Email bombing: what to do when your inbox is flooded, and how to keep your forms out of it

Email bombing buries one alert under thousands of real signup emails or sets up a fake IT-support call: steps for victims, IT teams and the sites sending it.

An ornate metal letterbox on a cream wall, stuffed with advertising flyers that bulge out of its slot
Photo: Letterbox 2303-0455 by Mozzihh, CC BY-SA 4.0, cropped. Via Wikimedia Commons.
In short
  • Email bombing floods one inbox, often with genuine mail from other sites’ forms, to hide one alert or to set up a fake IT-support call.
  • If it is happening to you: search for the hidden alert, check your accounts directly, and give no one remote access because they called about the spam.
  • Count sends per inbox, not per IP address or spelling: fold Gmail dots and +tags for the count, never for identity.
  • Send one confirmation and no reminders, never put visitor-typed text in the email, and give password resets and security notices their own sending budget.
  • A server-side check can stop the automation and proxy pools it detects; it answers a submission without a browser token with a degraded allow, so hold those, and it cannot tell whose address was typed, so keep the per-inbox cap.
On this page
  1. What email bombing is, and what the flood is hiding
  2. Email bombing: what to do right now
  3. List bombing: why your website’s forms are the ammunition
  4. Count sends per inbox, not per spelling
  5. Send one confirmation, then nothing
  6. Check the sender before the email exists
  7. Never let the visitor write your email
  8. Keep a flood from silencing your own security mail
  9. If your form was used in an email bombing

Email bombing is a flood of email aimed at one address so that its owner cannot use the inbox or misses the one message that matters. Today the flood is often made of genuine confirmations from real websites, sent because a script typed the victim’s address into hundreds of newsletter, signup, password-reset and contact forms. If it is happening to you now, start with what to do; the second half is for anyone whose website forms send email. Outside facts were checked on 10 October 2026; Maskbreak’s example answers are computed from its own code.

In early November 2024 an employee at a Sophos MDR customer reported over 3,000 spam messages in 45 minutes. Soon after, she accepted a Teams video call from an outside account named “Help Desk Manager”, who told her to allow a remote screen-control session (Sophos, 21 January 2025). Rapid7, reporting the same pattern in May 2024, found that many of the messages were not malicious at all but “newsletter sign-up confirmation emails from numerous legitimate organizations across the world” (Rapid7, 10 May 2024).

What email bombing is, and what the flood is hiding

The flood is often cover for something else, in one of two ways:

  • Hiding an alert. In 2012 Brian Krebs described floods for hire that kept a business from “ever receiving or finding alerts from their bank” (Krebs on Security, 18 July 2012). Switzerland’s National Cyber Security Centre wrote in February 2026 that in many cases attackers had got into a victim’s bank or shop account, made a transaction and buried its confirmation (NCSC).
  • Setting up a fake help-desk call. Microsoft (May 2024, updated in June) tied a campaign of this kind to Storm-1811, a group known to deploy Black Basta ransomware. Callers posing as IT support followed the flood and talked users into granting access through Quick Assist, from late May also through Teams accounts named “Help Desk” and “IT Support”. The US advisory on Black Basta says the spam came “often from legitimate sources like website registrations” (CISA AA24-131A, revised 8 November 2024).

It goes by several names. MITRE ATT&CK lists email bombing as technique T1667 (created 31 January 2025), where a bot registers the address for lists “that do not validate new signups”. Microsoft calls that form “link listing attacks”; others say subscription bombing or list bombing.

Spam filters let much of it through because the mail is genuine. It comes from “real web forms from legitimate companies” whose SPF and DKIM are correctly configured, so the filters “classify the messages as harmless”, the Swiss centre explains.

An email bomb attack keeps office hours. Mathias Payer (EPFL) and Candid Wüest (xorlab) studied 24 waves, 46,970 emails sent to medium-sized and large European organisations in late 2024 (Payer and Wüest, Communications of the ACM, May 2026):

  • Size: the average wave was 1,957 emails and the largest 4,847 in under two hours; a normal day brought fewer than ten an hour.
  • Day: half the waves fell on a Friday.
  • Time: most began in the morning, most often between 8 and 10.

