Open Gmail’s Spam folder these days and there is something oddly satisfying about it.
Fake alerts pretending to come from banks, credit card companies, online retailers and delivery services are often sitting there neatly quarantined. What makes that more impressive is that scam emails are no longer limited to the hilariously broken grammar that once gave them away. With generative AI readily available, the writing itself can look perfectly respectable.
So why does Gmail still catch so many of them? Once I started looking into it, the interesting part turned out to be that humans and Gmail are not really looking at the same email.
Gmail Is Not Just Reading for “Suspicious Wording”
According to Google, Gmail’s spam filtering uses machine learning and considers multiple signals. Those include characteristics of the sending IP address, domains and subdomains, sender authentication and user feedback—not just the words in the message.
A human opens an email and thinks, “Does this sound legitimate?” Gmail can also ask something closer to: “Who sent this, where did it come from, and does its identity check out?”
AI-generated conceptual illustration. It does not reproduce Gmail’s actual interface, infrastructure or internal systems.
Three of the better-known mechanisms are SPF, DKIM and DMARC. In simplified terms, SPF specifies which mail servers are authorized to send mail for a domain. DKIM uses a cryptographic signature so receiving systems can verify that a message is associated with the signing domain and has not been altered after signing. DMARC ties those authentication results to the domain shown in the visible “From” address and provides rules for handling failures.
A scam email can have flawless prose and still look suspicious if the identity behind it does not add up. In other words, scoring an A in English class does not get you through passport control.
Millions of “Report Spam” Clicks Become Another Signal
Gmail also has something an individual reader does not: feedback from an enormous user base.
When someone reports an email as spam, Google says a copy may be analyzed to help protect users from spam and abuse. Google also states that as users report more spam, Gmail becomes better at identifying similar messages as spam.
That changes the nature of the contest. A new scam campaign might slip past some people at first, but as reports accumulate, later messages have more history attached to them.
One person sees one email. Gmail can benefit from signals generated across a vast population of inboxes.
Spammers Even Attack the Text Itself—and Google Built RETVec for That Problem
Spam operators have spent years trying to fool automated classifiers. Their tricks include replacing letters with look-alike characters, inserting invisible Unicode characters and stuffing messages with unrelated keywords in an attempt to confuse text-processing systems.
In November 2023, Google described deploying a technology called RETVec—short for Resilient & Efficient Text Vectorizer—to strengthen Gmail’s spam classifier against this kind of manipulation.
Google reported that replacing the previous text vectorizer with RETVec improved spam detection by 38% over the baseline while reducing the false-positive rate by 19.4%.
That number needs one important warning label. It does not mean Gmail suddenly discovered an extra 38% of all spam in existence. It is an improvement measured against Google’s previous baseline system.
15 Billion Emails a Day Works Out to About 174,000 a Second
In May 2026, Google said Gmail blocks more than 99.9% of spam, phishing and malware from reaching users’ inboxes, amounting to nearly 15 billion unwanted emails every day.
Take that rounded daily figure and do a deliberately simple calculation:
15,000,000,000 ÷ 86,400 seconds = roughly 173,600 emails per second.
That is an average derived from Google’s daily figure, not a measurement of Gmail’s second-by-second traffic. Still, it makes the scale easier to picture. At that volume, this cannot simply be a machine hunting for a few suspicious words in each message. Reputation, authentication, user feedback and patterns in the message itself all become part of a much larger filtering problem.
AI-generated conceptual illustration. The figure of about 173,600 emails per second is a simple average calculated from Google’s published figure of nearly 15 billion unwanted emails per day, not a real-time measured rate.
Since 2024, Gmail Has Also Raised the Bar for Senders
There is another reason the system may feel stricter than it used to. It is not only the filter that has changed; Gmail has also tightened the rules for the people and systems sending mail into it.
Starting February 1, 2024, Google required senders to personal Gmail accounts to use SPF or DKIM authentication, along with other technical requirements. Senders delivering more than 5,000 messages per day to Gmail accounts face additional requirements, including SPF, DKIM and DMARC.
So Gmail is not merely waiting for a dubious message to arrive and then deciding whether to throw it into Spam. It increasingly asks senders to demonstrate that they behave like legitimate senders before their mail gets very far.
So Are Scam Emails Basically Solved?
No. Unfortunately, the game does not end there.
If reputation and authentication matter, attackers have an obvious incentive to abuse accounts and services that already possess reputation and authentication. Google itself warns that if spam suddenly starts arriving from someone in your contacts, that person’s account may have been compromised. Google has also documented scams that abuse trusted online services and infrastructure.
And that famous 99.9% figure should not be misread as “Gmail catches 99.9% of scam emails.” Google’s claim covers spam, phishing and malware together.
An email appearing in the inbox is therefore not a certificate of authenticity. Gmail can remove a remarkable amount of junk, but it cannot repeal fraud.
Editor’s Note
Old scam emails almost gave humans an unfair advantage. The grammar was strange. The tone was wrong. A bank supposedly wanted your password but apparently could not afford a competent proofreader.
That advantage is disappearing. If the problem is merely writing a convincing message, AI can now help a scammer polish the copy in seconds.
What I found more interesting is that Gmail has, in a sense, stopped playing the same game. It looks at the IP address. The domain. Authentication. Reputation. User reports. The text still matters, but the prose is no longer the whole battlefield.
A scammer can write the most convincing email in the world, and Gmail can still ask the wonderfully unfashionable question: “Fine—but where did you get this letter?”
That may be the better way to understand why Gmail feels surprisingly good at this now. It is not simply that an AI has become better at reading suspicious sentences. The system has become better at examining the email’s provenance as well as its content.
References
- Google Workspace Blog — “Understanding Gmail’s spam filters” (May 27, 2022)
- Google Online Security Blog — “Improving Text Classification Resilience and Efficiency with RETVec” (November 29, 2023)
- Gmail Help — “Email sender guidelines”
- Gmail Help — “Report spam in Gmail”
- Google — “Our fight against fraud: 5 ways we’re keeping you safer” (May 13, 2026)
- Google — “Our latest fraud and scams advisory” (June 2026)
