What email marketing is and why companies do it

Email marketing is when a company sends you promotional messages, newsletters, or product updates to your inbox. They do this because email is cheap to send at scale and because people who signed up are more likely to buy than people who see a random ad. The company builds a list of email addresses — either from people who checked a box on their website, bought something before, or in some cases bought the list from a data broker — and sends the same message to thousands or millions of addresses at once.

The reason this matters for your security and privacy is that your email address is now stored in a company's database, tied to information about what you clicked, when you opened the message, and sometimes what you bought afterward. That database can be hacked. It can be sold. It can be used to build a profile of your interests and habits. And once your address is on a marketing list, it often stays there unless you actively remove it.

Key Takeaways

  • Every time you receive a marketing email, the sender knows your address works and can see whether you opened it, which tells them you are an active target.
  • Unsubscribe links in legitimate marketing emails actually work and are required by law in most countries — using them removes you from that specific list.
  • Creating a separate email address just for shopping and signups keeps marketing mail away from your main inbox and limits what one breach can expose.
  • Spam filters catch most unsolicited marketing, but phishing emails disguised as marketing from real companies are harder to spot and more dangerous.
  • Marketing lists are bought and sold between companies, so signing up for one retailer's newsletter can lead to mail from others you never contacted.

How companies track you through marketing emails

When you open a marketing email, the sender can see that you opened it. They do this by embedding a tiny invisible image in the message — when your email client downloads that image to display the message, the server logs that a request came from your address at a specific time. This tells the company that your address is active and that you read their message. If you click a link in the email, they can track which link you clicked and when.

Over time, this data builds a picture of what interests you. If you open emails about winter coats but delete emails about summer sales, the company learns that and sends you more winter content. If you never click through to their website, they know engagement is low and may stop sending to you or move you to a less frequent list. This information is valuable — it helps them predict who will buy — and it is stored in their database along with your address.

The tracking happens whether you are on a legitimate company's list or a spammer's list. The difference is that legitimate companies usually have a privacy policy that says what they do with this data, and they are required by law in most places to let you unsubscribe. Spammers do not care about the law and will keep sending regardless.

The difference between legitimate marketing and phishing disguised as marketing

A legitimate marketing email comes from a company you actually signed up with or bought from. It has an unsubscribe link at the bottom — in the United States, the CAN-SPAM Act requires this; in Europe, GDPR requires it. The sender's address is real and matches the company's domain. The links go to the company's actual website. You can verify this by hovering over links before you click them to see where they actually point.

A phishing email pretends to be from a real company but is actually from a criminal. It might say "Confirm your Amazon account" or "Update your Apple ID password" and include a link that looks like it goes to Amazon or Apple but actually goes to a fake website designed to steal your password. These are dangerous because they exploit the fact that you trust the real company. The email might look almost identical to a real marketing message, complete with the company's logo and formatting.

The safest rule: never click a link in an email to log into an account or enter sensitive information. Instead, go directly to the company's website by typing the address into your browser or using a bookmark you created yourself. If the email is real, the company's website will show you the same information. If it is phishing, you will have avoided the fake site entirely.

What happens when a marketing list is hacked or sold

Marketing databases are targets for hackers because they contain thousands or millions of email addresses, often paired with names, purchase history, and sometimes payment information. When a company's database is breached, criminals gain access to all of that. They can use the addresses to send phishing emails, sell the list to other criminals, or use it to target you with scams.

Even without a hack, marketing lists are legally bought and sold between companies. When you sign up for a newsletter from one retailer, you might end up receiving mail from similar retailers you never contacted — because the first company sold or shared your address with partners. Some companies do this; others do not. The privacy policy should say whether they do, but most people do not read it.

Once your address is on a list, it is hard to remove completely. Unsubscribing from one company's mail does not remove you from lists that company sold to others. You may have to unsubscribe from each sender individually. Some addresses end up on so many lists that they become part of the permanent spam ecosystem — criminals buy them in bulk because even a tiny response rate is profitable.

How to reduce marketing email and protect your address

The most effective strategy is to use a separate email address for shopping, signups, and anything that might end up on a marketing list. This keeps promotional mail out of your main inbox and limits what one breach can expose. You can use a free email account from Gmail, Outlook, or Yahoo for this purpose. Some people create a new address for each major retailer or service; others use one catch-all address for everything non-essential.

