Spam is unwanted bulk email, almost always commercial, sent to a huge, unresearched list with no attempt to deceive you into acting. Phishing is a deliberate attempt to steal your credentials, money, or data by impersonating someone you'd trust - a bank, a coworker, a delivery company - and it specifically wants you to click, reply, or hand something over. Both show up uninvited, which is why people lump them together, but only one of them is actually trying to con you.
- Intent is the dividing line, not volume: spam wants your attention, phishing wants you to hand over something valuable - credentials, money, data, or access.
- Bulk-sending patterns are one signal spam filters use, but a single, individually-worded phishing email gives them far fewer of those patterns to work with.
- Every phishing email is technically unwanted mail, but most unwanted mail has no intent to defraud you.
- Lottery and inheritance scams sit in a blurry middle - unsolicited like spam, deceptive like phishing, but without impersonating a specific real company.
- Reporting the right way matters: your provider's dedicated "phishing" option gives it a more specific abuse signal than marking the same message as plain junk.
- The more an attacker personalizes a message, the less it resembles spam - and the fewer bulk-level patterns it leaves for a filter to catch.
Spam vs. phishing: the core difference
The real difference between phishing and spam is intent, not inbox placement or volume. Spam is unsolicited bulk email whose primary purpose is commercial - selling a product, promoting a service, or driving traffic - with no attempt to trick you into doing anything beyond reading an ad. Phishing is a social-engineering attack that borrows a trusted identity specifically to get you to act: click a link, confirm a login, wire money, or install something you shouldn't. A newsletter you never signed up for is spam. An email claiming your bank account is locked, with a "verify now" button, is phishing - regardless of whether it was blasted to a million addresses or crafted for one.
That distinction matters in practice because the two problems get handled by different machinery. Commercial email is regulated in the US under the FTC's CAN-SPAM Act, which has required accurate sender headers, non-deceptive subject lines, and a working opt-out mechanism since 2003 - a legal baseline, separate from and on top of which mailbox providers layer their own bulk filtering and reputation systems. Major providers are generally much better at catching that large-scale bulk traffic than they are at catching a single, carefully targeted deceptive message, because phishing isn't defined by who it was sent to or how many copies went out - it's defined by the lie it's telling, and lies don't have a header field.
Spot the difference: spam vs. phishing
The table below lines up the signals that actually separate the two, since "it's unwanted" applies equally to both and tells you nothing useful on its own.
| Signal | Spam | Phishing |
|---|---|---|
| Primary goal | Advertise a product, service, or website | Steal credentials, money, or data |
| Targeting | Broad, unresearched mailing list | Anywhere from mass-sent to individually researched |
| Borrowed identity | Usually none - sender is who it claims to be | Typically impersonates a trusted person or brand |
| Asks you to act | Rarely beyond "buy" or "click to browse" | Yes - log in, verify, confirm, pay, or download |
| Legal framework | Regulated commercial email (CAN-SPAM Act) | Fraud - no legitimate legal framework applies |
| Caught by bulk spam filters | Usually, for mass-sent messages | Only the mass-sent, templated variety |
Why your spam filter doesn't catch every phishing email
Bulk-sending patterns - the same message hitting thousands of inboxes from the same infrastructure - are one important signal spam filters use, but modern inbox filtering also weighs sender reputation, authentication records, message content, link destinations, and machine-learning models trained on both. That combination works well against commercial spam, because bulk-commercial email is, definitionally, bulk, and it leaves plenty of those signals behind. It works far less reliably against a targeted phishing email: a spear-phishing message sent once, from a domain registered days ago, worded specifically for one recipient, simply produces fewer of the campaign-level patterns and reputation signals a filter can lean on - not zero, but far fewer than a templated blast sent to ten thousand people.
This is precisely the gap we built Email Scam Checker's heuristic checks to close. We don't try to spot phishing by matching it against known bulk-spam campaigns - we run 28 independent checks against the content and metadata of the specific email in front of you: whether the display name matches the sending domain, whether a link's visible text disagrees with where it actually goes, whether the domain was registered in the last 30 days, whether the wording pressures you to act before you think. A recently registered domain, on its own, is a supporting risk signal rather than proof of phishing - it's one input among many, which is exactly why none of these checks depends on the message having been sent to anyone else first, and why together they catch the single, carefully-worded phishing attempt that campaign-level filtering has little history to recognize.
