
DNC Scrubbing Practices · September 28, 2026 · GrowthPros
Why do I keep getting spam emails even after blocking them?
Discover why blocking spam senders doesn't work and learn the consent-based solution that stops spam at the source for good.

Key Facts
- 3.4 billion phishing emails flood inboxes daily — roughly 39,000 every second according to aggregated phishing research
- 82.6% of detected phishing emails are now AI-generated, stripping away the grammar errors and generic greetings that once gave them away per industry analysis
- AI-generated phishing that bypassed filters surged from 4% to 56% of reported attacks in a single month per Hoxhunt's telemetry
- 20.3% of AI-assisted phishing emails use open redirects to hide malicious links from both filters and human eyes according to Hoxhunt's trends report
- Nearly 1 billion emails were exposed in data breaches in 2021 alone, affecting 1 in 5 internet users per the latest phishing statistics
- Phishing-as-a-Service kits let anyone launch sophisticated campaigns for under $100 with zero coding skills according to StationX's analysis
- Google blocks ~100 million phishing emails daily yet billions still slip through per AAG IT's phishing statistics
Why Blocking Senders Fails Against Modern Spam
You blocked the sender. The emails kept coming. That's not a glitch in your email client — it's a fundamental mismatch between how blocking works and how modern spam operates.
Microsoft's own documentation admits the limitation: blocked senders still reach your inbox because they either change their email address or hide their real address behind a spoofed display name. Blocking is an address-based defense, and spammers treat addresses as disposable.
Tech expert Leo Notenboom puts it bluntly: "Blocking email by the 'From:' address is useless in the war against spam." His analysis on Ask Leo! explains that spammers constantly rotate addresses and use "From: spoofing," so the address you blocked yesterday has nothing to do with the one hitting your inbox today.
The FTC adds another layer: most spam is sent via botnets — networks of millions of hacked computers, phones, and smart devices. Each hijacked device can send from a different address, meaning no blocklist can keep pace with the volume.
This isn't a teenager in a basement. According to StationX's analysis, phishing has become "a professional, AI-augmented industry with specialised roles," with 3.4 billion phishing emails sent globally every day — roughly 39,000 per second. Phishing-as-a-Service kits let attackers with zero coding skills launch sophisticated campaigns for under $100.
AI has made evasion even cheaper. A Hoxhunt trends report found that AI-generated phishing bypassing filters jumped from 4% of reported attacks in November 2025 to 56% in December. AI strips out the classic spam tells — bad grammar, generic greetings — that humans once relied on.
Why does the spam economy keep growing? Because it works on economics:
- Sending is nearly free via botnets, while even a tiny response rate pays off
- Harvested addresses circulate indefinitely — nearly 1 billion emails were exposed in data breaches in 2021 alone
- Malwarebytes calls it a "low-risk high-reward activity" with global reach and little law enforcement exposure
Spam persists because it's consent-free volume blasting. The same logic that makes blocking futile against rotating addresses is why legitimate outreach operations — like GrowthPros' lead delivery — take the opposite approach: DNC-scrubbing every list before contact and attaching a consent record to every lead. Consent-based contact is the only posture that doesn't depend on winning an arms race against rotating addresses.
Blocking still has one narrow use: it works when a sender's true address is stable. For everything else, the realistic goal is management and minimization — not elimination.
How AI and Botnets Have Supercharged Spam Volume and Evasion
Blocking a spammer today is like swatting one mosquito in a swarm bred in a factory. The swarm doesn't shrink — it just replaces the one you caught with a thousand more, each slightly harder to recognize.
The scale is genuinely industrial. According to aggregated phishing research, roughly 3.4 billion phishing emails are sent every day — about 39,000 every second. Most of that volume doesn't come from individual attackers sitting at keyboards. The FTC notes that most spam is sent via botnets: networks of millions of hacked computers, phones, and smart devices, each pumping out messages without their owners' knowledge.
AI has removed the last human bottleneck. StationX's analysis found that 82.6% of detected phishing emails are now AI-generated, and the industry has professionalized into specialized roles rather than lone operators. The classic spam tells — awkward grammar, generic "Dear Customer" greetings — no longer exist to tip you off.
The evasion tactics have scaled just as fast. Hoxhunt's telemetry shows AI-generated phishing that bypassed filters jumping from 4% of reported attacks in November 2025 to 56% in December, settling around 40% in January 2026. The same report found that 20.3% of AI-assisted emails used open redirects specifically to hide malicious links from both spam filters and human eyes.
The result is an arms race the defenders are losing:
- Attackers can launch sophisticated campaigns for under $100 using Phishing-as-a-Service kits, no coding required.
- Phishing sites live an average of just 12 hours before takedown — fast enough to dodge blocklists.
- About 40% of campaigns now extend beyond email into Slack, Teams, QR codes, and callback scams.
- Google blocks roughly 100 million phishing emails daily, yet billions still slip through.
