Thousands of newsletter confirmations at once is rarely a spam problem. It is usually a smokescreen, and the first hour matters.
Do not mass delete, and do not click unsubscribe on anything. Search the flood first for the words payment, order, invoice, password, security and verification. Then open your bank and payment accounts directly, from a bookmark rather than from any email, and look for activity you did not authorize. The rest of this page explains why.
An automated script has entered one email address into thousands of newsletter signups, account registrations and mailing lists across the web. Every one of those sites does what it is supposed to do and sends a confirmation. The result arrives as a wall of mail in a very short window. Proofpoint has measured bursts running at more than 1,500 messages an hour.
The flood is not usually the point. It is cover. While the inbox is unusable, something else is arriving in it: a purchase receipt, a password reset, a bank alert, a security notification about a login. The attacker already has enough of the victim's details to do something with them, and the noise is there so the one message that would have raised the alarm is buried on page fourteen.
There is a follow-up pattern worth knowing about. Some groups use the flood as a pretext to make contact, phoning or messaging the victim through Teams or similar while posing as internal IT offering to fix the spam problem. The fix involves installing remote access software. If somebody contacts you offering help with a mail flood you have not reported to them, treat that as part of the attack.
This is not a rare curiosity. Switzerland's National Cyber Security Centre issued a public advisory on it in February 2026, and it is now the subject of academic study.
This is the part vendors tend to skip, so we will be direct about it. No spam filter reliably stops subscription bombing, including ours. Anyone selling you one on that basis is misrepresenting how the attack works.
The reason is that almost every message in the flood is genuine:
A filter that blocked those messages would also block the newsletters your staff actually asked for, from the same senders, on the same infrastructure. The signal that something is wrong is not in any single message. It is in the pattern across thousands of them.
The terms get used interchangeably and it causes real confusion when people go looking for a fix, because the two attacks have different defences.
| Classic mail bomb | Subscription bomb | |
|---|---|---|
| Where it comes from | One source, or a few | Thousands of unrelated legitimate senders |
| Authentication | Often fails | Passes, every time |
| Do rate controls help | Yes, this is what they are for | No, the volume per sender is normal |
| Usual motive | Disruption or harassment | Concealing a fraud already in progress |
SpyderMail's rate controls stop the first one. They will not stop the second, and neither will anyone else's.
Not by blocking the attack. By making it survivable.
The practical problem during a bombing is that the mailbox becomes unusable and the important message is invisible. A service sitting in front of your mail server gives you somewhere to search the whole flow from outside the flooded mailbox, per-user block lists so the same sources can be shut off for one person without affecting anyone else, and an administrator who can look at message logs across the domain rather than scrolling one inbox.
That is triage, not prevention, and we would rather describe it accurately. If the attack is happening to one of your users right now, the useful things we can do are help you search, help you identify what arrived alongside the flood, and get the account back to a workable state.
If you want the wider version of this argument, including when a second filtering layer is not worth paying for, we have written that up honestly. If you are on Microsoft 365, this page covers what you already have and how to configure it, which is free and worth doing first.
Call during office hours and speak to someone who has seen it before.