Can spam end up costing you?

Jul 17, 2026 | Tips

Read the original in Spanish →

Can spam end up costing you?

A while ago, I signed up for a cybersecurity event and gave them my email address. Nothing unusual. Below it was a mandatory checkbox accepting promotional messages. Again, nothing unusual.

Then, one day, emails start arriving from random companies. Companies you have never heard of, that have never organized an event you attended. Congratulations: they have sold the database containing your contact details, and the buyers have sold it on again. Your data is now everybody’s business.

Is it legal? No. You are supposed to have agreed to the transfer of your data to third parties through explicit, informed consent. They will hide behind a clause in the “I agree to receive marketing communications” checkbox that supposedly lets them share your data. But that does not make it legal.

I wish you luck, and plenty of patience, if you decide to report the company. For one thing, you do not really know which company or event the data came from—probably every one you have ever signed up for—so tracing it will be difficult. For another, the AEPD, Spain’s data protection authority, might impose a fine smaller than the profit they made. You will never know whether it was collected, or what happened to the money afterwards.

Sorry, but I will pass. There is a much more effective tool, and it costs nothing.

A button called “Report spam”, “Report junk”, or something similar. You know the one. Using it should be obligatory: minimal effort, a huge reward. Here is how it works.

First, the obvious part: clicking the button automatically creates a rule that sends that address straight to spam. You have spared yourself the next five follow-up emails.

Now the interesting part: both Google and Microsoft have an internal indicator called SCL (Spam Confidence Level). Google calls it something else, but you get the idea. It is a number from -1 to 9, hidden in the header of every email, invisible to the ordinary user. In a fraction of a second, it determines whether a message reaches the inbox or gets buried in junk.

That is why deleting emails does not help. Deleting pushes the problem aside and leaves it alive: the spammer keeps sending, keeps earning, keeps going. Marking a message as spam is different: it poisons the well. It tells the system, “this sender should not reach anyone.”

You may be thinking what I thought: surely my report makes little difference. Actually, the margins these systems work with are ridiculously small. Google starts taking a dim view of a sender at a 0.3% complaint rate. Microsoft operates in similar ranges. Fractions of a percentage point. Almost nothing.

Let’s do the math. Someone sends 50 emails a day. Ten recipients mark them as spam: 20%. That is not “a little high”: it is almost a hundred times the threshold that triggers blocking. This is where intuition goes wrong: assuming that low volume means little damage. It is the other way around. These systems do not reward low volume; they penalize it more. A new domain with little history has no established reputation to soften the blow. It burns faster, not slower.

And this works at domain and IP level, not just for individual addresses. The spamming company cannot escape simply by creating another email account.

So, if the organizations responsible for protecting our privacy are not doing a particularly good job—but that is another article—let’s at least do something useful for everyone with one small gesture.

The button you think is harmless is a weapon. Use it.

← Previous The battle is not AI vs humans. It is judgment vs noise Next → Is email secure?
← Return to blog Back to top ↑