Explainer

What Is a Spam Trap?

A spam trap is an email address that exists to catch senders with bad lists. Here is how the three types work and how to keep them out of your sends.

Get your free API key →Free to start. No credit card. 1,000 records to spend whenever you like.

A spam trap is an email address that no real person reads, kept to identify senders who collect addresses carelessly or never clean their lists. Mail sent to one is a signal about you, not a message to a person.

Hit one and your sender reputation drops. Hit several and your domain or IP can land on a blocklist. This page covers the three types, how a send reaches one, and where to stop it.

Key takeaways

  • A spam trap never opts in and never replies. Any mail it receives proves the sender got the address without permission or kept it too long.
  • There are three types: pristine (never valid), recycled (once valid, then abandoned) and typo (a misspelled domain).
  • You cannot spot a trap by looking at it. Verification and list hygiene are the defense.
  • LeadOcean carries spam_trap as an email_status value, and the default mailable set leaves it out.

What it is

A spam trap is an email address, run by a mailbox provider or anti-abuse group, that exists only to identify senders with poor list collection or maintenance.

Spamhaus names three categories: typo traps, recycled traps and pristine traps. It says recycled traps make up the majority, and that researchers use pristine traps to investigate abuse (Spamhaus, September 2026).

HubSpot describes the same three types. Pristine addresses were never valid and sit hidden in website code, which catches scrapers and list buyers. Recycled addresses were once real and were repurposed after being abandoned. Typo addresses are misspellings of common domains (HubSpot Knowledge Base, September 2026).

How it works

A trap only works because honest senders never reach it. A sender who emails a trap has shown that the address came from somewhere other than a consenting person.

  1. An operator creates or repurposes an address and keeps it silent. It signs up for nothing.
  2. The address lands in public view, in page code, or on a lapsed list, or it simply stays on an old list.
  3. A sender collects it by scraping, buying a list, or never removing a dead contact.
  4. The sender mails it. The operator records the sender's domain and IP.
  5. The operator or provider acts on the pattern: a lower reputation, spam folder placement, or a blocklist entry.

Worked example, with placeholder values: a team imports 5,000 addresses for Acme-style SaaS companies from a list bought three years ago. The import has typos such as jane@gmial.com and mailboxes abandoned in 2022.

code
send 5,000 addresses
  -> a small share hit abandoned mailboxes (recycled trap risk)
  -> a few hit misspelled domains (typo trap risk)
  -> your sequencer still shows "delivered" for most of them

The sequencer reports delivery because the server accepted the message. A trap accepts mail on purpose, so nothing in your dashboard flags the hit.

The damage shows up later, as lower inbox placement across the whole domain. That is why a trap hit is hard to trace back to one list or one campaign.

Spam trap vs hard bounce

A hard bounce tells you at once that an address is dead. A trap tells you nothing at once, which makes it the worse of the two.

Spam trapHard bounce
What the server doesAccepts the messageRefuses it with a 5xx code
Feedback to youNone, or a reputation drop laterAn immediate bounce record
Who runs the addressA provider or anti-abuse groupA real mailbox that is gone
What it signalsPoor list sourcing or upkeepA stale or mistyped address
Typical outcomeLower reputation, spam folder, blocklistHigher bounce rate
FixSource cleanly, verify, remove inactive contactsVerify and drop the address

Both come from the same root: addresses nobody confirmed. For the bounce side, read what a good bounce rate is.

When it matters

When you buy or scrape a list

This is where pristine traps live. An address hidden in page code is only found by a scraper, so any list built that way can hold one. Pick sources where each address has a stated origin. If a vendor cannot say where an address came from, assume the risk is yours.

When you mail an old list

Recycled traps grow with age. An address that was real two years ago can now be a trap. Re-verify any list you have not mailed in the last 6 to 12 months before it goes to a sequencer.

When your sequencer says green and Gmail says spam

A trap hit does not appear as a bounce, so a clean dashboard proves little. If placement falls while delivery looks fine, audit the list first. The steps are in your sequencer says green, Gmail says spam.

When you collect addresses through forms

Typo traps start at the form. A visitor mistypes a domain and nobody catches it. Add a confirmation step so only a clicked link puts an address on your list. Spamhaus points senders to confirmed opt-in and routine list hygiene as the fix (Spamhaus, September 2026).

How LeadOcean handles it

Every people record carries an email_status, and spam_trap is one of its 13 values. The emailStatus filter takes any of them.

By default, leadocean_count_leads counts only the mailable set: verified, catch_all_valid and catch_all. That set does not include spam_trap, so a default count never includes one. Passing emailStatus yourself replaces the default.

You can size the flagged group for free. Send count=true as a query parameter with limit=1, and the response carries meta.total with an empty data array (LeadOcean OpenAPI, September 2026).

bash
curl -X POST "https://api.leadocean.io/v1/people/search?count=true&limit=1" \
  -H "x-api-key: $LEADOCEAN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"emailStatus": ["spam_trap"]}'

On 2026-10-01, leadocean_count_leads returned 8,799 people with emailStatus set to spam_trap, worldwide, no other filters. That is a count by status, not a mailable count. The default mailable set on the same day was 124,786,586 people (verified, catch_all_valid, catch_all).

Treat spam_trap, invalid, abuse and disposable as do not send. Read email_status on every row you export. LeadOcean gives no refund or credit for bounced emails, so the check is yours to make.

No status removes every risk. A status describes the address on the day it was checked, and records refresh monthly. Mail a list again after six months and check it again first. The Exports page of the app at app.leadocean.io shows the record price before you start.

Pricing is two plans: Free (1,000 records, one-off, no card) and Pro at $499 a month. See pricing. More guides are in the blog hub. For the law side of cold email, see CAN-SPAM for cold email.

FAQ

What happens if I email a spam trap?

Your sender reputation can drop, your mail can go to spam, and your domain or IP can be added to a blocklist. HubSpot says a hit can trigger quarantine of the segment and suspension of sending on its platform (HubSpot, September 2026).

Can I tell which addresses are spam traps?

Not by looking. A trap looks like any other address. A verification status such as spam_trap flags known ones, and removing contacts that never engage catches the rest over time.

Are recycled traps as bad as pristine traps?

Pristine hits are usually read as the stronger signal, because the address was never real. Recycled hits point at stale lists. Spamhaus says recycled traps make up the majority, pristine traps a small share, and that trap hits indicate overall list hygiene (Spamhaus, September 2026).

Does a verified email guarantee I will not hit a trap?

No. Verification checks that a mailbox accepts mail. It cannot prove who runs the mailbox. Combine verified with a fresh list, confirmed opt-in where you collect addresses, and low volume on new domains.

How do I avoid spam traps in cold email?

Build lists from sources with a stated origin and send only to verified addresses. Re-verify old lists before a send, drop contacts that never engage, and keep your hard bounce rate low.

Filter spam traps out of your list before you send

Free to start. No credit card. 1,000 records to spend whenever you like.

Get your free API key →