I've been remiss. This is my first article that's dedicated to arguably one of the oldest and annoying problems with the internet that affects pretty much everyone. And that's junk email; a/k/a "spam".
There's a lot of contenders for the top ten list of internet-borne annoyances, like rampant advertising, disinformation, toxic social media, and online crime, to name a few. But spam ranks right up there, buddy.
In this article, we'll take a deep dive into the topic of spam, a little history, how it got its name (hint: Monty Python), what exactly is spam, the different kinds of spam, and what you can do about it.
For you non-older people reading this, Monty Python's Flying Circus was a groundbreaking British sketch comedy show that premiered in 1969. It heavily influenced shows like Saturday Night Live that came later.

Monty Python Viking spam skit -- bloody brilliant comedy
They did a skit that eventually gave birth to the word "spam" as a name for junk email. Briefly, the skit involved a small cafe where a number of Vikings are seated and start loudly singing about spam and how good it is, drowning out all other conversation. Furthermore, nearly every dish the cafe served had spam in it and "spam" was repeated many times in the names of each dish. "spam egg spam spam bacon and spam".
Watch on Youtube, opens in a new tab. It's short, barely over two minutes.
Of course there was no email spam in the early 70's. But as soon as it became apparent that repeatedly posting junk messages on public message boards, drowning out other conversations, it organically started being called spam, which hearkens back to that famous Monty Python skit.
The makers of the tinned meat product SPAM weren't too excited about that, as you can imagine. They might have sued for trademark infringement but there wasn't any obvious person or party to sue. No one person or entity was responsible for the word spam being used to describe junk messages on the internet. So Hormel wisely decided to make peace with it. They ask that the word appear in lower case when describing junk messages and in all upper case when describing their product. Indeed, their trademark spells it as "SPAM".
Now, decades later, most people don't conflate the two uses. When discussing "spam" as an email problem, no one is imagining "SPAM" the meat product or vice versa.
Usenet, the "chat rooms" of the 1980's, is where spam made its debut. It simply meant repetitive electronic messages posted that no one asked-for or wanted to see. Later on, as email starting picking up steam as a more person-to-person communications media, spam found its way there as well.
Today, spam, or its more technical term "Unsolicited Bulk Email" (UBE) is just that: Un-asked-for email sent to a large number of recipients, generally but not always by a party not known to those recipients. It's usually commercial in nature, but could be anything: political messages, scams, malware, religious proselytizing, chain letters, etc.
But determining if any particular email is or isn't spam surprisingly difficult. There is no one test that works 100% of the time. But its enough to say that if a particular email looks like spam to you then it probably is. Not all spam is scammy or fraudulent, either. A lot of it is, but a lot of it isn't.
This recalls a famous quote from a 1964 SCOTUS ruling made by Justice Potter Stewart regarding what is obscene and what isn't: "I know it when I see it."
Here we'll discuss the really bad spam. Scams may arrive via email but could arrive via text message or even a live phone call.
Most of the scammy email you get is sent in mass to many thousands of people. We'll discuss those just below.
Short cons -- These are usually single contact, one-and-done scams
Typical objectives are:
Long cons -- These usually develop over time and over multiple email/text exchanges
*1- In this case, your realtor's email address was hijacked. The scammer read their emails so they know you're buying a home, had your offer accepted, and are preparing to close on the purchase. How did the realtor's email get hijacked? I'll cover that further down. This is an example of spear-phishing; a scam meant specifically for you.
*2- Zelle is a legit person-to-person payment service owned and operated by the major banks. Scammers trick people into performing transfers of money. More on Zelle (and Venmo) here.
*3- "Wrong number" scams begin with a simple, short innocuous message that seems like it was sent to you by mistake. Maybe it was and maybe it wasn't, but you do not owe them a correction. You'll notice that (virtually) all of them are sent via SMS -- and not iMessage. Do Not Reply!
About online scams: Let me clarify something right here.
Nobody should experience self-shame or be made to feel shame from someone else for falling for an online scam. There is no "you should have seen that coming". No one deserves that. Today's cons are layered in obfuscating tech (which is already bewildering enough to most people) to slip right past the defenses they have.
There is no denying human nature -- there's a wide range of credulity among people. Being susceptible often just means a person hasn't seen that fraud before. It could also be a person whose life experiences were such that having to be hypervigilant against bad actors of whatever sort wasn't necessary. So that can hardly be considered a moral failing.
No one is 100% immune from any and all scams. Simpler cons may work on the most credulous. But even the most hardened and incredulous among us could fall for a sufficiently sophisticated long con.
