Spam Traps and Recycled Addresses

The clock24 hours, then gone
A day of storage running down to nothing
The countdown on the address is the whole storage policy. When it reaches zero the mailbox and everything inside it are deleted, not archived.

In short. A spam trap is an address that exists only to catch senders who mail people who never asked. Hitting one damages a sender's ability to reach everybody else, which is the actual reason signup forms are hostile to throwaway addresses. Very little of it is about principle.

What a spam trap is

Mailbox providers and anti-abuse organisations operate addresses that no human reads and no human ever gave to anyone. Nothing legitimate can arrive at them, because there was never a moment when a person typed one into a form.

So anything that arrives is evidence. It says the sender got the address some other way: bought a list, scraped a website, guessed names against a domain, or kept mailing a contact who stopped existing years ago. The trap never judges the content. The message being there at all is the finding.

Traps are seeded where harvesters look: in page source, in old forum threads, or planted inside lists that get sold. A sender who collected addresses honestly never meets one.

Two kinds, and they mean different things

Pristine traps were never owned by anybody. They were created as traps and seeded to be scraped. Mail to one is close to proof that the address was harvested or purchased, and it is treated harshly.

Recycled traps used to belong to real people. Somebody had the address, signed up to things with it, then abandoned it. The provider eventually converts it into a trap. Mail to one is not proof of anything dishonest, and it is treated more gently, but it still hurts, because it says the sender is mailing a list that has not been cleaned in years.

Senders react differently to the two. A pristine hit is a crisis. A recycled hit is a symptom of neglect, and it is far the more common.

How a recycled trap works

The sequence is deliberate and reasonably standardised across large providers.

The mailbox goes quiet. The owner stops logging in and never comes back. After a long period the provider closes it and starts rejecting mail outright, usually for months, so that any competent sender receives repeated hard failures and removes the address. Then, quietly, the provider starts accepting mail at that address again, and begins counting who is still sending to it.

That waiting period is the fair part of the design. Every sender got repeated, machine-readable notice that the address was dead. Anyone still mailing it after the pause either ignored the bounces or never processed them, and both are what the trap is built to detect.

What happens to a sender who hits one

Reputation is scored per sending domain and per sending IP address, and those scores decide whether mail reaches inboxes, lands in spam, or is refused at the door.

A trap hit pushes that score down. Enough hits, or a handful of pristine ones, and the sender appears on a public blocklist. The damage is not confined to the bad addresses: once the domain or the IP is marked, mail to every legitimate subscriber degrades at the same time. A company can lose its password reset delivery, its order confirmations and its invoices at once because of a list it bought in 2019.

Recovery means fixing the list, waiting, and asking for delisting, which takes weeks. Traces of the episode are visible in message headers, in the results that receiving servers write down, which is one of the reasons reading headers is a useful skill.

The real reason forms refuse throwaway addresses

Here is the connection people miss. A marketing team that blocks disposable domains is usually not defending anything ideological. It is protecting a deliverability score it is measured on.

The logic is coarse but not irrational. Addresses that expire become dead addresses, dead addresses become bounces, and a fraction of them, on providers that recycle, become traps. A list carrying many throwaway addresses decays faster, so the cheapest defence is to refuse them at the form.

This is also why the refusal follows the domain and not you. The blocking is done by consulting lists of known throwaway domains, and once a domain is on one, every address on it is refused regardless of how the individual person behaves. Whether that trade is a good one for the site is a separate argument, and the answer is less obvious than the industry assumes.

How this applies to us, without softening it

We recycle addresses, and we should say so plainly.

A guest mailbox here is deleted twenty four hours after its last use, and immediately when you ask for a new address. Deletion is real: the mailbox, its messages and its stored files go, and nothing is archived. What we do not keep is a permanent record that the name was ever used, so the same address can be issued again to somebody else later.

The consequence is direct. A message sent to your old address weeks after you finished with it may arrive in a mailbox belonging to a stranger, who will read it, because it appeared in their inbox. A short name you chose yourself comes back around much sooner than a random one, since chosen names are drawn from a small pool of things humans think of.

We could prevent this by keeping an eternal list of every address ever handed out. We do not, because that list would be the one permanent record of everyone who ever used the service, and building it would contradict the reason the mailboxes are deleted in the first place. It is a deliberate trade, not an oversight, and it is part of why the service can be free and simple to run.

What this means for you

Do not use a throwaway address where the reply comes later. Confirmation codes arrive in seconds and are the ideal case. Recruiters, support tickets, warranty claims and anything with a password reset are the wrong case, and the failure is silent on both sides.

Prefer a random name over a memorable one. Randomness is what keeps the address from being reissued quickly, and it costs you nothing since you are not going to type it again.

If you want addresses that never get recycled at all, that is an argument for your own domain, where nobody else can ever be handed a name you used.

What this means if you send mail

Clean by inactivity, not by bounce. Waiting for a hard failure is precisely the behaviour recycled traps are built to catch, because by the time the failures stop and delivery resumes, you are mailing a trap.

Never buy or rent a list. Pristine traps exist specifically to be sold to you.

And read a wall of throwaway addresses as information rather than an attack. People give a burner address to a form they do not trust or do not care about, so the honest reading is that the offer did not earn a real one. Blocking the domains hides the signal without changing the fact, and it turns away the people whose real address is already circulating in leaked databases and who have learned to be careful with the next one.

Read next

All guides