Subscription Bombing: Why Your Spam Filter Did Not Stop It

Thousands of newsletter confirmations at once is rarely a spam problem. It is usually a smokescreen, and the first hour matters.

If this is happening right now

Do not mass delete, and do not click unsubscribe on anything. Search the flood first for the words payment, order, invoice, password, security and verification. Then open your bank and payment accounts directly, from a bookmark rather than from any email, and look for activity you did not authorize. The rest of this page explains why.

What Is Actually Happening

An automated script has entered one email address into thousands of newsletter signups, account registrations and mailing lists across the web. Every one of those sites does what it is supposed to do and sends a confirmation. The result arrives as a wall of mail in a very short window. Proofpoint has measured bursts running at more than 1,500 messages an hour.

The flood is not usually the point. It is cover. While the inbox is unusable, something else is arriving in it: a purchase receipt, a password reset, a bank alert, a security notification about a login. The attacker already has enough of the victim's details to do something with them, and the noise is there so the one message that would have raised the alarm is buried on page fourteen.

There is a follow-up pattern worth knowing about. Some groups use the flood as a pretext to make contact, phoning or messaging the victim through Teams or similar while posing as internal IT offering to fix the spam problem. The fix involves installing remote access software. If somebody contacts you offering help with a mail flood you have not reported to them, treat that as part of the attack.

This is not a rare curiosity. Switzerland's National Cyber Security Centre issued a public advisory on it in February 2026, and it is now the subject of academic study.

Why Your Spam Filter Let It Through

This is the part vendors tend to skip, so we will be direct about it. No spam filter reliably stops subscription bombing, including ours. Anyone selling you one on that basis is misrepresenting how the attack works.

The reason is that almost every message in the flood is genuine:

  • They come from real marketing platforms with good reputations, the same ones your legitimate suppliers use.
  • They authenticate correctly. SPF passes, DKIM passes, DMARC passes, because the sending platform is genuinely authorized to send for its own domain.
  • The content is a normal confirmation email. No forged sender, no malware, no malicious link, nothing for a content scanner to object to.
  • Each individual message really is a valid response to a form submission. The form was submitted. Just not by you.

A filter that blocked those messages would also block the newsletters your staff actually asked for, from the same senders, on the same infrastructure. The signal that something is wrong is not in any single message. It is in the pattern across thousands of them.

A Mail Bomb and a Subscription Bomb Are Not the Same Thing

The terms get used interchangeably and it causes real confusion when people go looking for a fix, because the two attacks have different defences.

Classic mail bomb Subscription bomb
Where it comes from One source, or a few Thousands of unrelated legitimate senders
Authentication Often fails Passes, every time
Do rate controls help Yes, this is what they are for No, the volume per sender is normal
Usual motive Disruption or harassment Concealing a fraud already in progress

SpyderMail's rate controls stop the first one. They will not stop the second, and neither will anyone else's.

What to Do, in Order

In the first hour

  • Search before you delete. Look for payment, order, invoice, receipt, password, security, verification, and the names of your bank and card providers. Whatever the attacker was hiding is in there.
  • Check accounts directly. Banking, payment processors, e-commerce, domain registrar and anything holding a card. Use your own bookmarks, never a link from the flood.
  • Change passwords and confirm MFA on anything the address is used to log into, starting with the mailbox itself.
  • Do not click unsubscribe links in the flood. Most are genuine, but you cannot tell which are not, and it confirms the address is live.
  • Distrust unsolicited help. Anyone who contacts you about the flood before you reported it is suspect.

Once the flood subsides

  • Work out what the cover was for. The attack was an expense to somebody. Something was worth hiding.
  • Sort by sender, not by date, when clearing up. It makes bulk removal safe and leaves genuine mail visible.
  • Check your own signup forms. If your website has a newsletter form with no CAPTCHA and no double opt-in, your infrastructure can be conscripted into doing this to somebody else.
  • Consider a second address for financial accounts, one that is not published anywhere and is not used for anything else.

Where a Filtering Service Does Help

Not by blocking the attack. By making it survivable.

The practical problem during a bombing is that the mailbox becomes unusable and the important message is invisible. A service sitting in front of your mail server gives you somewhere to search the whole flow from outside the flooded mailbox, per-user block lists so the same sources can be shut off for one person without affecting anyone else, and an administrator who can look at message logs across the domain rather than scrolling one inbox.

That is triage, not prevention, and we would rather describe it accurately. If the attack is happening to one of your users right now, the useful things we can do are help you search, help you identify what arrived alongside the flood, and get the account back to a workable state.

If you want the wider version of this argument, including when a second filtering layer is not worth paying for, we have written that up honestly. If you are on Microsoft 365, this page covers what you already have and how to configure it, which is free and worth doing first.

Dealing With This Now?

Call during office hours and speak to someone who has seen it before.


Contact Us