More than 376 billion emails are sent worldwide every day, nearly half of which are unsolicited messages that should never have reached recipients' inboxes (Statista study, 2025).
In the age of artificial intelligence, email spam has become a serious threat to data security, finances, and privacy. What is spam, what forms does it take, and how can you effectively defend against it? We answer!
Spam definition – what does this concept mean?
Spam is an electronic message sent to a recipient who has not consented to receiving it, usually of an advertising or fraudulent nature.
Spam is typically associated with mass mailings sent to thousands of addresses simultaneously, but this isn't a necessary condition – spam also includes messages directed at individuals, such as spear phishing or BEC (Business Email Compromise) attacks, in which the perpetrator impersonates a specific colleague or manager. While spam is most often associated with email, unsolicited messages also appear in text messages, instant messaging applications, and on social media.
(The rest of the article can be found below the form)
The very word "spam" as a synonym for unwanted messages is owed to the British comedy group Monty Python. In one of their sketches, a restaurant waitress lists dishes, almost every one of which contains SPAM-brand canned meats – repeated so insistently that they drown out the rest of the conversation. This association perfectly captures the nature of spam messages: they are ubiquitous, repetitive, and difficult to ignore.
New regulations for e-marketing – unification of rules within the E-marketing Act
What does this issue look like from a legal perspective? Since November 10, 2024, the Electronic Communications Law (ECL) has been in force in Poland. Article 398 of the Law unifies the rules regarding electronic marketing, taking them from the repealed Article 10 of the Act on the Provision of Services by Electronic Means and Article 172 of the former Telecommunications Law.
Sending unsolicited commercial information without the recipient's prior, express consent (in both B2C and B2B relationships) constitutes a violation of the law and an act of unfair competition. In addition to the GDPR, personal data protection regulations also apply, and fines for violations can reach up to 3% of the entity's revenue or PLN 1 million.
Types of spam – from advertisements to cyberattacks
Spam comes in many forms, each carrying different risks. It's worth understanding the different types to understand what you might encounter in your everyday electronic communications.
Advertising spam
This is the most common variety. It includes mass-mailed offers of products, services, dietary supplements, and quick-money schemes. According to data from 2025, marketing and advertising content accounts for approximately 36% of all spam (SQ Magazine, September 2025). While it doesn't contain malware itself, it can effectively clog your inbox and make it difficult to find important messages.
Phishing
Phishing is an attempt to obtain confidential data—logins, passwords, and payment card numbers—by impersonating trusted institutions. Fake messages imitate communications from banks, courier companies, or service providers, with the goal of persuading the recipient to click a link leading to a fake website.
According to the Anti-Phishing Working Group, 4,8 million phishing attacks were recorded in 2024. The trend intensified in 2025, as criminals began to massively use generative AI to create phishing emails. Hoxhunt data (Phishing Trends Report, 2026) shows that by the end of 2025, the share of AI-generated phishing had increased fourteen-fold – from less than 5% to 56% of detected attacks in just one month.
Malspam
Malspam, or spam containing malware, uses attachments—most often PDF files with malicious links or QR codes, or documents with macros—to direct victims to infected websites or trick them into downloading malicious files. The PDF file itself doesn't automatically install malware, but the embedded link or QR code leads to a page that can infect a device with a virus, Trojan, ransomware, or spyware.
Scam – email scams
Classic scams include messages about supposed lottery winnings, inheritances from distant countries, or requests for financial assistance. Their common feature is the application of emotional pressure—a sense of sudden opportunity or threat—to induce the recipient to act hastily and thoughtlessly.
Social media spam
Unwanted content also appears outside the inbox: as mass comments on posts, fake private messages on Facebook, Instagram, or LinkedIn, and bots posting links to suspicious websites. Social media accounts for approximately 9,8% of spam encounters (EmailToolTester, 2025).
Vishing and smishing
Spam isn't limited to written forms. Vishing (voice phishing) refers to telephone scams in which the caller pretends to be a bank employee, for example. Smishing, on the other hand, is phishing carried out via text message.
Spam in numbers – the scale of the problem
According to Kaspersky's 2025 Annual Report, spam accounted for 44,99% of global email traffic, which, with 376 billion emails per day, translates to approximately 169–176 billion spam messages each day. While the percentage of spam has declined in recent years, its absolute volume continues to grow as the overall volume of emails sent grows even faster.
Artificial intelligence is another factor driving the problem. Research by IBM X-Force, the cybersecurity division of IBM, found that AI tools can create a convincing phishing email in five minutes, compared to an average of 16 hours for an experienced human.
Artificial intelligence in phishing – the growing scale of threats and billions of dollars in losses
According to the Verizon DBIR report (2026 edition), the amount of AI-generated text in malicious emails has doubled year-over-year, and the Hoxhunt Phishing Trends report (2026) shows that by the end of 2025, the share of AI-generated phishing had increased fourteen-fold in just one month. Global phishing losses are now estimated at $25 billion annually (SentinelOne, 2026). This means that the traditional advice of "watch out for spelling errors" is becoming obsolete, as AI-generated emails are grammatically flawless and stylistically polished.
How to block spam?
