How to Stop Spam Before It Starts
position: 15
Filtering spam is fighting the symptom. Almost all of it exists because an address was handed over at some point and then travelled further than intended. Cutting the supply is far more effective than sorting the output, and it takes less effort.
Where unwanted mail comes from
Signups you have forgotten. The dominant source. A tool you tried once, a shop from four years ago, a forum you posted in twice. Each of them is still sending, and each has your address on a list somewhere.
Lists that were sold or shared. Many privacy policies permit sharing with "partners", which is a category with no fixed size. One address given to one company becomes an address held by dozens.
Breaches. Company databases leak regularly and end up in collections that are traded, combined and mined. Your address, once in one, is in all of them permanently.
Scraping. An address published anywhere public, including in a forum post or on a personal page, is harvested within days.
Notice that all four start the same way: you gave an address to somebody. That is the point where the problem can still be prevented.
The four habits that matter
Never give a real address for a one time need. A download, a code, a discount, a wifi login. These are relationships that end in five minutes and should cost an address that ends in five minutes.
Use a different address for each significant service. If you use aliases, make them specific. When unwanted mail arrives at the alias you gave to exactly one company, you know precisely who leaked it, and you can shut that alias off without touching anything else.
Do not publish an address as text. Anywhere public, in any format. Scrapers find it faster than people do.
Treat unsubscribe links from unknown senders with suspicion. For a legitimate company, unsubscribing works and is the right move. For a spammer, it confirms a live human reads that address, which makes it more valuable, not less. If you never signed up, mark it as spam instead.
What to do about the mail you already get
The supply lines are open, so this part is repair rather than prevention.
Sort by sender in your mail client and look at the largest sources first. Unsubscribe from the ones you recognise and once agreed to. Block the ones you do not.
For anything important still arriving at a compromised address, change the address on that account to an alias before you do anything else. Then the old address can be allowed to rot.
Do not delete an old address that important services still use, at least not until you have moved them. A deleted address bounces, and a bouncing recovery address is how people lose accounts.
Where a disposable address fits
It fits the first habit exactly. When something demands an address for a transaction that will be over in a minute, a disposable address satisfies the form, delivers the code, and then removes itself from existence. There is no list it can end up on afterwards, because there is no address.
It does not fit the others. For services you keep, you need something that lasts, and that means an alias or your real address with a filter.
The realistic outcome
You will not get to zero. Addresses already leaked stay leaked, and some services you genuinely want will always send more than you would like.
What changes is the direction. Right now, every month adds new senders to the pile. With the habits above, the pile stops growing, and the existing one slowly becomes irrelevant as those addresses are retired.