Scammers construct their cons based on the amount of expense and effort they want to invest and according to the target they are after. Some cons are simple and east to spot. Some are more elaborate. And others, well, you better hope you weren't the one targeted.
As an I.T. guy that's pretty savvy to many online cons, I'm probably more incredulous/less susceptible than most. But I ain't gonna lie: I've seen frauds forwarded to me by clients that impressed me, spooked me even -- frauds that required a second or third look to sus out. Makes me think that I could have been fooled if I wasn't paying particularly close attention that day.
No, not an oxymoron.
How you deal with a particular piece of spam (email, usually) depends on a number of things.
Spam from an otherwise legit sender
This is usually a newsletter, a weekly flyer, etc. from a reasonably well-known company that you may or may not have done business with. But the key is that the sender is a legit outfit.
e.g. email from a well-known retailer, politician, action group, etc. will almost certainly be legit. And by "legit", I don't mean that it's not spam. It damn sure can be spam and quite often is. What I mean is the sender isn't a fraudulent enterprise. They aren't trying to scam or trick you.
Their emails will quite likely have an unsubscribe link included, usually at the bottom somewhere. These unsub links are legit. Use them! They may say it'll take x amount of days to stop receiving their email -- usually so that existing advertising campaigns can conclude.
One pretty good test that the sender is legit is if you receive email them periodically. Getting emails from that sender on a semi-regular basis is a sign of legitimacy, even if it's spam you'd rather not see. Most scam/fraudulent emails are one-shot from a random email address. Granted, you can still get thousands of these, but they're usually all from different email accounts -- hijacked or otherwise.
Another test is to examine the sender's email address. Some email programs don't show the email address until you hover over the senders name or click a down arrow or something in order to see the actual email address. Scam emails are often from highly contorted from-addresses that don't reasonably match the "display name" shown.
Warning. Ima gonna geek out here pretty hard. But if you want to be a pro at sussing out scam emails, you really need to know this. I know, it's complicated and it sucks that we even have to know all this. But them's the facts. I'm your advocate, trying to help protect you.
Can you tell which of the following email sending addresses are legit and which are fraudulent? 1, 4 are legit. 2, 3, 5, 6 are suspect. Let's discuss why.
Lots of colors! And yes, there's a reason I colorized them.
I colored-up these email addresses to help us in parsing them to reveal their multiple components. An email address isn't just one thing, after all. There's several pieces and each play their role.
Not for nothing, but this is one of many reasons why dark mode is superior. Multi-colored text like shown in these examples stands out much better.
First, let me explain all the color coding.
▶︎ The part in yellow is the display name and it's optional. The sender can make it read whatever they want or omit completely. Senders of spam email will make this display name look important. Legit emailers will usually just have their personal name or company name.
▶︎ The part in magenta is the username and is positioned immediately left of the @ symbol. And while it must be present, it can be whatever the sender wants it to be.
▶︎ The part in green is the subdomain, it's optional, and can be whatever the sender wants. Subdomains are where a spammer often uses naming that suggests legitimacy as we'll see below.
▶︎ The part in red is the domain name. It can be whatever the sender wants but within some important limits that make it easier to verify as spam or not.
That is, a spammer can register and use a domain name like "fzwiwsbgn.us" shown in #3 above. But they cannot use an already-existing domain name that someone else owns and controls. That distinction is really important! We'll go more into that in a minute.
e.g. In #4, "fool.com" is a legit sender. (The Motley Fool is a financial markets advice site) So, unless their email server is hijacked (more on that as well in a minute) then you can be pretty sure the email is from a legit sender. Mind you, it can still be spam. Legit senders often send spam. But it's not likely to be a scam or fraud.
OK, now you know what the various parts of an email address mean. Now let's discuss the ways they can be weaponized to trick you. We'll also discuss the six examples from above.
Legitimate domain names are difficult to spoof these days due to SPF, DMARC, and DKIM -- three email architectural security features that, together, help to verify that an email comes from who it says it's from. This is why I cannot send email that appears to come from, say, the Whitehouse. That doesn't stop spammers from registering new domains, but at least they cannot (easily) spoof legitimate domains.
When you open an individual email, in the "from" area you may see a display name only or you may also see the actual email address itself. Popular email services such as Gmail and Outlook use intelligence signals to help decide whether or not to show the actual email address. Emails that meet certain trust thresholds may show only the display name while emails that fall below that trust threshold might also show the actual email address as well. Keep an eye out for that.
Google and Microsoft don't publicly disclose which signals they consider important, how they interpret them, etc. This helps to prevent them from being gamed.
