. Kaspersky found that spam made up 47.27% of global email traffic in 2024, up 1.27 percentage points on the year before.
If you run mail for a telecom, ISP, hosting provider, or email service provider, stopping that traffic is your job. This guide explains how spammers get messages through, and which anti-spam techniques stop each trick.
What Spammers Are Looking To Get
Most spammers want money. They sell dubious products, steal credentials through phishing, or deliver malware that pays off later. A smaller group wants disruption or attention.
Either way, spammers think like businesses. They want to send the most mail for the lowest cost, without getting blocked. Every technique below is a way to do exactly that. Your job is to make each message more expensive to deliver than it’s worth.
How Spammers Get Past Filters
Botnets and compromised accounts
Spammers rarely send from their own servers. They rent botnets of infected computers or take over real mailboxes with stolen passwords. The mail arrives from IP addresses and accounts with clean histories, making it harder to block based on reputation alone.
Snowshoe spamming
Instead of sending a million messages from one source, spammers spread them thinly across hundreds of IP addresses and domains. No single source sends enough to trip volume thresholds, so each one looks harmless on its own.
Spoofing and lookalike domains
Spammers forge the “From” address to impersonate a brand, or register domains that look almost identical to a real one, like a zero in place of an “o”. This is the basis of most phishing. Learn how to stop phishing emails.
Freshly registered domains
Many campaigns use domains registered hours before sending. They are used for a burst of mail and then abandoned, before they build up a bad reputation.
Content and URL obfuscation
To get past content filters, spammers put text inside images, swap characters, and hide destinations behind URL shorteners and redirect chains. The message looks different every time, so simple pattern matching misses it.
Malicious attachments
Attachments remain a common way to deliver malware. Kaspersky reports that users encountered malicious email attachments more than 125 million times in 2024, including password-protected archives and SVG images disguised as harmless graphics.
Address harvesting and dictionary attacks
Spammers scrape addresses from websites and data leaks, or simply guess common ones like info@ and sales@ at every domain they find.
AI-written content
Generative AI now writes fluent, personalized messages in any language. Spelling mistakes used to be a useful warning sign; they are disappearing.
Anti-spam techniques that stop them
No single check stops everything. The most effective approach is to layer several checks on your mail server, running the cheapest ones first. That way, most spam is rejected before you spend processing power on content analysis.
1. Reputation checks at connection time
Before accepting a message, check the connecting IP address against DNS-based blocklists (DNSBLs). This stops a large share of botnet and snowshoe traffic in milliseconds, before the message body is even transferred.
Abusix Mail (formerly known as Guardian Mail) provides real-time IP, domain, and URL blocklists for this step. Here’s how each list works.
2. Sender authentication
Check SPF, DKIM, and DMARC on every inbound message. Together they tell you whether the sender is allowed to send for that domain, and whether the message was changed in transit. This is your main defense against spoofing. Read our guide to SPF, DKIM, DMARC and BIMI.
3. Domain and URL intelligence
Check every domain and link in the message, not just the sender. Look out for domains that are newly registered or were only recently seen sending mail. Expand shortened URLs so you can see where they really lead.
4. Content and attachment analysis
Content filters and attachment scanners catch what gets past reputation checks, including obfuscated text and malware. Treat password-protected archives with suspicion. These checks cost more processing time, so run them after the cheaper checks above. Read our complete guide to spam filtering.
5. Behavior and volume signals
Watch sending patterns, not just individual messages. Sudden spikes from a single account or IP range often indicate a compromised account, potentially from within your own network. Monitoring outbound mail protects your IP reputation and other people’s inboxes. See how to detect compromised accounts.
6. User reports and complaint data
When users click “This is spam”, that is valuable data. Feed those reports back into your filtering and use feedback loops to share them with the networks the spam came from. Learn how feedback loops work.
Which technique stops which trick
| Spammer technique | What it exploits | Anti-spam technique that stops it |
|---|---|---|
| Botnets and compromised accounts | Clean IP and account history | Real-time IP blocklists, behaviour and volume monitoring |
| Snowshoe spamming | Volume thresholds per source | IP and domain blocklists that track distributed campaigns |
| Spoofing and lookalike domains | Trust in familiar brands | SPF, DKIM and DMARC; domain blocklists |
| Freshly registered domains | No reputation history yet | Newly observed domain lists |
| Content and URL obfuscation | Pattern-based content filters | URL expansion and URL blocklists; content analysis |
| Malicious attachments | Users opening files | Attachment scanning and sandboxing |
| AI-written content | Filters and users looking for poor wording | Reputation and authentication checks, which don’t depend on wording |
Put it into practice: a quick checklist
- Query at least one DNSBL at SMTP connection time, and decide whether to reject or score.
- Check SPF, DKIM and DMARC on all inbound mail.
- Check the domains and URLs inside messages, including newly registered ones.
- Scan attachments and flag password-protected archives.
- Monitor your outbound mail for compromised accounts.
- Feed “This is spam” reports back into your filtering.
- Review false positives regularly, so legitimate mail keeps flowing.
How Abusix helps
Abusix Mail provides mail platforms with real-time IP, domain, and URL blocklists that you can query over DNS at connection time. The lists are built from our own spam trap network and threat data, so you can reject the bulk of spam before it reaches your content filters.