What is a spam trap?

Spam trap, defined
A spam trap is an email address kept solely to catch senders who mail people who never asked, and hitting one damages sender reputation without producing any complaint.

There are two kinds and they behave differently. A recycled trap is an address that belonged to a person, was abandoned, and was later reactivated by the provider specifically to catch stale lists. A pristine trap was never used by anyone, and was published where only a scraper would find it.

Recycled traps are partially addressable, because the signal is age and silence: an address that stopped engaging two years ago is the risk. Sunsetting those is ordinary list hygiene.

Pristine traps are not detectable. At the protocol level the address exists, accepts mail and looks entirely ordinary. Any verifier claiming to strip them is selling a probability estimate and calling it a check.

The defense is how you collect addresses, not what you run them through afterwards. Scraped and purchased lists carry traps by construction.

How ZapBounce reports it

We do not claim to detect spam traps, and no verdict in our API means trap. What we can do is flag the conditions that correlate with recycled traps, and say plainly that pristine traps are out of reach for anyone.

What a trap hit looks like from your side

Say you mail 60,000 addresses, and four of them are traps run by a blocklist operator. Nothing unusual shows up in your campaign report. All four accept the message with a 250, none bounce, and none complain, because nobody is there to complain. Your delivery rate looks the same as last month.

The evidence turns up a day or two later, somewhere else entirely. A slice of your mail to corporate domains starts failing with text along the lines of: 554 5.7.1 Service unavailable; Client host [203.0.113.5] blocked using zen.spamhaus.org. The rejection names the list, and usually carries a link to a lookup page.

That delay is what makes traps hard to reason about. By the time the block appears, you can't tell which four addresses out of 60,000 caused it, and the operator won't say. You fix the source of the data because you can't fix the addresses.

Questions for a vendor that says it removes them

Ask what response from the mail server identifies a trap. There isn't one, so a straight answer has to involve something other than the SMTP check: a purchased database of known trap addresses, or a score built from the address's age and activity.

Then ask how the database was built and how old it is. Trap operators don't publish their addresses, and they retire any that leak, since a known trap has stopped doing its job. A list of known traps is by definition a list of the ones that were burned.

Finally, ask what happens to your money when the score is wrong. A probability dressed up as a verdict costs you real subscribers on one side and gives false comfort on the other. ZapBounce doesn't sell trap removal. Any flag for a likely recycled trap is labeled as a heuristic, never as a verdict.

Spam trap: common questions

Can a verifier remove spam traps from my list?

Not reliably. A pristine trap accepts mail and looks like any other working mailbox, so there is nothing to detect. Treat that promise as marketing.

How did a spam trap get on my list?

Scraping, a purchased list, or an old address that the provider recycled into a trap after it went unused for a year or more.

What actually reduces trap risk?

Confirmed opt-in at collection, and sunsetting addresses that have not engaged in twelve months. Both act before the trap is ever on the list.

See this on your own list

100 free checks a month, and the unknowns come back labeled.