While it's impossible to completely eliminate spam, adopting the right habits and tools can significantly reduce the number of unwanted messages. Here are some proven ways to block spam.
Configuring filters in the mailbox
Modern cloud-based email services like Gmail and Microsoft 365 (Outlook) are equipped with advanced server-side spam filters. Google claims to block nearly 10 million spam messages per minute, which translates to approximately 15 billion per day (Google Safety Center).
Regardless of the tool you use, it's a good idea to manually mark messages that slip through the automatic filter as spam – this way, the algorithm learns to recognize similar messages in the future. If you use your own email domain, be sure to configure SPF, DKIM, and DMARC records, which help servers verify the sender's authenticity.
Be careful when sharing your email address
One of the simplest rules to help prevent spam is to limit the number of times you share your email address. Avoid posting it on forums, comments, or social media, where automated bots can collect it. If you must provide an address for a one-time registration, consider using an email alias or temporary mailbox—this will keep your primary address free from unwanted messages.
Two-factor authentication (2FA)
Even if login credentials are leaked in a phishing attack, two-factor authentication provides an additional barrier to criminals. Apps like Google Authenticator and FIDO2 hardware keys are more secure than codes sent via SMS because they are not vulnerable to SIM swap attacks.
It's worth remembering that in 2024, adversary-in-the-middle (AiTM) attacks emerged, which can bypass multi-factor authentication methods based on one-time codes or browser sessions. The FIDO2/WebAuthn standard remains resistant to this type of threat, so wherever possible, physical keys or passkeys should be used, i.e., biometric login or device PIN, without the need to enter a password.
Regular updates and security software
Keeping your operating system, browser, and email client up-to-date closes the gaps exploited by malware sent via spam. It's also a good idea to use an antivirus program with an anti-phishing module, which blocks suspicious links and attachments before users can open them.
How do I get rid of spam that is already in my inbox?
If unwanted emails appear regularly despite filters, take a few steps to clean up your inbox. First, review your subscriptions—many messages that appear to be spam are actually newsletters you previously subscribed to.
How to Effectively Fight Spam? 3 Key Rules
Unsubscribe from emails you no longer need. Second, report spam to your email provider using the "Report Spam" or "Mark as Spam" buttons—this helps improve filters for all users of that service. Third, never respond to spam emails or click unsubscribe links if the sender is unknown. Clicking on unsubscribe links only confirms that your email address is active, which could worsen the problem.
Spam and the corporate mailbox
For businesses, email spam is not just a matter of convenience but also a real financial risk. As mentioned, phishing costs the global economy approximately $25 billion annually, and the average cost of a single phishing-related data breach is $4,88 million (IBM, Cost of a Data Breach Report, 2025).
For this reason, companies should implement an email security policy that includes employee training, phishing resistance testing (simulated campaigns), and multi-level email filtering at the server level.
Spam won't disappear, but effective defense is possible
Spam has accompanied internet users since its inception, but with the development of generative AI, it is entering a new phase. Messages are increasingly difficult to distinguish from authentic correspondence, so passive defenses (automatic filters alone) are no longer sufficient.
Effective protection requires a combination of technical tools—spam filters, SPF/DKIM/DMARC protocols, and two-factor authentication—with regular education and a healthy skepticism toward every unexpected message. Blocking spam isn't a one-time action, but an ongoing process that should be considered a permanent part of digital hygiene.
Spam FAQs
Spam is an unsolicited electronic message, typically of an advertising or fraudulent nature, that reaches the recipient without their explicit consent. It includes both mass mailings and precisely targeted attacks on specific individuals (e.g., spear phishing). It appears in emails, text messages, and even on social media.
We owe this term to the British group Monty Python. In one of their sketches, the persistent repetition of the name of a canned meat product called "SPAM" drowned out the entire conversation—perfectly capturing the ubiquitous, repetitive, and difficult-to-ignore nature of unwanted messages.
The article highlights, among others:
- Advertising spam: intrusive commercial offers.
- Phishing: attempts to obtain confidential data (e.g. passwords, card numbers).
- Malspam: messages containing malware in attachments or links.
- Scam: various types of email scams (e.g. requests for financial assistance).
- Vishing and smishing: unwanted and fraudulent voice calls and text messages.
Yes. Under the Electronic Communications Law (ECL) introduced in November 2024 and the GDPR, sending unsolicited commercial information without the recipient's consent is a violation of the law. It carries significant penalties – up to PLN 1 million or up to 3% of the company's annual revenue.
The most important protection methods include:
- Appropriate configuration of anti-spam filters in the mailbox.
- Exercise extreme caution and do not share your email address in public places.
- Using two-factor authentication (2FA).
- Regularly updating your system and using protective (antivirus) software.
Summary
The above article covers the following topics:
- Spam is common, unwanted and often dangerous electronic messages that are prohibited by law from being sent without the recipient's consent.
- Spam comes in many different forms, from intrusive advertisements to extremely dangerous scams and cyberattacks.
- The huge scale of spam continues to grow, and artificial intelligence makes it even faster, more accurate, and more dangerous.
- Effective spam mitigation requires being careful about sharing your email address, using filters and account security, and ignoring suspicious messages.
- Effectively defending companies against evolving spam requires a continuous combination of technical security measures and employee education.