They also quote the attackers’ plan, from a Black Basta chat leaked in February 2025:

I will flood their inboxes with spam, and you will call them pretending to be an IT admin, saying they need to install a spam filter. She installs AnyDesk, and we get in to install our software.

Black Basta chat, leaked February 2025

Email bombing: what to do right now

Treat the flood as a distraction from something else until you know otherwise.

  1. Do not delete everything yet. Search the inbox and the spam folder for “password”, “payment”, “order” and “security”, the Swiss centre’s list, to find what the flood may be hiding.
  2. Check your important accounts directly, in their own apps or by typing the address, never through a link in the flood, and change passwords where anything moved. For the mailbox itself Google suggests a Security Checkup.
  3. Give nobody remote access because they offered to fix the spam. A call or a Teams or WhatsApp message about it is how the help-desk scam starts: hang up and call your IT team on a number you already know. Let a Quick Assist helper connect only if you started the contact yourself, says Microsoft (May 2024). The FTC is blunter: “Legitimate tech companies won’t contact you by phone, email, or text message to tell you there’s a problem with your computer” (FTC, September 2025).
  4. Do not reply to any of it. Once the flood stops, lists that did sign you up keep writing until you unsubscribe (Payer and Wüest); use your mail app’s own unsubscribe button rather than links in messages you cannot vouch for.
  5. Keep a record and report it: when it started, a few senders, any call. Attacking inboxes without consent “is illegal in most jurisdictions”, Payer and Wüest note. In DPP v Lennon the High Court of England and Wales held that consent to receive email does not cover messages sent to interrupt the system. A householder, Mr Justice Jack wrote, does not consent “to having his letter box choked with rubbish” (judgment, 11 May 2006). This is not legal advice.

How to stop email bombing in Gmail and Outlook

You cannot switch subscription bombing off: the burst ends when the attacker’s paid run does, and one bombing service Payer and Wüest examined sold runs from one hour to 31 days. Meanwhile you can make the inbox usable:

  • Gmail warns you when it detects a mailbomb. Inbox categories split the flood from the rest, and once you have found what matters, a search such as category:updates newer_than:1d finds the junk to filter or delete (Google).
  • Outlook at work or school: Microsoft 365 moves a mail bomb it detects to the Junk folder, while senders on your safe senders list still reach the inbox (Microsoft, 30 June 2025).
  • Filter into a folder, never delete by keyword. Confirm, account, password and reset are among the flood’s most common subject words (Payer and Wüest), and the alert you are looking for may use them too.

If you run IT for the people being flooded

  • Microsoft’s mail-bombing detection, rolled out from May 2025, is available by default in Exchange Online Protection and Defender for Office 365. Analysts find it as “Mail bombing” in Threat Explorer and Advanced Hunting (Microsoft Tech Community, 30 June 2025). Google Workspace admins can block the flood’s senders and add content compliance rules (Google).
  • Restrict Teams external access to trusted domains and verify unsolicited “IT” contact through a known internal channel (Microsoft Threat Intelligence, 2 September 2026). Sophos’s cases exploited a default setting that “permits users on external domains to initiate chats or meetings with internal users”.
  • Remove Quick Assist and other remote tools you do not use: Microsoft noted in May 2024 that Quick Assist is installed by default on Windows 11. Tell staff how the real help desk reaches them, and consider a verbal code, “a key phrase that an attacker is unlikely to know” (Microsoft Security, 18 April 2026).
Try it

See the check on your own visit: the free live check on the homepage runs the network and browser checks on your connection and lists every reason.

Open the live check

List bombing: why your website’s forms are the ammunition

Much of the mail in such a flood comes from websites whose forms accepted a stranger’s address and mailed it: signup form spam with a victim at the other end. In 2016 Spamhaus reported that one company saw nine addresses signed up over 9,000 times in two weeks, “creating 81,000 confirmation emails”, and half the flood it examined was account signups at WordPress sites, not newsletters. The onus of stopping it, Spamhaus concluded, “is on everyone that has any sort of web-based signup that results in an email being sent” (Spamhaus, 16 September 2016).

