Material delivers a new solution to a resurgent threat: automated remediations to email flooding attacks.
An email bomb is a messaging-layer denial-of-service attack that floods an inbox with hundreds or thousands of messages in a short window, usually to bury a real alert, set up a follow-on social engineering call, or simply harass the target. It is also called email flooding or subscription bombing. The tactic is thirty years old and still hard to stop, because the individual messages are usually legitimate signup confirmations rather than obvious spam. Material built email bomb protection in response to a real customer attack, and its API connection to the mailbox gives it the historical context to detect a flood and reverse it. This guide explains what an email bomb is, the forms it takes, why it slips past filters, and how to respond.
What Is an Email Bomb?
An email bomb is a deliberate flood of email aimed at a single mailbox or server, designed to overwhelm it and drown out the messages that matter. In security terms it is a denial of service at the messaging layer. What makes it effective is that the flood is assembled from real services: newsletter confirmations, account verifications, and welcome emails that each look benign on their own and only become an attack in aggregate.
Attackers have three main goals:
- Obfuscation: bury a meaningful alert, such as a fraud notice or a password-change confirmation, under a wall of noise so the victim misses it.
- Social engineering setup: follow the flood with a fake IT help-desk call offering to fix the problem, which leads to remote access and malware.
- Harassment: render an inbox unusable to intimidate or disrupt a specific person, from executives to government accounts to reporters.
Types of Email Bombs
Email bombs use several techniques, and most real attacks combine more than one. The most common today is subscription bombing, where scripts sign an address up for thousands of legitimate services at once.
Because the flood is built from genuine signups, each message passes normal spam checks, which is part of why the attack is so hard to filter.
Background: The Email Bomb Threat
Email bombs are not new, but their use has climbed sharply in the last year, along with nastier variations. A scalable attack uses botnets to register a target address across many online services at once, producing a deluge of verification, confirmation, and welcome emails. The tactic is catalogued as Email Bombing, MITRE ATT&CK technique T1667, and the first reported cases date back roughly thirty years, including the 2016 flood of .gov addresses documented by Krebs on Security.
The most damaging pattern pairs the flood with a live social engineering follow-up. Attackers including the Black Basta ransomware group and the actor tracked as Storm-1811 have flooded a target's inbox, then contacted the user over Microsoft Teams posing as IT support offering to fix the spam, and talked the victim into installing a remote access tool that leads to ransomware. This is why an email bomb is rarely the whole attack. The flood is an email event, but the payload is usually an identity and data event: it is a smokescreen for account takeover, wire fraud, or business email compromise. Guidance from CISA and the HHS Health Sector Cybersecurity Coordination Center reinforces the same defensive pattern, and notes that healthcare organizations have been specifically targeted.
Why Traditional Email Tools and Spam Filters Miss It
Email bombs slip past most tools because the messages are technically legitimate. They do not come from known-bad domains, they carry no malicious payloads or links, and the language in a subscription confirmation is benign. Judged one message at a time, few if any would trip a filter, which is exactly the blind spot the attack exploits.
A secure email gateway inspects mail per message before delivery, so it has no concept of volume or velocity across the mailbox. Material takes a different angle. Because it connects by API and analyzes each account's full email history, it can see the one signal that defines this attack: an anomalous spike in incoming volume. That difference is the core of API-based email security, and it is the same reason gateways struggle with the broader set of attacks covered in how phishing emails outsmart users and bypass detection.
Detecting the Undetectable
Material detects email bombs by comparing live inbound volume against a historical baseline for each mailbox, then escalating when the spike is statistically significant. The method is deliberately per-mailbox, because what counts as a flood depends entirely on whose inbox it is.
Building historical models
Material builds a model of each mailbox's normal email volume. What looks like an email bomb for an intern's inbox is a routine Tuesday for a CEO, so a single global threshold does not work. Using message arrival times, Material calculates the average emails received per hour along with the variance and standard deviation, which becomes the baseline for that specific mailbox.
Surge detection logic
Against that baseline, Material compares the live arrival rate, computes a z-score, and escalates when the score crosses a threshold that can be tuned per customer. This suits the wide variation between inboxes, avoiding false alarms for naturally busy accounts while still catching spikes in quiet ones. Material also accounts for trusted internal senders, so a noisy but legitimate internal thread is not swept up as part of an attack.
Remediating the Attack
Detection is only half the job, since the victim already knows something is wrong. Material's advantage is the ability to move and reclassify messages after delivery. When an attack is detected, Material identifies when it started and filters the flood, both the messages already delivered and the ones still arriving, into a dedicated label in Gmail or folder in Outlook. Threat research, organizational context, and machine learning separate the attack wave from legitimate mail, and similarity matching lets one confirmed pattern clear the rest quickly.
