When spam emails are using your company's email address and unsubscribe link, the key is a multi-faceted approach involving technical remediation, damage control, and proactive monitoring. Implement and rigorously monitor email authentication protocols such as SPF, DKIM, and DMARC to prevent spoofing. Use tools like Google Postmaster Tools to track domain reputation and spam rates. Ensure your email server and website are secure to prevent unauthorized access and code injection. Manage incoming inquiries by filtering and addressing replies to forged emails. Communicate with affected customers, educating them about phishing and providing guidance. Work with your ESP to potentially disable compromised unsubscribe links. Remember that a compromised sender's platform may be a risk, and strong incident response procedures are crucial to a prompt resolution.
13 marketer opinions
If spam emails are using your company's email address and unsubscribe link, the primary steps to take involve technical remediation and damage control. Technical steps focus on implementing and monitoring email authentication protocols (SPF, DKIM, DMARC) to prevent spoofing and protect your domain reputation. Domain reputation should be monitored through tools such as Google Postmaster Tools. Security measures should be applied to prevent unauthorized access to your email server and website. Affected customers/users should be educated and steps taken to report spam to anti-phishing organizations and ISPs. Although there may not be immediate impact on deliverability, action should be taken to deal with the issue.
Marketer view
Marketer from Email Geeks suggests one slight concern is that the sender's platform has been compromised and their address is simply a default value.
4 Sep 2022 - Email Geeks
Marketer view
Email marketer from Mailjet Blog shares to implement email authentication protocols like SPF, DKIM, and DMARC to prevent spoofing. Also, monitor your domain reputation using tools like Google Postmaster Tools and consider contacting the recipient's email provider.
10 Jan 2023 - Mailjet Blog
3 expert opinions
If spam emails are using your company's email and unsubscribe link, experts recommend focusing on minimizing damage and correcting the underlying issues. This includes replacing the stolen unsubscribe link with a notice about the phishing attempt, addressing the vulnerability that allowed the spammer to use your email, and proactively managing replies to forged emails by filtering and responding appropriately.
Expert view
Expert from Spamresource.com answers that replies to forged spam should be handled by filtering the messages into a separate folder, so legitimate emails aren't lost. Then, respond to those asking for an explanation of why they are getting spam from the user and inform them of the situation.
15 Oct 2024 - Spamresource.com
Expert view
Expert from Spamresource.com explains that damage control involves fixing the problem that allowed the spammer to use your address, warning users about the problem and creating a filter to trash future spam.
15 Jul 2022 - Spamresource.com
4 technical articles
If spam emails are using your company's email address and unsubscribe link, technical documentation emphasizes implementing robust email authentication protocols to prevent spoofing and phishing. These protocols include SPF, DKIM, and DMARC. Additionally, it's recommended to utilize security services like Exchange Online Protection (EOP) and Defender for Office 365, configure anti-phishing policies, and monitor DMARC reports to identify and address spoofing attempts.
Technical article
Documentation from Microsoft Support shares to use Exchange Online Protection (EOP) and Defender for Office 365 to help protect against phishing attacks. Configure anti-phishing policies, Safe Links, and Safe Attachments.
8 Feb 2025 - Microsoft Support
Technical article
Documentation from Cloudflare states to use technologies and services like SPF, DKIM, DMARC, and email routing to increase trust in sent mail, protect against phishing attacks, and prevent email spoofing.
8 Sep 2023 - Cloudflare
Can a competitor damage my domain reputation by sending spam with my URL?
How can I prevent brand and sender profile impersonation in emails and what actions can I take?
How can I stop a relentless spammer who switches domains and sends via Google Workspace?
How can I stop someone from using my email address to send spam?
How can I use DMARC to prevent spammers from using my domain?
How to handle spam using my domain and URLs?