Payer and Wüest found newsletters the most common source, then registration confirmations, with password resets and support forms also abused: two of their victims received 77 and 49 reset emails for accounts, many created just for the attack. Proofpoint calls the contact-form version form bombing: thousands of “thanks for contacting us” replies that need no “click to confirm” step (Proofpoint, 11 December 2025).

The scripts are simple: according to underground forum discussions the researchers cite, some groups record a form’s requests once and replay them with new addresses. A CSRF token or nonce, used by most of the services abused in their case study, costs a script one extra request, and most bombing services they analysed claim to rotate IP addresses through proxies.

Your domain pays too. Google warns that “user spam reports can lower your domain’s reputation” (Gmail sender guidelines). During a 2016 wave Spamhaus even told ISPs to block mail from some of the largest email service providers, because many lists in the flood had not validated new signups (Krebs on Security, 18 August 2016). Like SMS pumping, it turns your own send into the weapon.

Emails a stranger can aim at someone else’s inbox
FormWhat it sendsWhat keeps it out of a flood
Newsletter or waitlistA confirmation, sometimes remindersOne confirmation per inbox, nothing before the click
Account signupA code or a welcomeThe same, and a check on the sender first
Signup for an address with an account“You already have an account”A per-inbox cap; the same answer as a new address
Password resetA code or a linkA per-account limit and its own sending budget
Contact or quote requestA “thanks for contacting us” receiptFixed text or none; a per-inbox cap
Team inviteA team name the sender typedLinks stripped; caps per sender and per team

Count sends per inbox, not per spelling

Per-IP limits, which the Swiss centre recommends, help, but the services say they rotate IP addresses, and what is under attack is an inbox: count that. OWASP asks the same of password resets, limited “on a per-account basis” (OWASP).

One inbox has many spellings. Gmail says “johnsmith@gmail.com and j.o.h.n.s.m.i.t.h@gmail.com are the same address”, and that it “can’t prevent people from accidentally or maliciously using a dotted version of your address to sign up for subscription emails” (Gmail Help). A plus sign and any word reach the same Gmail inbox (Google Workspace), and plus addressing is “enabled by default in Exchange Online” (Microsoft Learn). A cap on the address as typed resets whenever the attacker moves a dot.

So fold the spelling for the count: lower case, drop a +tag, and drop dots on gmail.com only (on work and school accounts “dots do change your address”). Read googlemail.com as gmail.com too: mail to either “will go to the same place” (Google Account Help). Fold for counting, never for identity: mail the address as typed, and never match or merge accounts on the folded form. Store a keyed hash, not the address:

Node.js, server only
// A counting key, never an identity: send to the address as typed.
const crypto = require('node:crypto');
const { domainToASCII } = require('node:url');

function inboxKey(email, secret) {
  const s = String(email).normalize('NFKC').trim().toLowerCase();
  const at = s.lastIndexOf('@');
  if (at < 1) return null;
  let local = s.slice(0, at).replace(/\+.*$/, '');              // drop a +tag
  let domain = s.slice(at + 1).replace(/\.$/, '');
  domain = domainToASCII(domain) || domain;                      // IDN, fullwidth
  if (domain === 'googlemail.com') domain = 'gmail.com';
  if (domain === 'gmail.com') local = local.replace(/\./g, ''); // dots: gmail.com only
  return crypto.createHmac('sha256', secret).update(local + '@' + domain).digest('hex');
}

Victim.Name@gmail.com, v.i.c.t.i.m.n.a.m.e+news@GMAIL.com and victimname+a1b2@googlemail.com share one key; jane.doe@example.com and janedoe@example.com keep two. Maskbreak’s own mail budget folds case, tags and Gmail dots the same way and stores only keyed hashes.

