Five to ten years ago, sending out email chain letters seemed as easy as boiling dumplings. You’d write up a story about a Nigerian inheritance, drop in a link, add an AliExpress database, and set up auto-mailing. Traffic poured in, profits grew.

By 2026, things have gotten much more complicated: spam campaigns now look like multi-stage covert operations. Still, this traffic source is more alive than dead.

We analyzed open sources and in this article, we’ll explain how much the mechanics have changed and how working with databases has become more complex.

The end of the golden age of email spam

Problems with this traffic source started a while ago. But since 2024, Google, Outlook, and Yahoo have required mandatory authentication for bulk senders. Anti-spam systems now evaluate not just the content of emails by keywords or links. Algorithms check the sender: who they are, where they’re from, how they’ve interacted with the recipient and email in general before.

Let’s break down the database: how anti-spam systems verify the data.

Domain reputation

The more often emails from a certain domain end up in the Spam folder, the lower its reputation. If users complain about mailings, Google or another provider flags the site’s address as suspicious. Algorithms then automatically send any emails from this domain to Spam, often without even checking.

Google warning — GoAff

A complaint rate above 0.3% is considered critical for bulk mailings by Google. Since November 2025, security algorithms reject emails if the domain is suspicious.

“Don’t be afraid of unsubscribes. When someone unsubscribes, that’s good. If you send emails to 10,000 people and 1,000 never open them, Gmail thinks: ‘Why are you emailing people who aren’t interested?’ — and marks you as spam.” — Jonathan Bouchard,   Performance Marketing Champions.

IP and device fingerprint reputation

Email services can analyze the digital fingerprint of the device sending 5,000 emails a day. So, affiliates need more effort and tools to spoof or hide:

  • IP and location;
  • device data: model, operating system, installed programs;
  • cookies;
  • browser data;
  • user behavior, etc.

Since 2024, enhanced sender authentication checks have become important. Anti-spam systems verify whether the mailing is really coming from the domain owner. Three main mechanisms are used for this:

  1. SPF (Sender Policy Framework) — determines if the sender has the right to send emails from a specific domain.
  2. DKIM (DomainKeys Identified Mail) — checks if the email was altered during delivery.
  3. DMARC (Domain-based Message Authentication, Reporting and Conformance) — evaluates mailings from the domain using the previous two mechanisms.

A study on arXivLabs showed that due to shortcomings, 34.7% of the 12 million domains checked allowed emails to be sent from over 1 million IP addresses. But since 2025, domain authentication has made mass mailing much harder.

Recipient Behavior Analysis

Algorithms now analyze not only the technical parameters of senders, but also recipient behavior. Security systems track how many people:

  • opened the email;
  • deleted it immediately;
  • clicked a link;
  • marked it as spam.

In other words, users themselves train smart algorithms to detect “bad emails.”

Updated AI Filters for Trigger Words

Ten years ago, anti-spam filters were basically triggered only by keywords.

Now their capabilities have grown even further. The system instantly understands the context and meaning of the message—even if you didn’t use any standard keywords at all.

Updated Google AI filters — GoAff

For example, back in November 2023, Google implemented RETVec (Resilient & Efficient Text Vectorizer), a modern text classification system:

  1. Letters and spelling do not matter. The algorithm converts text into numerical vectors that define its semantics. For it, “earnings” and “e@rn1ngs” are the same. You also cannot trick it by swapping Latin and Cyrillic letters.
  2. The algorithm sees all elements of the email. Previously, you could use white font or zero font size to confuse security systems. Now that won’t work.

With RETVec, it became possible to detect 38% more spam compared to standard benchmarks. Similar systems are used by OutLook as well.

Databases: a Mixed Bag for Spam Campaigns

By 2026, databases are mostly of two types: hacked and infrastructure-based. If you go to the darknet and buy a list for 50 USDT, in 99.9% of cases it’s been overused a hundred thousand times. These addresses have already received hundreds of emails with various offers: place a bet and win, buy supplements to lose weight, or cure diabetes completely.

