Inbox
Home

Spam, privacy and email security

Email Spam, Privacy & Security: What Your Email Address Can Expose

Understand how email exposure turns into spam, tracking, phishing, breach risk and account-security problems, then learn which protections address each threat.

An email address is not dangerous by itself, and every unwanted message does not come from the same source. The useful security model is a chain: an address can be exposed, harvested or reused; messages can track or deceive; breached data can be combined with other information; and a compromised mailbox can affect accounts that rely on it for recovery. This knowledge center separates those mechanisms so each problem gets the right response.

Follow the threat, not the buzzword

Start with the symptom you actually have—spam, tracking, a suspicious message, a breach notice or an account-security concern—and move into the mechanism behind it. Related KC02 guides cover everyday address choices; KC03 owns the deeper security and privacy mechanics.

Spam mechanics & address harvesting

Email tracking & inbox privacy

How Do Email Tracking Pixels Work?

Email tracking pixels record a remote-image request that can be treated as an open signal, but modern mail proxies, privacy features and image blocking make that signal less precise than it looks.

Read guide

What Can Email Senders See When You Open a Message?

Senders may receive open, timing, network or device signals when remote content loads, but what they actually learn depends heavily on the mail client, proxies, privacy settings and separate click tracking.

Read guide

Can an Email Reveal Your IP Address?

An email can expose an IP-related signal in some reading paths, but modern image proxies and privacy relays often hide the reader's direct address. The answer depends on how remote content is loaded.

Read guide

How Do Tracked Links in Emails Work?

Tracked email links commonly route a click through a measurement URL before sending you to the final destination. That redirect can record which link was clicked and when.

Read guide

Read Receipts vs Tracking Pixels: What Is the Difference?

A read receipt is an explicit mail feature that can ask for or report confirmation, while a tracking pixel silently relies on a remote-content request. They measure different things and offer different levels of user control.

Read guide

Does Blocking Images Stop Email Tracking?

Blocking remote images can stop many pixel-based open requests until you choose to load them, but it does not stop tracked links, explicit read receipts or tracking that happens after you visit a website.

Read guide

Phishing, spoofing & malicious email

Spam vs Phishing: What's the Difference?

Spam is mainly unsolicited bulk messaging; phishing is deception designed to make you reveal information, install malware or take a harmful action. A message can be both.

Read guide

How Do Phishing Emails Work?

Phishing emails manufacture trust or urgency so the recipient takes an action the attacker needs: opening a fake login page, sharing a code, downloading a file or sending money.

Read guide

What Is Email Spoofing? How Forged Sender Addresses Work

Email spoofing forges sender information so a message appears to come from a trusted domain. It is different from lookalike domains, display-name impersonation and compromised real accounts.

Read guide

How to Verify Who Really Sent an Email

Verify an email sender by separating display name, full address, domain, Reply-To, message context and authentication results, then confirm sensitive requests through an independent channel.

Read guide

How to Check an Email Link Before Clicking It

Check the real destination, hostname and context of an email link, but for sensitive account actions the safest path is often to avoid the link and navigate to the service independently.

Read guide

When Is an Email Attachment Safe to Open?

No attachment can be declared safe from appearance alone. Judge the sender, whether the file was expected, the file type, the request around it and whether you can verify the document another way.

Read guide

What Is Credential Phishing?

Credential phishing is a phishing attack designed to steal login secrets such as usernames, passwords, verification codes or other authentication material by sending the victim to a fake or deceptive sign-in flow.

Read guide

Clicked a Phishing Link? What to Do Next

What to do after clicking a phishing link depends on what happened next: whether you only opened the page, entered credentials, downloaded a file, approved MFA or shared financial information.

Read guide

Data breaches, leaks & data brokers

What Does It Mean If Your Email Was in a Data Breach?

A breached email address means the address appeared in an exposed dataset. The real risk depends on what else was exposed with it—especially passwords, identity data, phone numbers or payment information.

Read guide

How Do Leaked Email Addresses Get Reused After a Data Breach?

A leaked email address can persist in breach, spam and enrichment datasets long after the original incident. The risk grows when it is paired with passwords, names or other identifiers.

Read guide

Do Data Brokers Have Your Email Address?

Some data brokers collect and sell email addresses, but you cannot infer that every broker has yours. The answer depends on the broker's sources, your exposure and whether their records can be matched to you.

Read guide

How Do Data Brokers Get Your Email Address?

Data brokers can obtain email addresses and other personal information indirectly from businesses, datasets and other sources. The exact source varies by broker, jurisdiction and record.

Read guide

How to Remove Your Email Address From Data Brokers

Removing an email address from data brokers is a jurisdiction- and broker-specific process. Use official privacy requests where available, document the request and expect matching and deletion rules to vary.

Read guide

Should You Change Your Email Address After a Data Breach?

Changing an email address is not automatically the first or best response to a breach; the right action depends on whether the breach exposed only the address, a password, account access or more sensitive personal data.

Read guide

Protecting your email account

Why Is Your Email Account a Master Key to Other Accounts?

Your mailbox is often the recovery channel for other services. If someone controls it, they may be able to reset passwords, intercept security notices and impersonate you to trusted contacts.

Read guide

What Happens If Your Email Account Gets Hacked?

A hacked mailbox can expose messages, reset links, contacts and recovery flows for other accounts. Recovery should include password changes, session review, forwarding-rule checks, MFA and recovery-setting cleanup.

Read guide

How to Secure Your Email Account Without Relying on One Setting

A secure email account combines strong authentication, unique credentials, clean recovery settings, session review and careful treatment of forwarding rules because the mailbox often controls recovery for other accounts.

Read guide

Why Does Your Email Account Need a Unique Password?

A unique email password prevents a password stolen from another site from becoming a direct login attempt against your mailbox. Password reuse is what turns unrelated breaches into credential-stuffing risk.

Read guide

2FA vs Passkeys for Email Security: Which Protects You Better?

Traditional 2FA adds a second barrier after a password, while FIDO2 passkeys replace the reusable password login with phishing-resistant public-key authentication. Both improve security, but they resist different attack paths.

Read guide

How Recovery Email Protects an Account — and When It Becomes a Risk

A recovery email can restore access when normal sign-in fails, but it also becomes part of the account's authentication chain, so stale or weak recovery addresses can create a hidden dependency.

Read guide

Credential Stuffing and Email Accounts: How One Breach Spreads to Other Logins

Credential stuffing uses stolen username-and-password pairs from one breach against other sites. Because usernames are often email addresses, password reuse turns an exposed credential into a cross-account risk.

Read guide

Email identity & exposure