When the line blurs: scam email that's neither pure spam nor classic phishing
Not every unwanted, deceptive email fits neatly into either box. A "you've won the lottery" or "a distant relative left you an inheritance" message is unsolicited and mass-sent like spam, and it's built on a lie like phishing - but many inheritance and lottery scams don't impersonate any specific established brand at all; the deception is the invented scenario itself, not a borrowed identity. That's a meaningfully different attack shape from a message claiming to be PayPal, even though both want the same outcome: your money or your details.
Scam is the broader category here: an email built around deception to make you take a harmful action, whether or not it borrows anyone's identity to do it. Phishing is the specific, impersonation-driven type of scam - it's a scam that works by pretending to be someone you'd trust. Every phishing email is a scam; not every scam email is phishing.
Our own risk model collapses this distinction on purpose, because from the recipient's side the correct response is identical either way: don't engage, don't send money, don't click through. An email crosses into a "Scam" verdict in our scoring the moment its risk score hits 50 or it trips a single critical trigger - whether that trigger is an anti-phishing code mismatch on an impersonation attempt or a financial-fraud pattern like an advance-fee or inheritance pitch. The category matters for understanding how the attack works; it doesn't change what you should do when one lands in your inbox.
How to tell which one you're looking at
Three quick checks separate an ordinary pitch from an attack in progress, and none of them require technical expertise.
- Does it ask you to take a sensitive or consequential action? "50% off this weekend" is an ad. "Verify your account within 24 hours or it will be suspended" is asking you to log in, confirm a payment, or hand over a credential - a different category of ask than a coupon, even though ordinary marketing also asks you to click, renew, or sign up.
- Does it claim to be someone you already trust? Commercial spam usually promotes itself fairly directly, even if you don't want to hear from it. Phishing more commonly relies on a deceptive identity - a bank's, a coworker's, or a delivery company's - specifically so you'll lower your guard.
- Does it know anything about you? Generic mass phishing and spam both use blanket greetings, but a message that references your actual name, employer, or a recent purchase has moved into spear-phishing territory - which is far more convincing than typical junk mail, though personalization on its own isn't proof of anything, since a legitimate marketing or CRM email is personalized too.
Personalization only raises the stakes when it's paired with a sensitive request or a deceptive identity - on its own it's just good targeting. If a message combines a consequential ask with a borrowed identity, treat it as phishing regardless of how polished or sloppy the writing is - well-produced spear-phishing is often grammatically clean, so the absence of typos proves nothing on its own. Our guide on how to spot a phishing email walks through the full sender, link, and language checklist with an annotated real-world example.
What to do with each
The response differs because the risk differs. For ordinary spam, unsubscribing (if the sender is legitimate) or marking it as junk is enough - there's nothing to investigate beyond an unwanted advertisement. For phishing, the response needs to be more deliberate: don't click any link or open any attachment, use your provider's dedicated "Report phishing" option rather than the generic junk button, and if the message claims to be from a service you actually use, log into that service by typing its address directly into your browser rather than through the email's link.
Reporting the correct category matters beyond your own inbox. CISA recommends reporting phishing attempts rather than just deleting them, and the Anti-Phishing Working Group accepts forwarded phishing emails at reportphishing@apwg.org and feeds that industry reporting into its quarterly trend analysis. Marking a message specifically as phishing, rather than ordinary junk, gives your provider and these reporting organizations a clearer signal about the nature of the abuse. The FTC's phishing guidance covers the same reporting path for US consumers, including what to do if you already clicked.
Final verdict - phishing vs. spam
Spam and phishing share an inbox but not a purpose: spam wants your attention long enough to sell you something, phishing wants you to hand over credentials, money, data, or access, and is willing to lie about its identity to get there. Volume, personalization, and inbox placement are all just symptoms of that underlying intent - which is why the most reliable test isn't how the message arrived, but what it's actually asking you to do and who it's pretending to be while it asks. Bulk spam filtering already handles the advertising half of that problem reasonably well; catching the deception half is what heuristic, content-aware detection - automated or otherwise - is actually for.