The Zerobounce study states that over 22% of addresses in old lists are invalid. People whose data was hacked are unlikely to be happy about emails offering free spins or miracle anti-aging creams at a discount. Such emails will go straight to spam.

“Deliverability issues are often invisible until they become catastrophic, because unlike search rankings, there’s no obvious ‘page five’ moment — you just quietly stop reaching 35% of your database.” — Florin Armasu, CEO Data Innovation.

Buying a database from “official” services isn’t a silver bullet either:

  • one contact costs from $0.03 to $5;
  • you have to monotonously and painstakingly select suitable contacts by parameters.

Filtering data by dozens of parameters doesn’t guarantee users will bite on your mailing.

Infrastructure databases are a goldmine. They’re collected by affiliates, business owners, or webmasters themselves. These databases contain contacts of people who willingly left their email and subscribed to newsletters from dating apps, casinos, or crypto platforms. A user who agreed to receive emails from a casino might be interested in an offer from another gambling site.

How to Build Your Own Email List for Spam Campaigns

You can try to build your own list using a lead magnet:

  1. Create a lead magnet. Not just “Subscribe to updates,” but “Get the top 5 slots of the month” or “Exclusive promo code for 50% off a rejuvenation course.”
  2. Create a landing page. Nothing extra — just the offer, a description of the benefit, and a form to submit an email address.
  3. Then, the classic flow — pre-lander and offer.

Sources can be anything — from SEO to teaser ads. Even if the user doesn’t register at the casino or buy the rejuvenation product, the email stays in your database. You can then follow up with email sequences. The main thing is to hook them at the start, show the real value of the offer, so they agree to leave their email address.

How Affiliates Should Work with Spam Campaigns in 2026

You’ve got your own database. Now comes the main bulk of the work. Without it, email campaigns are pointless. 

Barracuda 2026 Email Threats Report shows that one in three emails worldwide is spam or phishing — GoAff

The Barracuda 2026 Email Threats Report found that every third email in the world is spam or phishing. Experts analyzed 3.1 billion emails. So, there are still loopholes for sending.

Authentication via SPF, DKIM, and DMARC

Without sender authentication through these mechanisms, your emails won’t get delivered. Set up each parameter as precisely as possible. If SPF, DKIM, or DMARC are weak, there will be no delivery.

In June 2026, a method was discovered to bypass SPF checks and other mechanisms in Outlook. Spammers set up an external spam filter, Mailgun or Barracuda, spoof the domain, and send emails directly to the server. The emails land in the “Inbox” folder without any warnings. In a study by InfoGuard Labs, it is claimed that in over 20% of cases, checks are bypassed and emails are successfully delivered.

If SPF, DKIM, and DMARC are configured, you can get BIMI (Brand Indicators for Message Identification)—a standard that allows you to display your logo next to your email. This increases user trust

IP Reputation Control

Even with perfectly set up sender authentication, a spam campaign can end before it even starts. It’s important to take care of your IP reputation and domain warming.

Don’t create mailing inboxes with ridiculous names. Imagine: you receive two emails, one from Mikhail Petrov and another from “4eloveka-Pa5uka.” The second one will obviously raise suspicion and you’ll be tempted to mark it as spam.

No one writes openly about the nuances of warming up in public sources. However, we managed to find the following strategy.

Use only residential proxies and don’t send 500 emails on the very first day of working with a domain. First, check the domain’s age. If it’s less than 30 days old, warming up is a must:

  1. First week. Send 15-20 emails per day from one domain. Personalize the emails, engage the user, and show value. Do not use links, images, or attachments. Spread out the sending times; don’t send everything at once.
  2. Second to fourth week. Increase the email volume by 20-30% per week. 

After four weeks, you can move to full-scale mailing—60-80 emails per domain. Naturally, you should have many domains for sending.