This isn't meant to relieve you from checking the actual email address if you think something is suspicious.
Now let us dissect the six examples from above.
#1: The domain name "adidas.com" is legit, because we know that Adidas is a maker of athletic shoes and that the domain is spelled correctly. The "us-news" subdomain is their internal, dedicated server that sends these emails. For sure, their emails are mostly spam. But Adidas is a legit company, not fraudulent, so using the unsub link in their emails is safe and effective.
#2: This one screams fraud from a mile away. First of all "Carshield Quote", on its face, is a major red flag because car warranties as a business classification is sketchy as hell. But there's technical tells, too: The sender name "wtwmctt" is a jumble of random letters and the full domain name "xoi.nej.rejear.biz" is suspicious as well. The "rejear.biz" part of the name is a registered domain, but it doesn't suggest any legit business identity. The subdomain, "xoi.nej", similarly, is random garbage.
Any unsub links in this email are fraudulent and clicking them only confirms that a real human read this email. And that, my friend, will significantly boost the value of your email address, landing you on dozens of additional spam lists. Never click unsub links on fraudulent spam like this one. Better to leave their spambot in the dark.
Furthermore, fraudulent spam like this are usually fully hyperlinked, meaning the entire email is clickable. Inadvertently clicking anywhere in these emails will trigger a read confirmation. You should mark this as spam or fraud in your email program then close the email. Never click anywhere inside the email window.
#3: Same as #2 above.
#4: Same as #1 above.
#5: This one is a fraud and is also trying harder to look legit. The username "bittonartcurator.gmail.com" is meant to confuse you into thinking this is from a Gmail account. After all, "gmail.com" is right in there, isn't it? But pay close attention to where it is. In this case, "gmail.com" is part of the username and not the domain name. This tiny little detail trips up a lot of people. There's also no @ symbol before the "gmail.com" portion -- that's another tell.
As with the other fraudulent emails we discussed, do not click on any unsub links. Mark this as spam or fraud in your email program then close the email.
#6: Here's another tricky fraud designed to confuse you. Looks pretty legit, coming from eTrade, yes? But look closely at this email address! Can you spot the trick?
The domain name part of this address is "west-coast-region.com". The familiar "etrade" name, which the scammer is hoping you'll focus on, is in the subdomain portion! And remember, the subdomain can be anything the sender wants. This email address looks pretty legit. I mean, eTrade is a major online brokerage so having a "West Coast Region" might look legit, right?
Now, had that email address been "closureteam@west-coast-region.etrade.com" (west-coast-region and etrade swapping positions) then it would be legit. That's because the domain name would then be "etrade.com". And domain names cannot (easily) be spoofed.
But it isn't. Instead, it was "closureteam@etrade.west-coast-region.com" -- which is fraudulent! The all-important "etrade", the part meant to trick you, is the subdomain, which, again, can be anything the sender wants. This is a very subtle detail, lost on those that don't understand domain hierarchies, but it makes all the difference in the world!
Fun fact: As of this writing, the domain name "west-coast-region.com" isn't even registered! Anyone can register that for about $15 or so.
Yes, I'm trying to be painfully detailed and clear on all this so pardon me if it seems over the top. But this subdomain and domain name sleight of hand is really freaking important to understand!
What???
I know, we're getting deep in the geek here -- but I can explain this. See if you agree. If you want to scroll down to the next section then I won't blame you.
IDN stands for Internationalized Domain Name. Back in the early days of the internet, domain names (web addresses like apple.com) used only Latin letters a-z, numerals 0-9, and a hyphen. That's it. 37 possible characters. Life was easy but not inclusive.
The internet is a very international thing. Before long, we realized that other non-Latin languages needed representation as well. To make that work, the Gods of the Internet allowed non-Latin letters to appear* in domain names using a thing called Punycode. I'll spare you the full technical rundown on Punycode, it's not important here. But what is important is what it does.
* Appear is the key word here. Actual domain names, even today, still only use those same 37 characters. The letters in the domain name don't change. Punycode just lets us display them differently, that's all.
That provides the end result of allowing non-Latin written languages, like Cyrillic (Russian, and others), Greek, Chinese, Hebrew, etc. to appear in domain names.
Some non-Latin letters coincidentally look like Latin letters. When a character from one writing system looks like a character from another, they're called homoglyphs. Briefly, homo means "same" or "similar" and glyph means the visual representation or shape of a character.
e.g. The Latin letter "a" looks like the Cyrillic letter "а". But they aren't the same! There are many other homoglyphs, too. Not just "a".
And therein lies the problem. Bad actors can register look-alike domains using a non-Latin homoglyph. It looks totally legit. But it's not.
