Experts warn clicking “unsubscribe” on that boring email could actually be a security risk – here’s why


- Researchers are warning about the “unsubscribe here” button in spam emails
- They can be used to redirect victims to malicious pages
- There are other ways to get rid of spam, so users should be on their guard
If you’ve received a spam email with an “unsubscribe here” button at the bottom, don’t press it – it could do more harm than good.
This is according to TK Keanini, CTO of DNSFilter, who recently revealed pressing such a button sends the recipient away from the safety of the email client and into the open internet, where potentially malicious landing pages are lurking.
In fact, Keanini claims that one in every 644 clicks can lead to a malicious website.
How to unsubscribe, then?
Even if clicking the button doesn’t lead directly to a phishing page, other, more subtle, risks, are lurking as well.
Keanini says that hackers would often place that button just to see who clicks – which would also help them determine which email addresses are active and thus worth targeting further.
The general rule of thumb seems to be – if you don’t trust the company that sent the email, don’t trust the unsubscribe process, either.
So, what’s the alternative? The alternative is to unsubscribe through the email client itself, rather than through the email’s body.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Most email clients have “list-unsubscribe headers”, which appear as built-in buttons and thus don’t include source code, Tom’s Guide explained. “If your email header doesn’t contain a link, you can reply on your spam filters, or try blacklisting the sender instead,” the publication further explained.
Those who don’t have these options can use disposable email addresses when signing up for different services. Most email service providers allow users to create throwaway email addresses, as well. For example, Gmail has a feature called “plus addressing” or “Gmail aliases”, which allow users to modify their address by adding a + and a tag before the @gmail.com address.
That way, the email address used during registration could be [email protected]. Messages will still arrive in the inbox, but they can be easily tracked or filtered.
You might also like
Researchers are warning about the “unsubscribe here” button in spam emails They can be used to redirect victims to malicious pages There are other ways to get rid of spam, so users should be on their guard If you’ve received a spam email with an “unsubscribe here” button at the…
Recent Posts
- NYT Wordle today — answer and my hints for game #1479, Monday, July 7
- Playdate Season 2 review: Taria & Como and Black Hole Havoc
- 3 features that would actually make me pay for a Samsung Health subscription for my Galaxy Watch – and one big problem it needs to avoid
- 250-million pixel virtual projector sets world record on 280-meter tall building used as a screen
- TikTok’s ‘ban’ problem could end soon with a new app and a sale
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022