this post was submitted on 11 Aug 2026
14 points (85.0% liked)

Google

2621 readers
14 users here now

A Lemmy community dedicated to Google products and everything Google.

Rules

  1. Keep it Google.
  2. Keep it SFW.

founded 3 years ago
MODERATORS
 

Has anyone else’s Gmail inbox just completely gone off the rails recently? At the beginning of 2025, I was getting maybe 10 to 15 spam messages a week. Now I'm easily clearing 500+ a week.

To Google's credit, most of it does actually land in the spam folder, but calling it "spam" is letting them off the hook. The vast majority of this is straight-up phishing. Scammers are constantly spoofing real company names to target credentials—I'm seeing fakes for Apple, Ace Hardware, Lowe's, Costco, and even healthcare portals like Epic (MyChart).

The main issue here is that Google provides absolutely zero adequate tools to limit or control this. You can't mass-report emails as phishing. You have to do it one by one. When you're getting hundreds of these, it's incredibly time-consuming, and honestly, it feels completely pointless because it’s obvious Google doesn't actually do anything with that information to stop the abuse.

Sure, these networks have gotten a bit more sophisticated using random domains and subdomains (I see a ton of .biz, .id, and .uk domains). But at the end of the day, global IP registries exist. These blocks get allocated and assigned to specific companies and individuals. Google and other major tech orgs have direct insight into this massive increase in spam, and they know exactly which operators manage those networks. So why aren't they locating the ISPs and ranges where the vast majority of this originates and just blocking them entirely due to persistent, pervasive abuse? They should be working with the US and other governments to adequately sanction or restrict services where action isn't being taken.

And before anyone says "just use plus addressing" (like email+spam@gmail.com)—that is totally insufficient to limit spam. It doesn't mask your real email, and anyone who knows how Gmail works can just write a script to strip the + tag off.

The only thing plus addressing is really good for is proving who leaked your data. I was actually one of the first people to notice the massive Comcast breach because I used a plus alias. Even though plus addressing does nothing to stop spam, it gave me enough info to know Comcast had a data leak when I suddenly started receiving fake Norton and McAfee antivirus subscription invoices (which I obviously don't subscribe to) sent directly to the exact Xfinity alias I had created. I actually called Xfinity/Comcast at the time, and they were in complete denial. It took them two full years from that date to even announce the breach. That alone should have resulted in serious fines and investigations by Congress.

These days, I rely on SimpleLogin for unique aliases, which helps limit a majority of the spam. But I still need my core Gmail account for personal use and for those annoying instances where companies actively restrict access to alias providers. Because of that, the problem on my main account has just grown rampant.

And when you get 500+ spam messages a week, the spam folder becomes untenable because false positives start piling up. Google has been flagging way more legitimate emails as spam lately. Ironically, the emails they consistently flag as spam are verified, legitimate legal notices for class-action lawsuits against Google, just buried in the influx of junk. You'd think Google actively flagging class-action notices against their own company as spam would be a major issue to bring to class counsel and the presiding judge.

Ultimately, this whole mess highlights a massive systemic failure: Congressional inaction and total corporate capture. Congress already permits data brokers to trade and sell our consumer info en masse. Unless you live in one of the few states with CCPA-like protections, you have zero rights.

The US government seems completely incompetent when it comes to stopping spam and phishing. Look at the Do-Not-Call registry—it does little to nothing to stop robocalls. One can only begin to assume the government isn't addressing the issue because of corrupt companies, like the timeshare conglomerates that literally refuse to stop calling me after I participated in a discounted Vegas rental to attend a meeting. Even physical mail is screwed; the USPS is entirely captured by advertisers. I demanded to be able to opt out of the multitude of useless junk flyers I get daily, and my local postmaster literally threatened to stop delivering my mail altogether if I continued to raise the issue.

The government neglects to understand the real-world impact of this stuff. Phishing and scams absolutely devastate the elderly. They are literally utilizing and attacking infrastructure, and many of these scammers make literal violent or financial threats against their victims—behaving in the exact same capacity and definition of terrorism. Yet, the government does nothing to actually pressure or sanction the countries harboring these operations.

But government failure doesn't mean companies like Google are helpless. They could easily provide actual email alias solutions natively. They could give us the ability to mass-report phishing messages. They could put serious pressure on bad-actor networks by defederating actual ISPs and even TLDs if they aren't cooperative in addressing the issue.