If some scammer sends you an email with a sender name that contains homoglyphs like these, they can look totally legit. This also applies to website domain names, like what may be included in the scammy email.
Consider these two domain names: 1) apple.com and 2) аpple.com. These look alike, yes? But they aren't! In fact, if you hover your mouse over these two domain names and look at the lower-left corner of your browser window, you'll see two different domain name URLs displayed.
#1 will show "apple.com" -- as you expected. Click on it and you'll land on Apple's home page.
#2 will show "xn--pple-43d.com" -- this is the Punycode equivalent of the Cyrillic letter "а" followed by the Latin letters "pple.com". Click on this and you'll get a page loading error.
I know all this is arcane as hell. But it's not really that important for you to know all about IDNs and Punycode. Mostly because we don't have a good, smooth solution or advice on how to avoid it. The good news is it's pretty rare to encounter in the wild.
That little trick of hovering-over and looking at the URL shown on the bottom left of your browser window generally only works for hyperlinked web addresses. Hovering over an email address in an email you received will not do this unless it is hyperlinked -- and they usually aren't.
When you open certain emails, you may have noticed a message saying "Images are not displayed. Display images below?" or similar wording depending on who your email service comes from.
You might think that's an odd thing to ask you. Is it trying to protect you from seeing possibly obscene images? Why would email from, for example, eTrade, prompt the email program to ask that? eTrade isn't going to send dirty pictures, after all.
Here's why you're seeing that message.
Embedded images in an email message serve two purposes. One purpose, of course, is to make the email more attractive, engaging, and informative by including relevant imagines such as pictures, logos, etc.
But the other purpose, and I'd argue just as important, is that including embedded images can serve as a read confirmation. It tells the sender when and roughly where you read their email.
How does it do that?!?
Plain old boring text in an email is nearly always included in the email body that's delivered to your inbox. So when you open that email, no further information needs to be fetched from the sender's server. All of what makes up that email is already in your email account, regardless if you view that email or ignore it.
But... Image data are rarely included in the email body. Instead, linked images are included. When you open an email with linked images, the email program fetches the necessary images from the sender's server right then and there. The sender's server can easily log that event and report to the sender. Hence, a read confirmation.
So, when you see "Images are not displayed. Display images below?" or whatever wording, that's your email program protecting your privacy by asking you to confirm if you want to load those images or not. The sending server, and hence the sending party, can only know if you opened the email if you consented to loading the images.
Refuse that and the sender generally has no other way to know when, where, or if, you read that email or not.
That offers some privacy, but depending on the nature of the email, important image-based information might not be shown to you.
Ultimately, it's up to you to allow images to load or not, based on who's sending the email and how important it may or may not be.
This is one reason spam emails, especially the scammy fraudulent ones, hyperlink the entire email. Hyperlinks behave differently from linked image loading because they aren't automatic. You have to click to activate them. Since they're not automatic, your email program doesn't ask your permission before displaying them, because simply displaying a hyperlink is (usually) harmless. But since the scammers hyperlink the entire email then it's all-to-easy to inadvertently click some random spot on the email, especially when using a trackpad, thus triggering the hyperlink payload -- be it a simple read confirmation or linking to a fraudulent webpage that plasters fake virus warnings all over your screen.
Fraudulent email from verifiably legit senders (who would never send such a thing) is a strong indicator that sender's email account was hijacked. I see this all the time.
One particularly dangerous scam is receiving email from your realtor (whose email was hijacked) informing you that wiring instructions have changed.
How does this happen?
Here's (at least) one way that can unfold:
A person, you perhaps, receive an email that looks legit. In fact, you know it's legit because you followed all my advice above on dissecting the sender's email address and determined it's good.
Wait, what this? The sender included an attachment or maybe it's a link. Hmmm, it's a PDF file. But the PDF file requires a password to open. Thankfully the sender included the password in the email so I can easily open the PDF file.
Does something look "off" to you? Do you see what's happening here?
Why would the sender put a password on the PDF file?
Well, it might be confidential, so it needs a password, right?
OK, sounds good. But then why would they include the password in the very email that contains the confidential document that needs protecting!?!
That's like locking up your bicycle to a post outside. But since your friend is coming by to borrow it, you'll just tape the key to the seat as a convenience to them.
In what world would that make sense?
Here's what's really happening. That PDF file or link is almost certainly malware. It might not even be a real PDF (or whatever) file. The attacker may have simply added ".pdf" to the end to trick you. But attachments are routinely scanned by modern email servers to detect malware. So how to bypass that detection? By encrypting the attachment, that's how. Email servers generally cannot open and scan encrypted attachments.
