A spam trap is a honeypot address built to catch spammers - and sending to one can tank your sender reputation. This guide explains the three trap types, how they get onto lists, and how to avoid them.
A spam trap (also called a honeypot) is an email address created or repurposed specifically to catch spammers. Because a trap never belongs to a real person, any mail sent to it is unsolicited by definition.
Hitting a spam trap is one of the fastest ways to destroy a sender's reputation:
BounceZero's Spam Trap Checker and trap-risk scoring look for address patterns typical of traps before you send - so the trap never gets a chance to hit your reputation.
A brand-new address created for the sole purpose of trapping. It is never published, never signs up for anything, and appears nowhere legitimate. Any mail to it is spam by definition - the worst kind of hit.
An old, abandoned inbox that was shut down and later repurposed as a trap. It looked legitimate when your list was built, so recycled traps catch senders who re-import stale data without checking whether the mailbox still exists.
An address registered on a domain with a common misspelling - gmal.com, yaoo.com, hotmal.com. Senders who rely on scraped or guessed addresses hit them; real opt-in lists almost never do.
Any list that was bought, rented, or scraped without consent will contain traps. Trap operators deliberately seed these lists.
Addresses collected years ago are recycled once the original owner abandons them. Re-importing old data without re-consent re-arms the trap.
Trap operators register misspelled versions of popular domains. One bad regex on a scrape imports thousands of trap addresses.
Publicly exposed addresses (forums, websites, WHOIS) are collected by harvesters and sold. Never use harvested addresses.
Every address should come from a real signup, ideally double opt-in. A person who typed the address is the strongest anti-trap signal there is.
Remove contacts who haven't opened or clicked in 6+ months. They are the ones most likely to be recycled into traps later.
Purchased lists are engineered to contain traps. There is no safe way to use them.
Run new imports and dormant re-imports through trap-risk detection, including typo-domain and known-trap-pattern checks.
Screen your list before the next campaign with the free BounceZero Spam Trap Checker.
A spam trap is an email address created or repurposed specifically to catch spammers. Because a trap never belongs to a real person, any mail sent to it is unsolicited by definition. Hitting one damages your sender reputation with mailbox providers and blocklist operators.
There are three main types: pristine traps (addresses created fresh and never used for anything but trapping), recycled traps (abandoned inboxes repurposed after a domain expires or is shut down), and typo traps (addresses registered on domains with common misspellings, such as gmal.com).
Pristine traps leak in through purchased or scraped lists that never went through real engagement. Recycled traps appear when old signup data is re-imported without checking whether the mailbox still belongs to a person. Typo domains catch senders who rely on scraped addresses instead of confirmed signups.
Use confirmed opt-in so every address came from a real signup, remove addresses that have been unengaged for months, never buy or scrape lists, and screen your list against trap-risk signals before each send. Clean, permission-based lists are the only reliable defence.
Flag trap-risk, catch-all and disposable addresses before you send. 100 free verifications.
Start FreeFollow BounceZero