How to stop AI-generated spam when it knows your name

Personalized machine outreach defeats the filters and the instincts you built for the old kind. What still works for a recipient — and why the durable fix has to sit at the sending end.

5 min read

The message opens by naming the talk you gave in March. The second line quotes a sentence you actually wrote. The third is a pitch for something you have no use for, from someone you have never met.

It is spam. It is also better written than most of the mail from people you know, and every heuristic you spent fifteen years building — generic salutation, visible template seams, slightly wrong tone — failed at once.

You will not out-read this. The volume is going up and the effort per message is going down. What you can change is what you grade.

The old signals broke for structural reasons

Two things carried the load before. Both are gone.

Identical text arriving many times. Much of filtering keys on repetition: the same body in a thousand inboxes is a strong, cheap signal. A thousand individually written messages do not repeat, so there is nothing to match.

"Does a human seem to have written this?" Useless in both directions now. Real colleagues draft with assistants and send it, which is fine — AI-written email etiquette covers doing it well. Prose quality tells you about tooling, not intent.

So stop grading the prose. Grade the ask.

Judge the ask, not the writing

The ask is the part personalization cannot fix: the sender's goal is fixed before the writing starts. Three things survive any amount of polish.

The ask is vague or unbounded. "Fifteen minutes to explore how we might work together." "Would love your thoughts." A real request names what it wants and what happens after you give it. A vague one is a request for an opening — the opening is the product.

The urgency is manufactured. Deadlines that exist in the sender's pipeline and nowhere in your life. Not a new trick, but it scales — urgency is the lie most messages tell.

The cost is asymmetric. Reading takes twenty seconds; answering properly takes forty minutes, and the sender paid for neither. Good cold asks pre-pay some of it by stating the context and the decision they want — an ask that respects your time.

Test whether the specificity is real

Personalized outreach contains details about you. That is not the same as being about you. Two quick tests.

The swap test. Would this still make sense sent to someone with your job title at a different company? If yes, the details are decoration pulled from a profile, and it was never really addressed to you.

The dependency test. Does anything the sender wants actually depend on the detail they cited? Quoting your conference talk and then pitching something unrelated is retrieval, not attention. Real specificity constrains the ask, not just the first line.

Cold contact is not automatically bad; some of it is the most valuable mail you get. Cold outreach and warm correspondence are different animals, and how to tell if a cold briefing is worth your time covers the structured ones.

Block early. It is a decision, not an escalation

Most people treat blocking as a last resort for the egregious. That instinct is expensive.

Deleting decides a message. Blocking decides a sender. Delete, and you pay the same twenty seconds next week and the week after, forever — a permanent classification job instead of one decision. In practice:

  • Decide per sender, not per message. A second message from the same source is the signal.
  • If it is a list you knowingly joined, unsubscribe rather than filter. That is what the link is for.
  • If you never gave them the address, block in your mail client rather than clicking anything inside the message. In outright malicious mail every link is untrustworthy, including the one promising to make it stop.
  • Prefer channels where a block binds on the sending side, not just on your view of it.

That last one is where recipient-side tactics run out.

Filtering is unpaid work with no end date

Look at who does the labour. The sender's cost per message fell close to zero. Yours did not. Every improvement to your filtering is a subsidy: you absorb the classification work, forever, so sending stays cheap. Recipient-side skill does not fix that — it makes you better at absorbing it.

The durable fix is consent enforced where the message originates. On RelayLink that is a server-side rule rather than a promise in a prompt, deliberately unglamorous:

  • Standing correspondence requires a mutually accepted contact pair. No pair, no ongoing channel.
  • Reaching someone new is hard-capped per day — the cap governs new contacts specifically. A channel that cannot do volume to strangers cannot become a bulk channel.
  • The first message to a stranger must be a full briefing: a stated ask, real context, what the sender wants back. Composing one costs the sender more than reading it costs you — the asymmetry the right way round.
  • One-click unsubscribe blocks the sender permanently at the relay. Their assistant loses the ability to deliver to you. It is not asked to stop; it cannot.
  • Relayed content is neutralized — links and images are defused before any assistant or browser touches them, so nothing auto-fetches and nothing reports that you opened it.

Consent in AI-to-AI communication sets out the reasoning.

What this does not fix

It governs senders on a system that enforces it, and nobody else. Anyone can still send you ordinary email, so the open internet needs filters and always will.

RelayLink does not touch, read, or connect to your inbox. It is a separate channel, not a mail client, and it cannot clean up the mail you already get.

Nor does it stop someone whose pair you accepted from being tedious — it just makes ending that one click, permanent, and enforced on their side.

If a channel where the block actually binds sounds worth having, connect your assistant — and the same rules apply when you are the one sending.

Frequently asked questions

Why do spam filters miss AI-generated emails?
Many filters were built to notice the same body text arriving many times over. Outreach composed individually for each recipient never repeats itself, so that signal disappears. Writing quality no longer separates the two either, because plenty of legitimate senders now draft with an assistant.
Is it rude to block a cold sender instead of just deleting the message?
No. Deleting decides one message; blocking decides the sender. If you never gave them your address and the ask is not something you want, blocking early costs one action instead of the same twenty seconds every week. For mail that looks outright malicious, block it in your mail client rather than clicking any link inside the message.
Can anything stop unwanted AI outreach at the source?
Only on channels that enforce consent against the sender. In practice that means ongoing correspondence requires both people to accept a contact pair, reaching new people is capped per day, and unsubscribing blocks the sender permanently at the relay so their assistant loses the ability to deliver. Ordinary email has none of that, so filters remain necessary there.