Has anyone else’s Gmail inbox just completely gone off the rails recently? At the beginning of 2025, I was getting maybe 10 to 15 spam messages a week. Now I'm easily clearing 500+ a week.
To Google's credit, most of it does actually land in the spam folder, but calling it "spam" is letting them off the hook. The vast majority of this is straight-up phishing. Scammers are constantly spoofing real company names to target credentials—I'm seeing fakes for Apple, Ace Hardware, Lowe's, Costco, and even healthcare portals like Epic (MyChart).
The main issue here is that Google provides absolutely zero adequate tools to limit or control this. You can't mass-report emails as phishing. You have to do it one by one. When you're getting hundreds of these, it's incredibly time-consuming, and honestly, it feels completely pointless because it’s obvious Google doesn't actually do anything with that information to stop the abuse.
Sure, these networks have gotten a bit more sophisticated using random domains and subdomains (I see a ton of .biz, .id, and .uk domains). But at the end of the day, global IP registries exist. These blocks get allocated and assigned to specific companies and individuals. Google and other major tech orgs have direct insight into this massive increase in spam, and they know exactly which operators manage those networks. So why aren't they locating the ISPs and ranges where the vast majority of this originates and just blocking them entirely due to persistent, pervasive abuse? They should be working with the US and other governments to adequately sanction or restrict services where action isn't being taken.
And before anyone says "just use plus addressing" (like email+spam@gmail.com)—that is totally insufficient to limit spam. It doesn't mask your real email, and anyone who knows how Gmail works can just write a script to strip the + tag off.
The only thing plus addressing is really good for is proving who leaked your data. I was actually one of the first people to notice the massive Comcast breach because I used a plus alias. Even though plus addressing does nothing to stop spam, it gave me enough info to know Comcast had a data leak when I suddenly started receiving fake Norton and McAfee antivirus subscription invoices (which I obviously don't subscribe to) sent directly to the exact Xfinity alias I had created. I actually called Xfinity/Comcast at the time, and they were in complete denial. It took them two full years from that date to even announce the breach. That alone should have resulted in serious fines and investigations by Congress.
These days, I rely on SimpleLogin for unique aliases, which helps limit a majority of the spam. But I still need my core Gmail account for personal use and for those annoying instances where companies actively restrict access to alias providers. Because of that, the problem on my main account has just grown rampant.
And when you get 500+ spam messages a week, the spam folder becomes untenable because false positives start piling up. Google has been flagging way more legitimate emails as spam lately. Ironically, the emails they consistently flag as spam are verified, legitimate legal notices for class-action lawsuits against Google, just buried in the influx of junk. You'd think Google actively flagging class-action notices against their own company as spam would be a major issue to bring to class counsel and the presiding judge.
Ultimately, this whole mess highlights a massive systemic failure: Congressional inaction and total corporate capture. Congress already permits data brokers to trade and sell our consumer info en masse. Unless you live in one of the few states with CCPA-like protections, you have zero rights.
The US government seems completely incompetent when it comes to stopping spam and phishing. Look at the Do-Not-Call registry—it does little to nothing to stop robocalls. One can only begin to assume the government isn't addressing the issue because of corrupt companies, like the timeshare conglomerates that literally refuse to stop calling me after I participated in a discounted Vegas rental to attend a meeting. Even physical mail is screwed; the USPS is entirely captured by advertisers. I demanded to be able to opt out of the multitude of useless junk flyers I get daily, and my local postmaster literally threatened to stop delivering my mail altogether if I continued to raise the issue.
The government neglects to understand the real-world impact of this stuff. Phishing and scams absolutely devastate the elderly. They are literally utilizing and attacking infrastructure, and many of these scammers make literal violent or financial threats against their victims—behaving in the exact same capacity and definition of terrorism. Yet, the government does nothing to actually pressure or sanction the countries harboring these operations.
But government failure doesn't mean companies like Google are helpless. They could easily provide actual email alias solutions natively. They could give us the ability to mass-report phishing messages. They could put serious pressure on bad-actor networks by defederating actual ISPs and even TLDs if they aren't cooperative in addressing the issue.
What really concerns me is the weaponization potential here. This influx of spam generated by a sophisticated nation-state, or even the US government, could easily be used as a way to bombard a protestor or someone they wish to create havoc for. By flooding their inbox with so many illegitimate messages, the target would be completely unable to filter through the noise without potentially missing out on legitimate, important communications as well.
Are any of you seeing a massive spike in this targeted phishing? How are you guys keeping your primary inboxes usable?