What Is Email Abuse? Types, Examples and How to Stop It

Email abuse is any use of email to deceive, harm or overload the people receiving it. That covers bulk spam, phishing, spoofed […]

Madhurendra SachanBy Madhurendra Sachan
March 22, 2021
7 min read
Updated October 4, 2026
What Is Email Abuse? Types, Examples and How to Stop It

Email abuse is any use of email to deceive, harm or overload the people receiving it. That covers bulk spam, phishing, spoofed senders, business email compromise, malware attachments, harassment and mail bombing. It exists because email was built to deliver almost anything to anyone, cheaply and instantly, with no built-in proof of who actually sent a message.

That design choice is still email’s greatest strength and its biggest weakness. Anyone can send a message to anyone else within seconds, at almost no cost. The same openness lets criminals send millions of fake invoices and login alerts for the price of a cheap server. This guide covers the main types of email abuse, why the protocol makes it easy, and what you can do about it as a person and as an organisation.

Why email is so easy to abuse

The protocol that moves mail between servers, SMTP, was designed in an era when the people on the network mostly knew each other. A sending server simply states who the message is from. Nothing in the original design checks that claim. The From line you see in your inbox is just text the sender typed.

Three things make abuse cheap:

  • No sender verification by default. Unless the receiving server checks SPF, DKIM and DMARC, a forged From address looks the same as a real one.
  • Near zero cost per message. A spammer pays roughly the same to send ten thousand messages as to send ten.
  • Disposable infrastructure. Domains, free webmail accounts and cloud servers can be set up in minutes and thrown away once they are blocked.

To combat abuse you have to add accountability back. On the legal side, laws such as the US CAN-SPAM Act set rules for commercial email and penalties for breaking them. On the technical side, sender authentication protocols give receiving servers a way to tell a forgery from an authentic message automatically.

The main types of email abuse

TypeWhat it looks likeMain risk
SpamUnsolicited bulk mail, often for dubious productsWasted time, a cover for scams and malware
PhishingA message posing as a bank, service or colleague that asks you to log in or payStolen passwords, card data and money
SpoofingA forged sender address or display nameMakes every other type more convincing
Business email compromiseA fake or hijacked executive or supplier account asking for a payment or a bank detail changeLarge one-off wire transfer losses
Malware deliveryAttachments or links that install ransomware, stealers or remote access toolsFull compromise of the device or network
Harassment and threatsAbusive or extortion messages, including fake sextortion claimsDistress, extortion payments
Mail bombingThousands of sign-up and newsletter messages sent to one inboxHides a real alert, such as a fraud warning from a bank
BackscatterBounce messages for mail you never sent, because someone forged your addressYour domain’s reputation suffers

Business email compromise is the most expensive of these for companies. The FBI’s Internet Crime Complaint Center logged 24,768 BEC complaints with reported losses of about $3.05 billion in 2025, according to its 2025 Internet Crime Report. We explain how forged senders and phishing combine in the difference between phishing and spoofing.

When your own domain is the one being abused

A lot of email abuse doesn’t target you as a recipient. It uses your name to target other people. Criminals send mail with your domain in the From line, or register a lookalike domain one letter off yours, and write to your customers, suppliers or staff. You often find out only when someone complains about an invoice you never sent, or when bounces for messages you never wrote start filling your inbox.

Signs that your domain is being abused:

  • Customers forward you messages “from” your company that you don’t recognise.
  • You receive non-delivery reports for mail nobody in your organisation sent.
  • Your DMARC aggregate reports show sending sources you can’t match to any service you use.
  • Your legitimate mail starts landing in spam folders more often.

If you get spam that seems to come from your own address, we cover the causes in why am I receiving spam email from my own address.

How to stop email abuse: what to do

If you run a domain

  1. Publish SPF listing every service that sends mail for you, including your CRM, ticketing and marketing tools.
  2. Sign outgoing mail with DKIM on each of those services.
  3. Publish DMARC, start at p=none to collect reports, fix anything legitimate that fails, then move to quarantine and finally reject. A reject policy tells receiving servers to refuse mail that falsely uses your domain.
  4. Meet the big mailbox providers’ rules. Since February 1, 2024, Google has required anyone sending more than 5,000 messages a day to Gmail accounts to set up SPF, DKIM and DMARC, offer one-click unsubscribe and keep reported spam rates below 0.3%, per its email sender guidelines.
  5. Watch for lookalike domains. DMARC only protects the domains you own. Mail from a lookalike domain passes its own checks, so it has to be found and taken down at the registrar and host. That is what a takedown service does.
  6. Staff an abuse@ mailbox. RFC 2142 reserves abuse@ as the standard address for reporting misuse, and other providers will use it to tell you about problems.

If you receive abusive mail

  • Don’t reply, click links or open attachments in a message you didn’t expect.
  • Use your mail client’s “report spam” or “report phishing” button. It trains filters for everyone on that service.
  • Check the real sender domain, not just the display name.
  • If a message asks for a payment or a change to bank details, confirm it by phone using a number you already have.
  • In India, report fraud attempts on the National Cyber Crime Reporting Portal at cybercrime.gov.in or call 1930 if money has already moved.
  • If the mail is threatening or extortionate, keep it, including the full headers, and report it to the police rather than deleting it.

How email providers fight abuse behind the scenes

Large mailbox providers combine several layers: authentication checks (SPF, DKIM and DMARC), reputation scores for sending IPs and domains, content and attachment scanning, and signals from millions of users pressing “report spam”. Senders who keep complaint rates high or skip authentication see their mail throttled or rejected. That is why a company with weak authentication can find its genuine invoices in spam folders while criminals are busy impersonating it.

Blocklists play a part too. Organisations such as Spamhaus publish lists of IP addresses and domains seen sending abuse, and many servers refuse mail from listed sources. If your own server ends up on one, it usually means a compromised account or a misconfigured form is being used to send spam.

FAQ

What counts as email abuse?

Email abuse is any use of email that deceives, harms or overloads recipients. The common forms are spam, phishing, spoofed senders, business email compromise, malware attachments, harassment and mail bombing. It also includes criminals using your domain or a lookalike of it to send mail to your customers or staff without your permission.

Is spam the same as phishing?

No. Spam is unsolicited bulk mail, usually advertising something. Phishing is a targeted scam that tries to get you to hand over a password, card details or money, or to open malware. Many phishing messages arrive the way spam does, in bulk, but the goal is fraud rather than selling something.

How do I report email abuse?

Use the report spam or report phishing button in your mail client first. Send a copy with full headers to the abuse@ address of the sending provider. In India, report fraud attempts on cybercrime.gov.in, and call 1930 at once if money has been lost. Companies should also file a takedown request for any lookalike domain involved.

Can DMARC stop all email abuse?

No. DMARC stops other people sending mail that uses your exact domain in the From line, once your policy is set to reject. It doesn’t stop spam in general, lookalike domains, hijacked mailboxes or free webmail accounts with your brand in the display name. Those need monitoring, user reporting and takedowns.

Want to learn more about protecting your organization?

Talk to a TIKAJ security expert and discover how our platform can help secure your digital ecosystem.

Get in Touch