What is a pristine spam trap?

Pristine spam trap, defined
A pristine spam trap is an address created purely as bait, never owned by a person and never used to sign up for anything, so any mail arriving at it was obtained without consent.

Anti-spam organizations and mailbox providers plant them where only a harvester would look: hidden in page markup, in old forum posts, on abandoned domains they bought. Nobody types them into a form, because nobody knows they exist.

The moment one receives mail, the sender has proven something about their collection practice. That is the entire design. There is no complaint to weigh and no engagement history to consider.

Detection would require knowing which mailboxes belong to no one, and the protocol has no field for that. Every probe you can run returns the same friendly 250 a real inbox returns.

The only defense runs before the list exists. Addresses you collected yourself, with a confirmation click, carry almost no trap risk. Scraped and purchased data carries it structurally.

How ZapBounce reports it

We return no verdict called trap, and we make no claim to find these. If you see a vendor advertising pristine-trap removal, ask what protocol response they think identifies one. There isn't one.

How one scraped page poisons a list

Say a contractor offers you 25,000 contacts in your industry, gathered by crawling company websites and directories. Somewhere in that crawl was a page with an address in the HTML that no visitor could see: white text, a hidden element, or a mailto link inside a comment. A person browsing the page never meets it, but the crawler picks it up.

You verify the file. The trap address has a working domain, a real mail server and a mailbox that answers 250 and refuses a made-up neighbor, so it comes back valid. Every check did its job correctly. The address is real, and what's missing is the owner.

Then you send, and the operator's system records that your domain mailed an address which has never been given to anyone. There's no bounce for you to see and no complaint in your dashboard. The consequence arrives later as filtering or a listing.

Pristine trap or typo trap: only one can be caught

People often group a third kind of trap with pristine ones. Typo traps live on misspelled versions of big provider domains, the sort of thing you get when someone types the letters of gmail or hotmail in the wrong order. Some of those domains are registered by anti-spam groups, and they watch what arrives.

The difference is that a typo can be seen. A signup form can spot a domain one keystroke away from a major provider and ask the visitor whether they meant the real one. No such hint exists for a pristine trap, because nothing about the address is misspelled or unusual.

So the two call for different defenses. Catch typos at the form, while the person is still there to correct them. For pristine traps the only control you have is the source of the data: if every address on your list was typed in by its owner and confirmed by a click, there's no route for one to get in.

Pristine spam trap: common questions

Can any service detect a pristine spam trap?

No service can do it reliably. The address exists and accepts mail like any other. Claims to the contrary are scoring guesses, not running a check.

How do pristine traps end up on a list?

Through scraping, a purchased list, or an appended data file. They are planted in places only an automated harvester reaches.

What happens when I hit one?

The blocklist operator records the hit against your sending IP and domain. Enough of them and your mail starts landing in spam folders across that provider's network.

See this on your own list

100 free checks a month, and the unknowns come back labeled.