What really concerns me is the weaponization potential here. This influx of spam generated by a sophisticated nation-state, or even the US government, could easily be used as a way to bombard a protestor or someone they wish to create havoc for. By flooding their inbox with so many illegitimate messages, the target would be completely unable to filter through the noise without potentially missing out on legitimate, important communications as well.

Are any of you seeing a massive spike in this targeted phishing? How are you guys keeping your primary inboxes usable?

top 12 comments
sorted by: hot top controversial new old
[–] baines@lemmy.cafe 5 points 2 days ago* (last edited 2 days ago) (2 children)

what are you doing with your email?

this is not normal

[–] LifeInMultipleChoice@lemmy.world 2 points 2 days ago* (last edited 2 days ago)

I checked a Gmail account today I haven't checked in 2 weeks:

Most definitely it is tied to how the accounts are used.

[–] timewarp@lemmy.world 2 points 2 days ago (1 children)

Honestly I don't do anything unusual with it. It's just my main account for everyday things. What is unusual is the sheer amount of cyberbreach notices I get every single year telling me almost every company and government agency I interact with has been compromised.

If you exist in modern society, data brokers likely have a massive profile on you, and those brokers are notoriously terrible at actually securing that data.

Take LexisNexis for example. Just look at the news from a couple days ago:

https://www.scworld.com/brief/lexisnexis-services-offline-due-to-unusual-activity-on-third-party-vendor-servers

And what are they doing with all this data they clearly can't keep secure? Selling it to literally anyone with a checkbook, including the government:

https://lawreview.colorado.edu/print/volume-95/lexisnexiss-contract-with-ice-as-unjust-enrichment-lizzie-bird/

ICE is literally paying LexisNexis millions of dollars for access to data to feed into Palantir's ELITE system so they can figure out which neighborhoods to target for raids.

So you've got these massive, unregulated data brokers hoarding heavily enriched profiles on us (names, addresses, primary emails, who we do business with) and selling them off to power government surveillance, only to constantly get popped or have their third-party vendors compromised. That data then gets dumped straight to scammers.

That's exactly why the phishing attacks I'm getting are so highly targeted and use real company names—the scammers already likely know what services I use because the data brokers packaged it up and failed to protect it. I'm not putting my email where it doesn't belong or signing up for shady sites. My inbox is just collateral damage in a completely broken data economy where our information leaks constantly.

[–] baines@lemmy.cafe 2 points 2 days ago (1 children)

all of this is true but i have 5 spam email over 2 weeks

[–] timewarp@lemmy.world 1 points 2 days ago (1 children)

Maybe I should stop talking about the genocide in Gaza and see if my spam decreases.

[–] baines@lemmy.cafe 2 points 2 days ago (1 children)

depends on the where

bet it’s tied to a forum with your registered email, selling your info

wouldn't think it would be lemmy or the like

[–] timewarp@lemmy.world 1 points 2 days ago

Nah, really I use SimpleLogin for a majority of things these days and have for a few years. This is mostly just a long-lived Gmail account I've used, where I didn't always do that, and despite trying to switch over nearly all of my accounts emails to unique aliases, it doesn't stop the plethora of companies that likely never removed my old email from their systems. Ping me in a week if you want and I'll show you another 500+ spam emails, many pretending to be real companies. I just went through my spam today.

[–] Krusty@quokk.au 2 points 2 days ago

I get emails purporting to be deceased contacts.

Like my uncle was a photographer, died of brain cancer a decade ago. I'll get emails using his first and last name telling me he has photos he wants to share.

People=shit... Whatchu gonna do about it?

[–] swicano@programming.dev 2 points 2 days ago

I get about 1 every other day, on my main Gmail that I've used for 15+ years, multiple breaches. What you're experiencing is not what I'm experiencing, but who can say what the average experience is. I get so few false spam flags that I barely even check anymore.

[–] Krusty@quokk.au 1 points 2 days ago (1 children)

This is why you use the + trick and add a tag for whatever you sign up for, then you know who's leaking your email.

Like if your email is John@gmail.com use john+tag@gmail.com where tag can be anything you want as long as the characters are valid.

[–] PlantJam@lemmy.world 2 points 2 days ago (1 children)

Serious question: then what? So you find out that some retailer sold/breached your email. What's the recourse?

[–] Krusty@quokk.au 1 points 2 days ago

Live and learn. Divest if possible.

Also you can filter those tags.