When you do sign up for something, read the checkbox before you click it. Many websites have a pre-checked box that says "Yes, send me marketing emails" — uncheck it if you do not want mail. Some sites make this hard to find or use confusing language, but the option is usually there.

For mail you already receive, use the unsubscribe link at the bottom of the email. It works on legitimate marketing mail. It may take a few days to process, and you might receive one more message confirming the unsubscribe, but you will stop getting mail from that sender. Do not reply to the email asking to be removed — that just confirms your address is active and may result in more mail.

Do not click "report as spam" on legitimate marketing mail you straightforward do not want anymore. Use unsubscribe instead. Reporting as spam trains your email filter that this sender is unwanted, but it does not remove you from their list, and it can sometimes cause legitimate mail to be filtered incorrectly in the future.

Why marketing emails are a security risk even when they are real

A real marketing email from a real company is still a security risk because criminals use them as cover. They send phishing emails that look almost identical to legitimate marketing from companies you know. Your brain is trained to trust marketing from Amazon or Apple or your bank, so you are more likely to click a link without thinking carefully about where it goes.

The more marketing mail you receive, the harder it is to spot the fake ones. If your inbox is full of newsletters and promotional messages, a phishing email blends in. This is another reason to keep marketing mail separate — a phishing email in a dedicated marketing folder is easier to spot as suspicious because you know what legitimate mail from that sender looks like.

Marketing emails also train you to enter information in response to email requests. A real company might email you asking to confirm your address or update your payment method. A criminal can copy that format and send you to a fake site. The safest habit is to never respond to any email request for sensitive information by clicking a link — always go to the company's website directly.

Email marketing laws and what they mean for you

In the United States, the CAN-SPAM Act requires that marketing emails include a real unsubscribe option and a real physical address for the sender. It does not ban unsolicited marketing — companies can send to you without permission — but it does require them to honor unsubscribe requests within 10 business days. Violations can result in fines, but enforcement is inconsistent and many spammers ignore the law entirely.

In Europe, the GDPR requires companies to get your permission before sending marketing email. This is why European websites often ask you to check a box to receive mail, and why unsubscribing is taken more seriously. If a company violates GDPR, the penalties are severe.

In Canada, CASL (the Canada's Anti-Spam Legislation) is even stricter than GDPR — companies must have explicit permission before sending any marketing mail, and unsubscribe requests must be honored within 10 business days. The rules vary by country, but the trend is toward requiring permission and making it straightforward to opt out. This means that in most places, if you unsubscribe from a legitimate sender, they are legally required to stop.

Frequently Asked Questions

Is it safe to click unsubscribe links in emails I do not recognize?

Unsubscribe links in legitimate marketing emails are safe and required by law. However, if the email looks suspicious — misspelled sender address, urgent language, requests for passwords — do not click anything. Legitimate companies do not ask for sensitive information via email. When in doubt, go to the company's website directly and manage your preferences there instead of clicking the email link.

Why do I get marketing emails from companies I never signed up with?

Your address was likely sold or shared by another company, or it was purchased from a data broker who collects addresses from public sources. This is legal in most places if the original company's privacy policy mentioned it. Unsubscribe from each sender individually. If you see a pattern — for example, multiple furniture retailers after you visited one furniture site — that company probably shared your address with partners.

Can I get my email address removed from all marketing lists at once?

No. There is no central registry where you can remove your address from all marketing lists. You have to unsubscribe from each sender individually. Some email providers offer filters that automatically sort marketing mail into a separate folder, which makes it easier to ignore. Creating a separate email address for shopping and signups is the most effective way to keep marketing mail away from your main inbox.

What should I do if I get marketing emails from a company I never heard of?

Use the unsubscribe link if one is present and the email looks legitimate. If there is no unsubscribe link, or if the email looks suspicious, mark it as spam and delete it. Do not reply to the email or click any links. If you keep getting mail from the same sender after unsubscribing, that is a sign they are not following the law, and you can report them to your email provider or your country's consumer protection agency.

Does opening a marketing email put my computer at risk?

Opening a marketing email itself is safe — the risk comes from clicking links or downloading attachments. If you open an email and just read it without clicking anything, you are not at risk. However, opening an email does tell the sender that your address is active, which may result in more mail. This is why some people use email filters to automatically delete marketing mail without opening it.