How honeypot addresses are planted

Anti-spam organizations and individual domain owners embed addresses in places invisible or meaningless to a normal human visitor — hidden form fields, HTML comments, or addresses that only appear when a page’s raw source is parsed rather than rendered. A legitimate human visitor browsing the page would never encounter or submit these addresses; only an automated scraper indiscriminately pulling every email-looking string from a page’s source would pick one up.

Why honeypots specifically target scraping, not just any bad list

Unlike a recycled spam trap (which punishes failure to re-verify an aging list), a honeypot exists purely to catch the specific practice of harvesting addresses from the open web without any consent mechanism at all. Hitting one is a strong, almost unambiguous signal to receiving mail servers that a sender’s list wasn’t built through any legitimate opt-in process.

Why this matters even if you don’t scrape yourself

The risk is usually inherited rather than direct: purchasing or renting a list from a third-party data provider means trusting that provider’s acquisition methods, which you typically can’t verify. A single honeypot address mixed into a purchased list carries the same reputational consequence regardless of whether you personally did the scraping.

The only reliable prevention

Build lists exclusively through explicit opt-in (ideally double opt-in) rather than purchasing, renting, or scraping address data from any source, however reputable the vendor claims to be. No verification tool can retroactively undo the reputational risk of a list acquired through scraping — prevention at the acquisition stage is the only fully reliable defense.