The two kinds
Pristine traps are addresses created by blocklist operators and mailbox providers that have never belonged to a person and have never opted in to anything. They are seeded into scraped lists and public pages. Mail arriving at one is proof the sender did not get permission, because there was never anyone to give it.
Recycled traps are real addresses that were abandoned, left to hard bounce for months, and then reactivated as traps by the provider. Mail arriving at one proves the sender is not removing bounces.
Why they hurt so much
A trap hit is unambiguous evidence in a way that a spam complaint is not. Complaints are noisy — people report mail they signed up for. A pristine trap has no innocent explanation. Blocklist operators weight them heavily, and a small number of hits can list a domain or an IP outright.
There is no feedback. No bounce, no complaint, no signal at all. The first thing you notice is a listing or a sudden placement drop.
Avoiding them
Never buy or scrape lists — that is where pristine traps live. Validate addresses before sending, and validate again for lists older than a few months. Remove hard bounces immediately rather than retrying them, because a repeatedly bouncing address is exactly what becomes a recycled trap. Drop contacts who have not engaged in a long time.
For cold email, where recipients have not opted in by definition, list sourcing quality is the entire defence. Verified data from a provider that maintains its lists is meaningfully different from a scraped export.
Check yours
These run free in your browser. Nothing you type reaches a server.
Common questions
How do I know if I hit one?
You generally cannot, directly. The signals are indirect — a sudden blocklist listing, or a placement drop with no other explanation. Some blocklist operators will tell you a trap hit caused a listing when you file a delisting request.
Can I remove spam traps from my list?
Not by inspection — they look like ordinary addresses. Validation services catch some known traps, but the real defence is list hygiene rather than trap detection.
Does cold email always hit traps?
No. It depends entirely on where the data came from. Verified data from a reputable provider carries far fewer traps than a scraped or purchased list.
Related concepts
Everything above is diagnosis. To confirm a fix worked you need placement data — seed accounts across the major providers, plus the DMARC aggregate reports read as a trend rather than a wall of XML. GlockApps is what I run for both.
See GlockApps →Affiliate link — it costs you nothing and help keep these tools free. Everything I use →If this is the thing going wrong
The pages explain it. If you would rather it was simply fixed, that is the work I do.