Deliverability

What is a spam trap, and how do I avoid hitting one?

A spam trap is an email address maintained by an anti-abuse operator or mailbox provider that exists only to catch senders who should not have it. Mail arriving at one is close to proof that the sender acquired addresses without consent or stopped maintaining their list, which is why a trap hit costs so much more than an ordinary bounce.

Spamhaus, which operates traps and publishes the blocklists they feed, defines them like this:

A spamtrap is an email address traditionally used to expose illegitimate senders who add email addresses to their lists without permission. They effectively identify email marketers with poor permission and list management practices.

Why can I not just find them and remove them?

Because nobody will tell you which addresses they are, and removing them would fix nothing.

Spamhaus makes both halves of that explicit:

Spamtraps are never revealed by their owners. Partly because they are a component of the secret sauce of their filtering, and partly because if the trap is identified, what usually happens is that the sender simply suppresses the trap address – and they don’t undertake any of the necessary to work to improve their data.

and states the conclusion in bold on its own page:

We strongly urge people to view spamtraps as proof of a data collection or hygiene issue and not be misled into conducting a hunt for spamtraps. Attempting to locate and remove traps only treats the symptom and not the underlying problem.

This is the practical point of the whole topic. A trap hit is a symptom. The cause is a specific defect in how addresses got onto the list or how long they stayed there, and that defect is putting other bad addresses on your list too.

What kinds of trap are there?

Enough kinds that each one points at a different mistake.

TypeWhat it isWhat hitting it says about you
Pristine or classicAn address never issued to anyone and never publishedThe address was guessed, bought, or invented
SeededAn address deliberately hidden where only a scraper would find itYou are scraping, or buying from a scraper
Typo domainAn address at yaaho.com or homail.com and similar lookalikesYou accept typed addresses without validation
Recycled or deadA real address that its provider shut off and later reopened as a trapYou are ignoring hard bounces
Dead domainAn expired domain bought by a trap operatorSame, at domain scale
LiveA real person's mailbox, used to make blocking decisionsYou mailed someone who did not ask
Role addressespostmaster@, abuse@, admin@, published in registration recordsYou harvested from public records

Two of these deserve emphasis because they catch senders who think they are careful.

Recycled traps punish ignored bounces specifically. Spamhaus describes the mechanism: dead addresses are rejected "with a hard bounce for a period of time, often 12 months or more", and then "the addresses are silently turned back on in the form of spamtraps". So a list you stopped cleaning a year ago is not merely stale, it is arming itself. Their verdict on this one is blunt: "Hitting this type of trap is a significant red flag."

Typo traps are the argument for validation at the point of collection. They catch honest mistakes rather than dishonest sourcing, which is why Spamhaus notes they "are not 'pure' spam traps, can contain a lot of real mail, and are generally weighted accordingly".

How do I avoid hitting them?

By changing the two things that put addresses on your list: how they get on, and how they come off.

  • Confirm the address at signup. A confirmation step defeats pristine, seeded and typo traps at once, because none of those addresses will complete it. Nothing else covers all three.
  • Never buy, rent, or append a list. There is no such thing as a purchased list without traps in it, since traps exist precisely to be in purchased lists.
  • Suppress hard bounces immediately and permanently. This is the only defence against recycled traps, and it works only if it is automatic. Bird's suppression list does it on your behalf, and hard bounces land on it without you acting.
  • Retire addresses that have gone quiet. A subscriber who has not opened anything in a year is either uninterested or gone, and "gone" is the case that turns into a trap. List hygiene covers the sunset policy.
  • Keep role addresses off marketing lists entirely. Spamhaus is unusually emphatic here: these "should almost NEVER be on a marketing mailing list".

What happens if I hit one?

It depends on the trap, and you will usually learn about it indirectly.

Nobody sends you a notice. What you see is the downstream effect: a reputation slide, sudden filtering at a provider, or a blocklist entry that arrives with no obvious cause. What is a blocklist covers what to do once that has happened.

The recovery is the same as the prevention, which is the tidiest thing about the subject. Fix the acquisition path, suppress everything that has bounced, retire the unengaged, and the traps stop being reachable. As Spamhaus puts it, if you get the data collection and hygiene right, "you won’t need to worry about the various types of spamtraps that exist…. Because you won’t be hitting any."

Buduj na tej samej sieci.

Testowy klucz API otrzymasz od razu. Dostęp produkcyjny odblokujesz po dodaniu metody płatności i zweryfikowaniu nadawcy.

Zacznij od jednego kanału.
Dodaj kolejne, gdy będziesz gotowy.

Testowy klucz API otrzymasz od razu. Dostęp produkcyjny odblokujesz po dodaniu metody płatności i weryfikacji nadawcy.

Używasz Claude Code, Cursor lub Codex? Skopiuj prompt konfiguracyjny, a Twój agent zainstaluje za Ciebie Bird CLI i umiejętności. Wybierz swój:

Cursor