The Spam That Didn’t Kill Email
or, how a shared thing with no fence and no fine survived the people who tried to strip it for parts
Jump to the simulation: turn off the filter and watch the commons drown — then turn it on and watch a defense evolve that never quite wins
Cast your mind back to an inbox around 2003. You open it in the morning and there are forty new messages, and maybe three of them are for you. The rest are a pharmacy you never visited, a Nigerian official who has chosen you specifically, a watch that is definitely a real Rolex, and a stranger who is delighted to inform you about your enlargement options. You delete, delete, delete, and by the time you find the note from your sister it feels like sorting mail out of a snowdrift. Everyone you knew was doing the same arithmetic every morning: is this thing still worth using?
That was a fair question, because email in 2003 was a textbook case of a doomed commons. Think about what a spammer actually needs. Sending a million messages costs a rounding error — a little bandwidth, a borrowed machine. There is no gate at the front of email and no bouncer; anyone can send anything to anyone. And there is no fine. Nobody could reach out of your inbox and charge the spammer a nickel for wasting your morning. Free to abuse, nobody in charge, no penalty for cheating — that is the exact recipe that turns a green pasture into a mud pit. By the logic of the herders and their overgrazed field, email should have died. Sally should have given up on it a decade ago.
And yet here you are, reading a link somebody emailed you. The thing did not die. That is the puzzle worth sitting with — not “isn’t spam annoying,” but how is there anything left to annoy? A commons this exposed, this cheap to plunder, was supposed to end up as a wasteland. Instead it settled into something you still use every day. Something saved it, and it wasn’t a fence.
Two ways to save a commons
There are two ways to rescue a commons, and it helps to hold them apart. The first is the one Elinor Ostrom spent a career documenting: govern the people. Get the users in a room, agree on limits, watch each other, punish the cheaters. That is how real fisheries and mountain pastures and irrigation systems have kept themselves alive for centuries — not through a distant government, but through a community that made its own rules stick. It is a beautiful mechanism, and for email it barely worked at all.
You can watch it not work. In 2003 the United States passed the CAN-SPAM Act, a law with rules about honest subject lines and working unsubscribe links. A year later, by one accounting, fewer than one in a hundred spam messages bothered to comply. The reason is baked into the medium: your spammer is in another country, behind a hijacked computer, under a name that isn’t his. There is no room to gather the users into, and no sheriff whose writ reaches the guy renting a botnet three borders away. Governing the people assumes you can find the people. Email cheating is anonymous and global, and that is precisely the crack Ostrom’s solution falls through.
So email took the other road. If you cannot govern the users, you can harden the resource — change the thing itself so that abusing it stops paying. You don’t need to catch the spammer or fine him or even know his name. You just need to make his million messages land in a folder nobody opens. Do that reliably enough and spamming a given trick stops earning, and a thing that stops earning starts to die on its own. No court required. This is the move that saved email, and the interesting part is that nobody built it on purpose. It grew.
- Spam is nearly free to send, so as long as any trick still reaches inboxes, someone will send a flood of it.
- A filter learns what the current flood looks like — the words, the links, the senders — and starts dropping messages that match, faster than a person could ever sort them by hand.
- Once a trick is being caught, it stops paying, so the spammer has to re-tool — invent a new disguise the filter hasn’t learned yet. That costs him time and money. Then the filter learns the new one. Repeat, forever.
Notice what that loop does and doesn’t promise. It never promises to end spam — there is always some fresh trick in its first days, sailing through before the filter catches on. What it promises is subtler and more durable: it makes cheating expensive, and it keeps making it more expensive, so the flood that reaches you shrinks to a trickle you can live with even though nobody ever wins. Below is that arms race, stripped to its bones. Give it a look before we walk through how it actually played out in the world.
The Experiment
The wide strip at the bottom is the spammer’s bag of tricks — every possible disguise, laid out left to right. Each glowing dot is a spam campaign, camped on whatever trick it’s using now. The green shadow creeping across that strip is the filter’s knowledge: wherever it has learned to recognize a trick, the green rises and messages there get dropped. The calm blue band is what your real mail looks like — the filter learns to leave that alone. Up top is the only number you feel in your gut: the share of spam that reaches your inbox, week after week. It opens paused; press Begin when you’re ready.
Things to try:
Load No filter (1998) and press Begin. Nothing chases the spam, so the line pins to the top — almost every spam message reaches you — and the “junk” readout climbs past 80%. This is the drowning inbox, the commons on its way to a wasteland. It’s where email was actually headed.
Switch to A filter vs. lazy spam. Now a filter learns, and the spammers just sit there using the same tricks. Watch the line dive from the top and flatten near the floor. Against an enemy that doesn’t adapt, defense is a clean, boring win. If spammers were lazy, this page wouldn’t need to exist.
Now the real world: load The arms race. The filter still learns, but when a campaign gets caught it jumps to a fresh trick. The line stops flattening and starts sawing — a spike each time someone breaks into new territory, a slide each time the filter catches up. It settles low, but it never reaches zero, and it never will.
Keep the arms race running and watch the times re-tooled counter, not the line. It climbs and climbs. That number is the whole point: the filter isn’t erasing spam, it’s taxing it — forcing the spammer to keep paying for new disguises. The protection isn’t a wall. It’s a bill that never stops coming due.
Load Turn the filter up, or just drag filter learning speed to the right. The line does drop lower — but glance at the re-tool counter: it climbs even faster. A sharper filter doesn’t win the war. It raises the tax. You buy a quieter inbox by making the other side spend more, not by making them leave.
Push how fast spammers re-tool to the right and watch them claw some back — the line rides a little higher, the counter runs away. Then notice the blue band the whole time: real mail almost never gets blocked. The filter learned which features are yours and left them be. That restraint is what keeps the cure from being worse than the disease.