Send one confirmation, then nothing

Double opt-in is the baseline (Google’s sender guidelines: “Confirm each recipient’s email address before subscribing them”), but not a defence on its own. Spamhaus found that confirmed opt-in “didn’t help much because the volume of confirmation emails alone was enough to cause a substantial problem”. Payer and Wüest add that “even with proper validation the first verification email can still be used to flood victims”. Make the confirmation the only email a stranger can cause:

  • One per inbox per window, counted with the folded key.
  • No reminders. A 2016 wave aimed at .gov addresses made Brian Krebs’s Gmail “basically useless” for most of a weekend, and even lists that did require confirmation “still send you additional emails reminding you to complete the signup process” (Krebs on Security, 18 August 2016).
  • Nothing else before the click, and unconfirmed signups expire.
  • The same on-screen answer whether the email was sent, capped or already subscribed, as OWASP asks of reset forms.

Check the sender before the email exists

The usual advice is a CAPTCHA (Spamhaus in 2016, the Swiss centre in 2026). It raises the cost, but solving services charge a fraction of a cent per CAPTCHA: 2Captcha listed reCAPTCHA v2 at $1 to $2.99 per 1,000 solves on 10 October 2026, or €0.99 to €2.80 when the page is viewed from Europe (2Captcha). How that trade works is in CAPTCHA farm economics. Payer and Wüest also tested AI browser agents that “can automate browser interactions and even assist with scaling and CAPTCHA solving”, though they saw no sign attackers used them yet.

A check on your server asks a different question: whether the browser is automated or tampered with, and whether it came through a proxy (bot detection without CAPTCHAs). Run it before the email is created and, in enforce mode, before the per-inbox slot is taken, so a blocked bot cannot spend the owner’s one confirmation.

With Maskbreak, the browser SDK on the form collects a network token and a device event, and your server sends both to POST /v1/evaluate. Its answers when the check flags each case, computed with Maskbreak’s response builder:

The API’s answer per submission, and what the gate below does in enforce mode
Submissiondecisionrisk_scorereasonsEnforce mode
Automated (headless) browser on a home connectionblock40automation_detected403, no email
The same browser on a cloud serverblock70datacenter_asn, automation_detected403, no email
Ordinary browser through a residential proxy tied to a known poolblock50proxy_detected403, no email
A person on a VPN, nothing else flaggedreview35vpn_detected409, no email
A person at home typing someone else’s real addressallow0noneOne confirmation
A script posting the form without loading the pageallow0none, with degraded: true409, held without a call

Design for the last row. A script that posts straight to your endpoint never runs your page, so it sends no browser token. The API accepts that as a degraded fallback and answers allow, saying nothing was measured:

Treat it as missing evidence. The handler in the integration guide, which the sample below follows, holds a submission with a missing browser field without calling the API in enforce mode, and holds review and degraded answers too. Watch mode, the default for a rollout, only logs, so the per-inbox cap must work from day one (rolling out without locking customers out).

A request replayed from a real visit carries that visit’s old token. evidence.network_age_s and evidence.device_age_s give each reading’s age in seconds, and evidence.device_replayed is true when the device check marked the event as a replay. Hold a send that is marked so, or whose readings are far older than a visit to your form takes.

A VPN on its own is review, not block, and so is Apple’s iCloud Private Relay (reason privacy_relay); network.service names the service when known. Answer both with a step that sends nothing, such as a challenge on the page.

What the check cannot tell is whose address was typed: a person entering someone else’s real address gets allow, so the per-inbox cap protects that inbox. The optional email field only flags disposable domains, and list bombing uses the victim’s real one (disposable email detection; for signups, stopping fake signups). The form, with the gate in front and the cap behind:

Node.js and Express, server only
const MASKBREAK_MODE = process.env.MASKBREAK_MODE || 'watch';