From the user's side, they may see the first wave of notifications, then within seconds watch the flood stop and the attack messages move out of the inbox into a new label or folder. Security teams can configure automatic notices to the user at the start and end of the surge. Two design choices matter here. Detected messages are moved, not deleted by default, so anyone can retrieve a legitimate message that happened to land during the window. And the whole response is tunable, with granular settings including the ability to turn automated remediation off entirely, which is the right call for teams that want to review before acting. Because a flood usually arrives as a wave of user reports, this pairs withautomated user report response, described further in how Material automates user-reported phishing at scale.
Incident Playbook: Defusing an Email Bomb Attack
If a mailbox is under an active flood, work the response in four stages. The most important early move is to resist mass-deleting, since that is how legitimate messages get lost.
- Detect: confirm the pattern, dozens or hundreds of subscription and newsletter confirmations in minutes. Identify the affected users, the earliest and latest timestamps, and the most common senders and domains. Note baseline deviation in volume and any new rules or forwarding.
- Contain: temporarily rate-limit or hold bulk and newsletter categories for affected mailboxes, auto-label and mute bulk items to restore signal, and review any new auto-forwarding or inbox rules created during the surge. Watch for the follow-on contact, since the fake IT call is the real danger. See how to detect and defend against social engineering threats.
- Eradicate: bulk-unsubscribe using the List-Unsubscribe header where present, remove subscriptions created during the window, quarantine or delete the time-bounded attack wave, and block abusive senders and domains. Remove any malicious rules or redirects.
- Recover: re-run alert and keyword searches over the attack window to confirm nothing critical was missed, gradually lift rate limits, keep heightened monitoring for 24 to 48 hours, and document what changed for the runbook.
Stopping Email Bombs Before They Bury What Matters
Email bombs are old, but that does not make them any less disruptive. Most of the email security market still relies on blocking inbound threats one message at a time, which overlooks a flood assembled from legitimate mail, and the account and data risk hiding underneath it. Material's approach to email and cloud workspace security detects and remediates email bombs in seconds, with no effort from the user or the security team, and without deleting the legitimate messages caught in the wave. To see where your workspace stands, run the free Workspace Security Scorecard, or contact us for a demo.
Email Bomb FAQs
What is an email bomb?
An email bomb is a messaging-layer denial-of-service attack that floods an inbox with hundreds or thousands of messages in a short window to bury a real alert, set up a social engineering call, or harass the target. It is also called email flooding or subscription bombing, and it is hard to filter because the individual messages are usually legitimate signup confirmations rather than obvious spam.
Why am I suddenly getting thousands of emails?
A sudden flood of subscription and confirmation emails is usually an email bomb, and it is often a smokescreen for fraud or an account takeover happening at the same time. Check immediately for password-reset notices, new login alerts, or financial confirmations buried in the noise, and do not mass-delete, since that can hide the one message that matters. Then secure the account and filter the flood into a separate folder.
Is email bombing illegal?
In most jurisdictions, deliberately flooding someone's inbox to disrupt access is treated as a form of denial-of-service attack and can violate computer-misuse and anti-fraud laws, especially when it is paired with fraud or extortion. Enforcement and specific statutes vary by country and region, so this is general information rather than legal advice. If your organization is targeted, preserve logs and report it through the appropriate channels.
How do you stop an email bomb?
You stop an email bomb by filtering the flood out of the inbox rather than deleting it, blocking abusive senders and domains, and checking for fraud or account compromise underneath. Rate-limit or hold bulk and newsletter mail for the affected mailbox, unsubscribe using the List-Unsubscribe header, and review any new forwarding or inbox rules. A platform like Material automates this by detecting the volume spike and moving the attack wave into a separate label within seconds.
What should I do first if I am being email bombed?
First, look for what the flood is hiding, since email bombs are commonly used to obscure fraud in progress. Search for password-reset emails, new-device login alerts, and payment or wire confirmations before you clear anything. Then move the flood into a separate folder instead of deleting it, secure the targeted account with a password change and MFA, and watch for a follow-up call or message claiming to be IT support.
How does Material detect and stop email bombs?
Material detects email bombs by modeling each mailbox's normal email volume and escalating when live volume spikes past a tunable z-score threshold, so it catches floods in busy and quiet inboxes alike. It then moves the attack wave, both delivered and incoming messages, into a dedicated label or folder, keeping legitimate mail in place and notifying the user. Because messages are moved rather than deleted by default, anything caught by mistake can be retrieved. See email security.
Can AI-powered email security stop inbox flooding attacks?
Yes. AI-powered email security stops inbox flooding by detecting the behavioral signal a per-message filter cannot see, an anomalous spike in incoming volume against a learned baseline, then automatically remediating the wave. Material combines this volume analysis with organizational context and similarity matching so one confirmed pattern clears the rest, and the response can be tuned or turned off entirely for teams that want to review first.
.png)


