Disclaimer: Creating an account to hide behind is like creating a false address so you can hide. Almost all cybercrime, including spamming, starts with creating these accounts and not use them like "normal" people do. Probably 90% of all gmail accounts that are created today probably need to be RED-flagged by definition, monitored from day 1. Is it used for NORMAL correspondence, used frequently for that, OR NOT? It is THAT easy. It's like can someone live in a post box?
Recommendation to Google/Gmail: Stop the Spammer, Not Just the Spam
Gmail already has extremely sophisticated spam detection. Google says its systems block billions of unwanted messages and use signals such as user reports, IP addresses, domains, and sender behaviour. Google also prohibits spam, fake accounts and the use of multiple accounts to circumvent restrictions.
My recommendation is simple:
Move the primary point of detection from the spam message to the creation and behaviour of the account.
A newly created Gmail account should be evaluated against Google's enormous database of established, legitimate account behaviour.
Google can measure:
- how many Gmail accounts already exist and remain active;
- the normal rate at which genuinely new users create accounts;
- how new accounts normally behave during their first days and weeks;
- how frequently legitimate users create multiple accounts;
- how quickly abusive accounts begin sending mail;
- how often newly created accounts are abandoned and replaced.
This creates a measurable baseline.
A newly created account that immediately behaves radically differently from normal users should receive a "RED FLAG" and increased scrutiny.
Consider this example:
`[email protected]`
`[email protected]`
`[email protected]`
`[email protected]`
These addresses deliberately manipulate the same apparent identity by varying the placement of dots.
Importantly, Gmail itself states that dots do not create different Gmail identities: dotted versions belong to the same underlying Gmail address.
Therefore, the relevant question is not merely:
"Is this particular email spam?"
It is:
"Who is creating these accounts, why are they creating them, and what other accounts and activity are connected to them?"
If the behavioural evidence establishes deliberate abuse, Google should escalate from automated filtering to account termination, identification of the underlying operator, preservation of evidence, and—where appropriate—referral to law enforcement or civil litigation.
Google already states that it automatically detects and disables accounts made for abuse and prohibits multiple accounts used to circumvent its policies.
Google therefore already has the policy foundation.
What is missing, from the user's perspective, is a stronger emphasis on finding the person behind the disposable accounts.
The principle
Don't endlessly catch the spammer's new addresses. Catch the spammer.
If creating a disposable Gmail identity is likely to trigger an immediate investigation and the loss of the underlying accounts, the economics of professional spamming change completely.
The goal should not simply be:
"99.9% of spam doesn't reach the Inbox."
The goal should ultimately be:
"Creating Gmail accounts for organized abuse is no longer a viable business model."
Google is one of the few organizations in the world with the technical scale, behavioural data, and legal resources necessary to pursue this strategy effectively.
It should use them.