How it actually happened
Everything in that little box happened for real, in order, with names and dates. The “filter that learns” showed up in earnest in August 2002, when a programmer named Paul Graham posted an essay called A Plan for Spam. The idea was almost impudent in its simplicity: stop writing rules by hand and let the math count. Feed a program a pile of spam and a pile of real mail, and it learns on its own that Viagra and free and a certain kind of link lean spammy, while your sister’s name and your project’s jargon lean legitimate — then it scores each new message by the words it carries. Within a year that Bayesian trick was inside SpamAssassin and Thunderbird and a dozen other tools. It is the green shadow in the simulation, learning the shape of the current flood.
It didn’t arrive alone, and no single piece was the answer. Blocklists came first, actually — back in 1997, Paul Vixie and others started keeping public lists of the machines caught spewing spam, so a mail server could refuse them at the door. Later came a harder layer aimed at the disguise itself: standards with names like SPF, DKIM, and DMARC that let a domain prove a message really came from it, so a spammer can no longer cheaply pretend to be your bank. Blocklists, content filters, authentication — three different defenses, invented by different people at different times, no committee coordinating them. Together they grew into something that behaves like an immune system: distributed, always learning, no single cell in charge, wrapped around a resource that has no owner. Nobody designed the immune system of email. It assembled itself around the commons because every piece of it paid for itself the day it shipped.
You can even see the one time the world tried the blunt, governing-style fix. In November 2008 investigators got a single sleazy hosting company called McColo cut off from the internet — one company that happened to sit under a big share of the world’s spam machinery. Global spam fell by roughly two-thirds overnight. It was glorious. It also didn’t last: within weeks the botnets found new homes and the flood came back. That is the shape of a takedown — a deep, thrilling notch in the line, and then the water rising again. Compare it to the filter, which never scores a knockout but never stops working either. One is a raid. The other is weather.
Nobody ever wins
I want to be careful not to let this curdle into a fable about how cleverness always wins and the good guys come out on top. That isn’t the lesson, and the simulation is honest about why.
Look again at what actually happened up on that sawing line. It never reached zero. It never will. What biologists call a Red Queen race — after the character in Through the Looking-Glass who runs as fast as she can just to stay in the same place — is not a war anybody wins; it is a standoff both sides pay to maintain, step for step, without end. Spam today is still something like half of all email sent. The filters got good enough that you mostly don’t see it, which is a real and lovely thing — but “you don’t see it” is not “it’s gone.” The flood is still out there, breaking against a seawall that has to be rebuilt every single day. The peace you enjoy is maintained, not permanent. Stop maintaining it and it rots in a season.
And the cure had a price of its own. Filtering spam well takes enormous scale — oceans of mail to learn from, armies of engineers to keep the models fresh. Small players can’t really do it anymore, which is a large part of why your mail now flows through a handful of giants like Google and Microsoft. The commons survived by hardening, and hardening favored whoever could afford the biggest walls, and so a thing that began as everyone’s open field is now mostly tended by a few enormous landlords. That is not a tragedy and it is not a triumph. It is a trade, and it is worth seeing clearly rather than cheering.
So hold the two roads side by side, because email is a clean natural experiment in the difference. You can save a commons by governing the people who use it — Ostrom’s way, the fishermen and the pasture, and it works where you can find the people and make the rules bite. Or you can save it by hardening the resource until abuse stops paying — email’s way, no permission and no plan, an immune system that grows itself. The same pitiless bookkeeping runs underneath both: cheating survives exactly as long as it profits, and dies when it doesn’t. It is the survivors-reproduce algorithm again, running here on tricks and filters instead of on beaks and finches — the universe doesn’t care whether the thing evolving is a bird or a con.
The universe did not save your inbox because it loves you, and it did not bless the arrangement it left you with. It permitted a defense to evolve, on terms — and it permits the flood to keep testing that defense on the same terms, forever. What stands between you and the wasteland isn’t a fence somebody built and walked away from. It’s a truce, held up by machines that never sleep, quietly charging the cheaters more than the cheat is worth. Open your inbox tomorrow. The three real messages will be near the top, the snowdrift will be somewhere you never have to look, and the whole invisible arms race will have run another night on your behalf — not won, never won, just held.
- Graham, P. “A Plan for Spam” (August 2002) — the essay that put Bayesian filtering into wide use. paulgraham.com. Background on its adoption in SpamAssassin, Thunderbird, and others: Naive Bayes spam filtering (Wikipedia).
- The McColo shutdown (November 2008) and the ~two-thirds overnight drop in global spam — and its temporary nature: McColo (Wikipedia); analysis by Richard Clayton, “How much did shutting down McColo help?” Light Blue Touchpaper.
- CAN-SPAM Act of 2003 and its limited effect (well under 1% compliance the following year; enforcement and jurisdiction problems): CAN-SPAM Act (Wikipedia); retrospective by Brian Krebs, “Is it Time to Can the CAN-SPAM Act?” Krebs on Security.
- Spam as a share of email traffic — a peak around 80% in 2011, roughly half of all email today: Statista: share of global e-mail traffic.
- Sender authentication — the “harden the identity” layer: SPF, DKIM, and DMARC. Early DNS-based blocklists (the MAPS RBL, Paul Vixie & Dave Rand, 1997): DNS blocklist (Wikipedia).
- Ostrom, E. Governing the Commons (1990) — the other way to save a commons, by governing its users. Elinor Ostrom (Wikipedia).
- Van Valen, L. “A New Evolutionary Law” (1973) — the Red Queen: running to stay in place. Red Queen hypothesis (Wikipedia).