Spam vs phishing

Spam is unsolicited bulk messaging. Phishing is deceptive fraud that tries to obtain sensitive information or induce a harmful action. A message can be both: a criminal can send the same deceptive login request to many recipients. Treat the message as phishing when it asks you to trust a false identity, disclose information, open something unsafe, or take an urgent action.
At a glance
Quick takeaways
- Spam describes unsolicited bulk delivery, while phishing describes deceptive intent.
- A bulk phishing campaign can be both spam and phishing.
- A suspicious message does not become safe because it looks like ordinary junk mail.
- Spoofing is the use of a false identity or address. It can support phishing, but it is not the same classification.
- Do not click links, open unexpected attachments, or reply with requested information when a message may be phishing.
- A public DNS check can assess a domain's published controls, but it cannot classify one delivered message.
How spam and phishing differ
NIST defines spam as electronic junk mail or abuse of electronic messaging systems to send unsolicited bulk messages indiscriminately. The delivery pattern is central: messages are sent at scale without the recipient asking for them.
NIST defines phishing as a technique that uses a fraudulent solicitation to acquire sensitive data, often by masquerading as a legitimate business or person. The central question is intent and deception: does the message try to make the recipient disclose information, sign in to a false site, send money, or perform another unsafe action?
That distinction gives each term a different job:
- Spam describes how unsolicited messages are distributed.
- Phishing describes a deceptive attempt to obtain information or cause an action.
- Spam email and prevention covers the broader unwanted-email problem.
- Phishing covers the fraudulent technique and its common forms.
When the classification changes
Use the message's purpose before its volume as the decision rule.
- If an unsolicited message promotes something without trying to deceive you into an unsafe action, classify it as spam.
- If it pretends to be a trusted party and asks for credentials, payment, sensitive data, or a risky action, classify it as phishing.
- If the same deceptive message is sent indiscriminately to many recipients, it is both spam and phishing. This is an inference from the NIST definitions of unsolicited bulk messaging and deceptive solicitation.
- If the message claims to be from a known organization, verify the request through a trusted channel you already use. Do not use the phone number, link, or reply address supplied by the message.
A message that appears routine can still be phishing. Do not treat a deceptive request as ordinary junk mail just because it arrived in bulk.
The Federal Trade Commission's phishing guidance recommends avoiding unexpected links and attachments, then reporting suspected phishing through the appropriate reporting channel. Your organization's security-reporting process determines where to send the message internally.
A classification rule for a suspicious email
Apply this rule before deciding whether to dismiss, report, or investigate the message:
Illustrative classification rule
Unsolicited bulk promotion with no deceptive request
= spam
False or misleading identity plus a request for credentials, money,
sensitive information, a link click, attachment opening, or urgent action
= phishing
Deceptive request sent indiscriminately to many recipients
= spam and phishing
The rule does not require proving who sent the message. It classifies the observable risk to the recipient.

A message can also pass some technical checks and still be dangerous. SPF and DKIM indicate authentication results for a sending path. They do not prove that the content, linked destination, or requested action is legitimate. See why phishing emails can pass SPF and DKIM for that boundary.
What to do with the evidence you have
If you have only the message, do not interact with its links, attachments, or requested payment or sign-in flow. Report it through the mailbox provider or your organization's security path, then preserve only the redacted evidence your security team requests. The FTC also advises reporting phishing rather than replying to the sender.
If you manage the domain that appears in the message, separate the message investigation from the domain-control check. A public DNS check can show whether the domain publishes email-authentication records. It cannot determine whether this particular message was phishing, inspect its headers or links, or show why a receiving system handled it a certain way.
Check the public email controls for a domain you manage
If the suspicious message uses a domain your team manages, inspect its published DNS-based email controls with the Email Security Score.
Check the domain's email security score
This public DNS check cannot classify an individual message as spam or phishing, inspect message headers or links, prove sender intent, or establish a receiver's handling decision.
Evidence
Sources and further reading
Questions readers ask
Frequently asked questions
Keep going with AI
Ask AI how this applies to you
Take this guide to your assistant — each question opens pre-filled, with a link back to this page so it can read the details.

Written by
Samuel ChenardCEO & Co-Founder, Palisade
Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.
More from Samuel →