This is why blocking individual senders feels futile. You're playing whack-a-mole against an adversary with near-zero cost, infinite addresses, and machine-generated polish. As one security expert puts it, blocking by the "From:" address is useless when spammers rotate addresses constantly.
The economics only work because consent is absent from the equation. That's the same reason legitimate businesses are moving the opposite direction: GrowthPros scrubs every lead list against the DNC and attaches a full consent record — disclosure text, timestamp, IP address — before any outbound contact. Consent-based contact is the one strategy spammers can't copy, because copying it would destroy the volume economics their entire model depends on.
The Consent-Based Alternative: How GrowthPros Stops Spam at the Source
If blocking can't stop spam, the only real fix is to stop spam from being sent in the first place — and that starts with consent. The spam economy survives because volume is cheap and accountability is absent. Phishing-as-a-Service kits let anyone launch campaigns for under $100, and industry analysis describes spam as a "low-risk high-reward activity" with global reach and little enforcement risk.
The spray-and-pray model depends on addresses people never agreed to share. Nearly 1 billion emails were exposed in data breaches in 2021, affecting 1 in 5 internet users, and the FTC notes that websites and apps may sell your address to third parties. Once a list is bought, no amount of blocking by the recipient undoes the original decision to send.
The consent-based alternative flips that logic. Instead of blasting rotating addresses from botnets — which, per the FTC, power most spam — every contact originates from a documented opt-in. GrowthPros applies this at the lead level: lists are DNC-scrubbed before any outbound contact, and every lead carries a full consent record — disclosure text, timestamp, IP address, and the named contacting party.
What that looks like in practice:
- Every lead is qualified and consent-recorded before delivery — never dumped into a shared inbox or resold to a list of strangers.
- Opt-outs are honored immediately and permanently across SMS, voice, and email, not queued for "one last campaign."
- Reactivation targets only pre-existing, opted-in relationships — never cold lists — with FCC one-to-one consent direction built in from day one.
- "Capped-shared" means a hard maximum of two buyers, not the five-plus you'll find on shared marketplaces.
Contrast that with the numbers behind the spam problem. With 3.4 billion phishing emails sent daily — roughly 39,000 per second — the senders face no meaningful cost when one address blocks them. They simply rotate to the next one. A consent-recorded pipeline removes that escape hatch by making the sender accountable to a documented permission trail for every single contact.
The distinction matters most at the moment of opt-out. Security experts warn that engaging with spam — even clicking "unsubscribe" in a malicious email — confirms your address is live and invites more spam. A compliant pipeline treats opt-outs as binding instructions, not engagement signals to exploit. That's the difference between a lead process and a spam generator, and it's the only sustainable posture for businesses that never want to end up on the wrong side of someone's block list.
Frequently Asked Questions
Why do I still get emails from someone I already blocked?
Blocking targets the "From:" address, but spammers simply rotate to a new address or hide their real one behind a spoofed display name — Microsoft's own documentation confirms both reasons. As Ask Leo! puts it, blocking by the From: address is "useless in the war against spam" because the address you blocked yesterday has nothing to do with today's.
Is blocking email senders ever actually useful?
Yes, but only in one narrow case: when the sender's true address is stable and they aren't spoofing it. For everything else, experts agree the realistic goal is management and minimization, not elimination — Malwarebytes notes it's almost impossible to completely stop receiving spam, so layered defenses beat any single blocklist.
Should I click unsubscribe to stop spam emails?
No — if the email is spam or phishing, clicking unsubscribe (or replying, clicking links, or loading images) confirms your address is live and typically invites more spam, according to security experts at Malwarebytes. Unsubscribe links are only safe for legitimate newsletters you actually signed up for; for everything else, mark it as spam to train your provider's filters.
How big is the spam problem really?
Roughly 3.4 billion phishing emails are sent every day — about 39,000 per second — and 82.6% of detected phishing emails are now AI-generated. The FTC notes most of this volume comes from botnets, networks of millions of hacked devices, so no personal blocklist can keep pace.
Why is spam so hard for filters to catch now?
AI has stripped out the classic tells like bad grammar and generic greetings, and Hoxhunt's telemetry shows AI-generated phishing that bypassed filters jumped from 4% of reported attacks in November 2025 to 56% in December. Phishing sites also live only about 12 hours on average before takedown — fast enough to dodge blocklists entirely.
How do spammers get my email address in the first place?
Addresses are harvested via web-crawling bots, malware, and purchased breach lists — nearly 1 billion emails were exposed in data breaches in 2021 alone, affecting 1 in 5 internet users. The FTC also warns that websites and apps may sell your address to third parties, which is why consent-based contact practices — like DNC-scrubbed, consent-recorded lead delivery — are the sustainable alternative to the spray-and-pray economy.
Key Takeaways
{ "title": "Blocking Was Never the Answer — Consent Is", "content": "The reason your block list keeps failing isn't a broken email client — it's a math problem. With 3.4 billion phishing emails sent every day from botnets and
This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.