A spam trap is an email address that no real person reads, kept to identify senders who collect addresses carelessly or never clean their lists. Mail sent to one is a signal about you, not a message to a person.
Hit one and your sender reputation drops. Hit several and your domain or IP can land on a blocklist. This page covers the three types, how a send reaches one, and where to stop it.
Key takeaways
- A spam trap never opts in and never replies. Any mail it receives proves the sender got the address without permission or kept it too long.
- There are three types: pristine (never valid), recycled (once valid, then abandoned) and typo (a misspelled domain).
- You cannot spot a trap by looking at it. Verification and list hygiene are the defense.
- LeadOcean carries
spam_trapas anemail_statusvalue, and the default mailable set leaves it out.
What it is
A spam trap is an email address, run by a mailbox provider or anti-abuse group, that exists only to identify senders with poor list collection or maintenance.
Spamhaus names three categories: typo traps, recycled traps and pristine traps. It says recycled traps make up the majority, and that researchers use pristine traps to investigate abuse (Spamhaus, September 2026).
HubSpot describes the same three types. Pristine addresses were never valid and sit hidden in website code, which catches scrapers and list buyers. Recycled addresses were once real and were repurposed after being abandoned. Typo addresses are misspellings of common domains (HubSpot Knowledge Base, September 2026).
How it works
A trap only works because honest senders never reach it. A sender who emails a trap has shown that the address came from somewhere other than a consenting person.
- An operator creates or repurposes an address and keeps it silent. It signs up for nothing.
- The address lands in public view, in page code, or on a lapsed list, or it simply stays on an old list.
- A sender collects it by scraping, buying a list, or never removing a dead contact.
- The sender mails it. The operator records the sender's domain and IP.
- The operator or provider acts on the pattern: a lower reputation, spam folder placement, or a blocklist entry.
Worked example, with placeholder values: a team imports 5,000 addresses for Acme-style SaaS companies from a list bought three years ago. The import has typos such as jane@gmial.com and mailboxes abandoned in 2022.
send 5,000 addresses
-> a small share hit abandoned mailboxes (recycled trap risk)
-> a few hit misspelled domains (typo trap risk)
-> your sequencer still shows "delivered" for most of themThe sequencer reports delivery because the server accepted the message. A trap accepts mail on purpose, so nothing in your dashboard flags the hit.
The damage shows up later, as lower inbox placement across the whole domain. That is why a trap hit is hard to trace back to one list or one campaign.
Spam trap vs hard bounce
A hard bounce tells you at once that an address is dead. A trap tells you nothing at once, which makes it the worse of the two.
| Spam trap | Hard bounce | |
|---|---|---|
| What the server does | Accepts the message | Refuses it with a 5xx code |
| Feedback to you | None, or a reputation drop later | An immediate bounce record |
| Who runs the address | A provider or anti-abuse group | A real mailbox that is gone |
| What it signals | Poor list sourcing or upkeep | A stale or mistyped address |
| Typical outcome | Lower reputation, spam folder, blocklist | Higher bounce rate |
| Fix | Source cleanly, verify, remove inactive contacts | Verify and drop the address |
Both come from the same root: addresses nobody confirmed. For the bounce side, read what a good bounce rate is.
When it matters
When you buy or scrape a list
This is where pristine traps live. An address hidden in page code is only found by a scraper, so any list built that way can hold one. Pick sources where each address has a stated origin. If a vendor cannot say where an address came from, assume the risk is yours.
When you mail an old list
Recycled traps grow with age. An address that was real two years ago can now be a trap. Re-verify any list you have not mailed in the last 6 to 12 months before it goes to a sequencer.
When your sequencer says green and Gmail says spam
A trap hit does not appear as a bounce, so a clean dashboard proves little. If placement falls while delivery looks fine, audit the list first. The steps are in your sequencer says green, Gmail says spam.
When you collect addresses through forms
Typo traps start at the form. A visitor mistypes a domain and nobody catches it. Add a confirmation step so only a clicked link puts an address on your list. Spamhaus points senders to confirmed opt-in and routine list hygiene as the fix (Spamhaus, September 2026).
How LeadOcean handles it
Every people record carries an email_status, and spam_trap is one of its 13 values. The emailStatus filter takes any of them.
By default, leadocean_count_leads counts only the mailable set: verified, catch_all_valid and catch_all. That set does not include spam_trap, so a default count never includes one. Passing emailStatus yourself replaces the default.
You can size the flagged group for free. Send count=true as a query parameter with limit=1, and the response carries meta.total with an empty data array (LeadOcean OpenAPI, September 2026).
curl -X POST "https://api.leadocean.io/v1/people/search?count=true&limit=1" \
-H "x-api-key: $LEADOCEAN_API_KEY" \
-H "Content-Type: application/json" \
-d '{"emailStatus": ["spam_trap"]}'On 2026-10-01, leadocean_count_leads returned 8,799 people with emailStatus set to spam_trap, worldwide, no other filters. That is a count by status, not a mailable count. The default mailable set on the same day was 124,786,586 people (verified, catch_all_valid, catch_all).
Treat spam_trap, invalid, abuse and disposable as do not send. Read email_status on every row you export. LeadOcean gives no refund or credit for bounced emails, so the check is yours to make.
No status removes every risk. A status describes the address on the day it was checked, and records refresh monthly. Mail a list again after six months and check it again first. The Exports page of the app at app.leadocean.io shows the record price before you start.
Pricing is two plans: Free (1,000 records, one-off, no card) and Pro at $499 a month. See pricing. More guides are in the blog hub. For the law side of cold email, see CAN-SPAM for cold email.
FAQ
What happens if I email a spam trap?
Your sender reputation can drop, your mail can go to spam, and your domain or IP can be added to a blocklist. HubSpot says a hit can trigger quarantine of the segment and suspension of sending on its platform (HubSpot, September 2026).
Can I tell which addresses are spam traps?
Not by looking. A trap looks like any other address. A verification status such as spam_trap flags known ones, and removing contacts that never engage catches the rest over time.
Are recycled traps as bad as pristine traps?
Pristine hits are usually read as the stronger signal, because the address was never real. Recycled hits point at stale lists. Spamhaus says recycled traps make up the majority, pristine traps a small share, and that trap hits indicate overall list hygiene (Spamhaus, September 2026).
Does a verified email guarantee I will not hit a trap?
No. Verification checks that a mailbox accepts mail. It cannot prove who runs the mailbox. Combine verified with a fresh list, confirmed opt-in where you collect addresses, and low volume on new domains.
How do I avoid spam traps in cold email?
Build lists from sources with a stated origin and send only to verified addresses. Re-verify old lists before a send, drop contacts that never engage, and keep your hard bounce rate low.
Filter spam traps out of your list before you send
Free to start. No credit card. 1,000 records to spend whenever you like.
Get your free API key →