Recurring spam
Spam Keeps Coming From Different Email Addresses: What to Do
Blocking one sender can stop one exact address, but it does not stop a campaign that changes addresses, domains, or sending infrastructure. The useful next step is to find the stable pattern behind the messages.
TLDR
Do not assume every new From address represents a completely new problem. Compare several messages in logs, identify what stays consistent, and apply the narrowest safe control. Use a sender block list for a stable known sender, a domain block when the whole domain is unwanted, and a carefully tested advanced filter when the useful pattern appears elsewhere.
Why Blocking One Address Fails
A mailbox block normally matches one visible address or domain. Spam operations can generate new local parts, move between domains, use compromised accounts, or send through services that host many unrelated customers.
This is why blocking [email protected] may have no effect on tomorrow’s message from [email protected]. The block worked; the next message simply did not match it.
Repeated manual blocks are still useful for persistent known senders. They become inefficient when the sender identity changes faster than an administrator can maintain the list.
Which Sender Identity Are You Seeing?
An email can contain several sender-related values: the display name users see, the visible From address, an envelope sender used during delivery, a Reply-To address, and the server that made the connection. These values can differ.
A familiar display name is not proof of identity, and a changing From address does not mean every other signal changes with it. Filtering systems evaluate more than the name shown in the inbox, while mailbox block buttons may act on only one value.
If the messages imitate your own domain or a known supplier, review SPF, DKIM and DMARC versus spam filtering before creating broad exceptions.
Find the Recurring Pattern
Collect several examples and compare them together. Useful questions include:
- Do the addresses change while the sender domain remains the same?
- Does the display name repeat across different addresses?
- Are the same recipients, aliases, or public addresses targeted?
- Do subjects or message bodies contain a stable phrase?
- Do the messages arrive in a repeated time pattern?
- Do logs show the same action, classification, or source pattern?
Logs are better evidence than the inbox view alone. They help an admin compare what the filtering layer received and how it handled each message. Our guide to tracing email with mail logs explains the investigation process.
Choose the Narrowest Useful Control
| Pattern | Possible response | Main caution |
|---|---|---|
| One stable unwanted address | Sender block list | The sender may rotate addresses |
| One consistently unwanted domain | Block the sender domain | Confirm it does not send legitimate mail |
| One mailbox receives the junk | Mailbox rule or address cleanup | Does not protect the wider domain |
| Spam affects many addresses | Domain-level inbound filtering | Requires proper mail-route setup |
| Stable pattern across changing senders | Advanced content or regex filter | Broad patterns can create false positives |
A sender allow list should not be used merely to undo an uncertain result. First confirm the sender is legitimate, then use the narrowest allow entry that solves the repeated false positive.
When Regex-Based Filters Help
A regular expression can match a defined pattern rather than one literal address. This can help when unwanted messages share a stable structure while small details keep changing.
Regex is powerful enough to cause problems when written broadly. Start with log evidence, target a distinctive pattern, test against legitimate examples, and avoid rules based on common words such as “invoice,” “payment,” or “order.” Keep a record of why the filter exists and review it when mail patterns change.
Where SpamVest Fits
SpamVest filters incoming mail for the protected domain before accepted messages reach the existing provider. Admins can manage known unwanted senders with sender block lists and investigate messages using quarantine and logs.
For each protected domain, Open antispam cloud provides deeper controls including sender allow lists, sender block lists, log search, quarantine review, and advanced regex-based filters. SpamVest does not replace mailbox hosting or guarantee that every unwanted message will be identified.
Frequently Asked Questions
Why does spam continue after I block the sender?
Blocking one address only affects mail matching that address. Bulk senders can rotate addresses, domains, sending services, display names, and message wording.
Should I block an entire sender domain?
Only when the domain is consistently unwanted and not used for legitimate mail. Domain-wide blocks are broader and should be checked carefully.
Can regular expressions block recurring spam patterns?
Yes. Regex-based filters can match stable patterns across changing messages, but broad expressions can catch legitimate mail and should be tested cautiously.
Do email logs help with changing spam senders?
Yes. Logs let admins compare sender, recipient, timestamp, delivery action, and other available details across multiple messages.
Can SpamVest block known unwanted senders?
Yes. Admins can manage sender block lists and use antispam cloud per protected domain for logs, quarantine, sender controls, and advanced regex-based filters.
Stop Chasing One Address at a Time
When rotating spam affects the business domain, SpamVest adds an inbound filtering layer with the logs and controls administrators need to respond consistently.
Start a 30-day trial Compare filtering options