
Why unsubscribing doesn't stop the spam
You unsubscribed three weeks ago. The emails are still coming — sometimes from the same sender, sometimes from a "partner" you've never heard of, sometimes the identical promotional pitch under a slightly different subject line. Clicking unsubscribe didn't fix the problem. Here's what's actually happening, and what does work.
What "unsubscribe" is legally required to do
The CAN-SPAM Act in the US requires commercial email senders to honor opt-out requests — but the obligation is narrower than most people expect. Senders have up to 10 business days to process an unsubscribe. That delay is written into the law deliberately, not a loophole companies are exploiting.
More importantly: the law applies only to the sender who received your address directly. It doesn't cover what happens downstream — to affiliates they shared your address with, to data brokers they sold it to, or to co-registration partners who got your email when you checked a box at signup three years ago. Once your address leaves the original sender, it enters a distribution chain that CAN-SPAM doesn't reach.
GDPR is stricter and includes the right to erasure, but it applies to EU residents and most American companies treat compliance as a 30-day process that doesn't retroactively pull your email from every list it was shared to in prior years. Filing a GDPR request can help at the margins, but it's not a practical tool for the average inbox-cleaning problem.
Where your email goes after you sign up
Most email marketing platforms — Klaviyo, Mailchimp, Constant Contact, HubSpot — operate inside a data-sharing ecosystem. When you sign up for a store newsletter or download a free guide, your address doesn't stay in one place:
Data brokers like LiveRamp, Acxiom, and Oracle Data Cloud aggregate consumer contact records and resell them to advertisers. A confirmed mailing list is a data asset, and many companies treat it as a revenue line item.
Co-registration networks work more subtly: when you check "I'd like to receive offers from our partners" during checkout or signup, you've opted into a syndication network. Your email goes to whoever bought that traffic segment, and those buyers are often dozens of companies you've never interacted with.
Affiliate chains: Company A shares your address with Company B under a data partnership agreement. Company B shares it with C and D. Each party may have no idea where in the chain your address originated — and none of them received the opt-out signal when you unsubscribed from Company A.
The "partners" and "third-party advertisers" language you scrolled past in the terms of service is doing real work here. It's intentionally vague because the actual network of recipients would be alarming to read in full. Most marketers aren't malicious about it — this is just how the email advertising industry is structured.
The unsubscribe button sends a flag to the one company you interacted with. It doesn't cascade. The brokers keep mailing you. The co-registration partners keep mailing you. The affiliate network keeps mailing you. None of them received the instruction.
The reconfirmation problem
There's a less-obvious issue: clicking any link in an email — including an unsubscribe link — confirms to the sending system that your address is real, active, and monitored by a live person. That confirmation is valuable data. Confirmed-active addresses trade at a higher price in data broker files because they're more likely to generate engagement downstream.
Some senders handle unsubscribes by flagging the address as a "confirmed opt-out but confirmed active" record and selling it. The reasoning is that an active address is worth something even if the person opted out of this particular list. You stop getting email from Company A; you start getting email from companies that bought the record from Company A's CRM export.
There's also the re-engagement sequence. If a subscribed address goes quiet for 90 days, many platforms will automatically trigger a win-back campaign. The logic is that dormant subscribers drag down deliverability scores — either you re-engage them or you clean them out. Some senders clean by passing the address to a list broker before removing it from their own system. You get a final surge in email volume right before the list drops you.
The practical result is that being selective about when you click unsubscribe links is a reasonable instinct. On lists you don't recognize, clicking anything — including the unsubscribe link — can do more harm than good.
Why a per-service address works where opt-out links don't
The unsubscribe problem is structural: you can't opt out of systems you don't know exist, and you can't trace which sender sold your address without a dedicated canary address per signup. A throwaway address per service solves both at once.
Isolation: if [email protected] starts receiving spam about credit cards and investment alerts, you know where it came from. Target shared it. That's attributable and concrete — not a guess. The detailed version of this attribution pattern is in how to find out which website sold your email.
Containment: the downstream spam never reaches your real inbox. You don't have to unsubscribe from anything, file a data erasure request, or wait 10 business days. The throwaway address collects whatever it collects, and you check it only when you need something from that sender.
Rotation: when an address is compromised — when you're getting more spam than signal — you stop using it and generate a new one. No cleanup required. No opt-out form to submit. The address stops being checked, and whatever arrives there doesn't affect your real inbox.
This is the same principle as using a unique password per service, but considerably cheaper to execute. A new throwaway address takes about three seconds. There's nothing to remember and nothing to update if the address gets shared or breached.
A naming pattern that keeps it manageable
Randomized throwaway names add friction you don't need. A consistent, predictable format works better because the whole point is that the address is disposable — not secret:
[service]-[year]@cybertemp.xyz
[email protected]for a retail store loyalty account[email protected]for recruiter messages and platform notifications[email protected]for a publication registration wall[email protected]for a software trial where you expect a drip campaign to follow
The year suffix tells you when the address was created. If [email protected] is receiving volume in 2026, the address was shared roughly two years ago. You can generate [email protected] for any new activity and let the old one sit idle without touching it. You don't need to "close" the old address — just stop checking it.
These addresses look real to signup forms because they are real inboxes on a real domain. Verification emails arrive. OTPs work. The signup completes normally. The address can receive replies if needed. The per-service free trial version of this pattern is covered in detail in temp email for free trials: the per-service pattern.
Using CyberTemp for this in the browser
Open cybertemp.xyz. Type the local part you want in the inbox field — for example, amazon-2026 — pick a domain from the list, and the inbox is live immediately. Paste the address into the signup form, wait for the verification email to appear in the browser tab, click the link or copy the OTP, and you're done.
The FREE tier requires no account and no install. The inbox is available immediately. ECO, CORE, and ELITE tiers give you longer retention, more active inboxes, and higher daily limits — useful if you're managing addresses across several ongoing services at once. For a one-off signup or newsletter trial, the free browser tool handles it without any setup.
When you want to stop the cycle entirely — not just manage its downstream effects — the approach is to stop leaking your real email at every signup going forward. Unsubscribing is reactive cleanup. Per-service addresses prevent the problem from happening in the first place.
For the simple case: open cybertemp.xyz, type the local part you want, paste the address into the signup form, and collect the verification email. No unsubscribe link required when the address has already done its job.