But then neither can you. The sender (attacker) needs you to open the attachment in order to execute the malware.
How to facilitate that?
Simple! Just include the password in the email. Duh.
Not realizing this, you enter the password provided right there in the mail then open the attachment.
Then (maybe) you see an utterly realistic password box from your email provider asking you to login.
^^ This is your second clue something fishy is going on. ^^
Why would your email client or service, that you are logged into and accessing at this very second, ask you for your email password?
If you proceed, then your email account will likely be hijacked and start sending this same fraudulent email to all your contacts, and so on, and so on...
Yet a significant number of people fall for this every single day.
When reading an email from a sender you know is legit, consider your relationship to that sender. Is this the kind of message they'd normally send you? Is the message out of character in any way for this particular sender? Are they discussing or asking you for something out of the ordinary? Anything?
If you feel even the slightest spidey tingle then you should reach out to that person using a different channel of communication. Call or text them. Or someone they know. Or email them if they have another email account.
Don't just reply saying "Betty, is that really you?" You see the problem with that? Don't let "It's probably nothing" enter your mind. Be suspicious.
Note, I'm phrasing these examples in the first person as a rhetorical device to insert you into the moment. I want you to feel it rather than just reading it as a detached party. I want you to remember this and think about things before robotically proceeding full steam ahead when presented with fraudulent content.
Well, finally, I'm onto the good part of all this.
First of all, use an email service that has good spam filtering built-in. Gmail is the clear winner here. Gmail is one of Google's most important products. They put a lot of time, energy, and resources into making it one of the best free email options available.
Yes, yes, I can hear you all the way over here and I largely agree. Google is "evil" in many ways. But that doesn't mean every last thing they do is evil. I use and recommend several Google products.
Google explicitly states they do not scan emails for advertising purposes. You can choose to believe that or not. But if you don't believe that, then don't think the other major email providers would be any better.
A really cool solution that would be uniquely yours is a personal dot-com that you own. It's not free, but it's not that expensive, either. And since it would be yours, then you can host it wherever you want and move to another host at any time. e.g. My email robert@itcomo.com is all mine. I own the domain itcomo.com. That's my company name but you can have your personal name, if you wanted, assuming availability.
And for all that's holy and good, please don't use the email address your ISP (Internet Service Provider like Socket, Mediacom, Comcast, AT&T, etc.) gives you. They aren't interested in running a modern, feature-rich email system. The main reason they offer email in the first place is for lock-in and maintaining mindshare. e.g. Every email you send is an ad for your ISP. Neat, huh?
If your email is on AOL (ug), Hotmail, MSN, Yahoo, Bellsouth, your ISP, or other email system from the 1990s, chances are good you're getting 17 metric tons of spam every day. Their spam filtering ranges from nothing to merely ok. Those services should have died 15 years ago and I'm frankly surprise they're still around.
Another way to slow the tide of spam is to have a second email account (again, Gmail) that you use for all your online ordering, social media signups, and other things for which you don't expect to receive email that you need to pay quick attention to. You can check that account once a week or so.
Then your main account can be dedicated to actual correspondence you have with the real people in your life, your bank, and other important parties that may send you emails that you want to read right away. This will be your daily account.
Click here for more details on Gmail , Your email , and Business email for why I recommend Gmail. There's some overlap but you'll get a good reading.
Changing your online accounts from one email address to another isn't difficult. I can show you the steps in fairly short order. Yes, it's a tedious process if you have a lot of online accounts. e.g. I have about 400. What a PITA that would be. I should know because I'm doing that right now.
But one terrific bonus from doing this is taking the opportunity to improve your passwords and adding multi-factor authentication on all your online accounts, especially the important ones. That ain't nothing.
Spam is incredibly cheap to send. It only takes one person out of many, many thousands to respond to a spam message's call to action for the campaign to be worth it.
For actual scam/frauds, just one single person responding to the call to action can pay off handsomely. Just one.
The good news
Authentication features like SPF, DMARC, and DKIM, along with advanced spam detection algorithms, and today's AI spam detectors, have made life difficult for spammers. But just like the rats in NYC, spammers constantly adapt and figure out how to reach their marks. They constantly tweak their emails until they slip through the spam filters then let loose a campaign.
And when they are inevitably caught and blocked, the tweak some more. Again, Gmail keeps up with this better than anyone else.
There's no reason today to put up with spam. It's not a completely solved problem but anti-spam forces are ahead and have quite a lead on the spammers. The tools and techniques to effectively filter out most spam are here. You just have to use them.