// The integration guide's gate as a function: null = go ahead, else [status, message].
async function senderHold({ token, fingerprintEventId, tz }) {
  const missing = !token || !fingerprintEventId;
  if (missing && MASKBREAK_MODE === 'enforce') return [409, 'Verification required.']; // no call
  try {
    const r = await fetch('https://maskbreak.com/v1/evaluate', {
      method: 'POST', signal: AbortSignal.timeout(5000),
      headers: { Authorization: 'Bearer ' + process.env.MASKBREAK_API_KEY, 'Content-Type': 'application/json' },
      body: JSON.stringify({ token, fingerprintEventId, tz })
    });
    const v = r.ok ? await r.json() : null;
    if (!v || !['allow', 'review', 'block'].includes(v.decision) || v.test || v.sample || v.sandbox) {
      throw new Error('No production verdict');
    }
    console.log('[maskbreak]', v.decision, v.reasons);
    if (v.decision === 'block') return [403, 'Request declined.'];
    if (missing || v.decision === 'review' || v.degraded || !v.device) return [409, 'Verification required.'];
    return null;
  } catch {
    return [503, 'Verification unavailable. Try again later.'];
  }
}

app.post('/subscribe', async (req, res) => {
  const { email, monocle, sentinel_fp, sentinel_tz } = req.body || {};
  if (!isValidEmail(email)) return res.status(400).json({ error: 'Enter a valid email address.' });
  const hold = await senderHold({ token: monocle, fingerprintEventId: sentinel_fp, tz: sentinel_tz });
  if (MASKBREAK_MODE === 'enforce' && hold) return res.status(hold[0]).json({ error: hold[1] });
  try {
    // One fixed-text confirmation per inbox per day. takeOnce: atomic set-if-absent
    // with expiry (in Redis, SET key 1 NX EX 86400).
    if (await counter.takeOnce('confirm:' + inboxKey(email, process.env.INBOX_KEY_SECRET), 86400)) {
      await sendConfirmation(email);
    }
  } catch (err) {
    console.error('[subscribe]', err.message); // a failed store or send is logged, not rethrown
  }
  return res.json({ message: 'Check your inbox to confirm.' }); // the same answer every time
});

Maskbreak’s Free plan includes 10,000 visitor checks a month with no credit card; paid plans start at €29 a month (pricing).

Never let the visitor write your email

If a form copies what the visitor typed into the mail it sends, the attacker writes your email and your domain signs it. In April 2026 BleepingComputer reported a phishing message split across the name fields of an Apple account and delivered inside Apple’s own account-change alerts, which passed SPF, DKIM and DMARC (BleepingComputer, 19 April 2026). So:

  • Receipts and confirmations are fixed text, with no name, company, message or subject the visitor typed; the full submission goes only to your own inbox.
  • A name that must appear, such as a team name in an invite, loses its links and control characters and fits on one short line.
  • One recipient per message, and no cc or bcc taken from the form.

Maskbreak’s own contact and public-interest receipts have been fixed text since 28 September 2026, never carrying the submitted name, organisation or message. Its invites drop http and www links and control characters from the organisation name, and its mail sender refuses any message with more than one recipient.

Keep a flood from silencing your own security mail

Hiding one security email is the point of many floods, so make sure yours still goes out. If signup confirmations, password resets and “your password was changed” notices share one sending budget, a flood through your signup form can spend it. Split it:

  • Signup codes, confirmations and receipts in their own pool (or pools), behind the per-inbox caps.
  • Password-reset and email-change codes in a pool of their own, limited per account, so a signup flood cannot cut a customer off from recovery; check both password-reset endpoints.
  • Security notices (password changed, two-factor turned off, new sign-in), where the first of each kind a person gets in a day is never held back by a full shared budget.
  • Marketing on its own, so it never drains the others.

Alert on the shape of an attack, such as one inbox getting confirmations again and again or a pool filling up, and answer the same way whether an address exists or a budget is full.

Maskbreak’s own mail is split this way. A signup flood from rotating addresses drains only the signup pool, never the separate pool for the password-reset and email-change codes that let a customer back in. The first critical notices of each kind a person gets in a day skip the shared ceilings, and a refused critical notice alerts Maskbreak’s operations inbox.

If your form was used in an email bombing

Count sends per folded inbox per hour to find when it started, stop reminders and drip mail to the unconfirmed addresses from that window, and let those signups expire. Tell your email provider. In 2016, Laura Atkins of Word to the Wise said, many email service providers asked their customers to tighten signup verification and comb their lists for recent signups matching the attack (Krebs on Security). Then put the per-inbox cap and the check in front of the next send.