Microdomains (Satellite Domains)

Microdomains (satellite or secondary domains) are technical expendables for cold mailing. Microdomains are needed as a reserve to reduce the load and risks on your main business domain.

Several dozen microdomains are suitable if you have a large email database. You can distribute the load and send 30-50 emails from each. The main thing is to warm up the microdomains.

The reputation of one of the domains may drop due to a technical failure or unexpected moderation tightening. But you will still have backup microdomains. You can easily switch traffic from the failed domain to the others. You won’t have to pause your campaign.

Using Trusted SaaS Platforms

In the 2010s, to automate spam mailings, people would buy or rent virtual servers and install specialized software on them. IP addresses had to be configured manually. The method was tedious, complicated, and expensive.

Now, it’s impossible to do mass mailings without automated services. MailChimp, SendPulse, and Unisender can be used “in the gray zone”: disguising aggressive creatives and copy as white-hat marketing. For example, instead of pushing for a bet or deposit, you talk about a new slot or bonus. All three services have a ban on mailings for controversial niches. Still, in our experience, these restrictions are easily bypassed in dating.

In 2026, many use the trusted SaaS platform method. 

Instead of setting up servers, you can use well-known platforms like Google AppSheet, Atlassian Jira, and others.

For example, at the end of 2025, spammers used trial Jira accounts and, thanks to built-in automation features, sent thousands of emails to clients inviting them to a casino or crypto platform. Users were promised bonuses, free spins, and solid passive income.

So, if you craft your emails smartly—focusing not on slots but on the chance to boost your salary—the method works.

Choosing the Right Creatives and Copy

Shock content and loud claims about winning a million no longer work. Users want value. Players want a bonus with clear wagering terms. Those looking to lose weight want an extra fat burner or a new easy diet.

Email campaign statistics — GoAff

The key is personalization and an individual approach. McKinsey experts in 2026 showed that companies that personalized their emails saw 10% more profit.

“Contrary to popular belief, the secret to high engagement is not in clever emails, but in a human approach.”

The sender is a person. We sell to people, not companies. I sign with my name, not ‘CPV Lab.’ This creates the feeling of a personal conversation,” — Jonathan Bouchard, Performance Marketing Champions

Choose non-aggressive copy. Don’t scare the user—let them calmly read the information and make a choice. Always include an “Unsubscribe” button. This is a requirement from Gmail and other email services. But it also benefits you: the user is less likely to feel manipulated. 

Verticals Where E-mail Still Works

In 2026, there are still traffic arbitrage verticals where e-mail marketing remains profitable:

  1. Gambling and betting. Keywords like “freespin” and “bonus” are disliked by anti-spam filters, but the game is worth the candle. The money at stake belongs to those who love to play. Email campaigns are a source of first deposits. For example, from November 24 to 30, 2025, the team managed to get 422 FTD totaling $20,213.65.
  2. Crypto, finance. Just like in gambling, LTV matters in crypto. Clients no longer fall for “Get a million by payday in 30 days,” but they do respond to “Pay a tiny fee and get Bitcoins to your wallet.” Emails include a link to telegra.ph or Google Forms to bypass algorithms and build trust.
  3. Adult, dating, SOI-DOI offers. People always want to connect, so they will enter their email and confirm it to access new acquaintances.
  4. Nutra. To order with a discount, you need to provide a phone number and/or email for contact. Plus, readers on the pre-lander are promised an extra guide on weight loss, rejuvenation, or blood sugar stabilization.
  5. E-commerce (whitehat approaches). This isn’t spam, but a legal tool after audience segmentation and analysis.

Conclusion

In 2026, email spam campaigns are more alive than dead. But email marketing requires deep technical expertise: authentication, reputation management, server and domain setup, and much more. Spam still works well in nutra, gambling, crypto, and dating. But without your own database of active addresses and proper technical setup, there’s nothing to do in any vertical.