Questions people ask

What is email bombing?
Email bombing is a flood of email aimed at one address so that the owner cannot use the inbox or misses one important message in it. Today the flood is often genuine mail: a script types the victim’s address into hundreds of newsletter, signup, password-reset and contact forms, and each site sends its own confirmation. It is also called subscription bombing, list bombing or mail bombing.
Why am I suddenly getting hundreds of subscription emails?
Someone has probably signed your address up to many sites at once. The flood is often cover for something else: a purchase, password change or bank transfer whose alert is buried in it, or a call, Teams or WhatsApp message from someone posing as IT support who offers to fix the spam and asks for remote access. Search for the hidden alert first, and give no one access to your computer because they contacted you about the spam.
What should I do if my inbox is being email bombed?
Do not delete everything. Search your inbox and spam folder for words such as password, payment, order and security; check your bank, card and shopping accounts in their own apps; and secure your email account if anything changed. Hang up on anyone who contacts you offering to fix the spam and call your IT team on a number you already know. Do not reply to the messages; once the flood stops, unsubscribe from lists that keep writing with your mail app’s own unsubscribe button.
How do I stop email bombing in Gmail or Outlook?
You cannot stop the senders: the flood ends when the attacker’s run does. Gmail warns you when it detects a mailbomb, inbox categories split the flood from the rest, and once you have found any hidden alert a search such as category:updates newer_than:1d finds the junk to filter or delete. Work and school Microsoft 365 mailboxes move a detected mail bomb to the Junk folder in Outlook. Filter into a folder rather than deleting by keyword, because the alert you are looking for may use the same words as the flood.
Should I unsubscribe from the emails?
Not while the flood is running, and never through links in messages you cannot vouch for. Once it stops, lists that really signed you up keep writing until you unsubscribe, so use your mail app’s own unsubscribe button for those. Do not reply to any of the messages.
Why doesn’t my spam filter stop email bombing?
Because the flood is mostly genuine mail: confirmations and welcomes from real companies whose mail servers are correctly set up, so the messages pass SPF and DKIM checks and filters treat each one as harmless. Some providers now detect the flood itself: Gmail warns you when it detects a mailbomb, and Microsoft 365 moves a detected mail bomb to the Junk folder.
How long does email bombing last?
It varies. Sophos described an employee who received over 3,000 messages in 45 minutes. A 2026 study of 24 attack waves found an average of 1,957 emails per wave and a largest wave of 4,847 in under two hours, and one bombing service the researchers examined sold attacks lasting from one hour to 31 days. Lists that really did sign you up keep sending until you unsubscribe.
Is email bombing illegal?
It can be. Attacking inboxes without consent is illegal in most jurisdictions, the authors of a 2026 study of email bombing note, and in England and Wales the High Court held in DPP v Lennon (2006) that the consent a mail owner gives to receiving email does not cover messages sent to interrupt the system. Laws differ between countries; keep a record of the flood and report it to your IT team, your bank and, if money moved, the police. This is not legal advice.
Does double opt-in stop list bombing?
Not on its own. Double opt-in stops the newsletters that would follow, but the confirmation email is itself the flood: in 2016 Spamhaus reported one company that saw nine addresses signed up over 9,000 times in two weeks, creating 81,000 confirmation emails, and found that confirmed opt-in did not help much. Send at most one confirmation per inbox per window, no reminders, and check the sender before the email is created.
How do I stop my website’s forms being used for email bombing?
Count sends per inbox rather than per IP address or per spelling of the address, send at most one confirmation and no reminders, check the submitter on your server before any email is created and hold the send when the browser evidence is missing, never put text the visitor typed into the email, and give password-reset and security mail its own sending budget so a flood cannot silence it.

Put the check where the attack enters

One call before signup, login or checkout returns decision, risk_score and the reasons behind them. The Free plan includes 10,000 visitor checks a month, no card required. Start with VPN detection and proxy detection, the network layer most attacks lean on.

Get started freeRead the API docs