If your email address appears anywhere on your website, it is probably already on a spam list. Harvesting bots crawl the web looking for anything with an @ in it, then sell or use those addresses.
You can't take your contact details offline. But you can make them much harder to collect.
What harvesters look for
mailto:links- Plain-text addresses on contact, team and "about" pages
- Author bios and comment sections
- PDFs and documents linked from your pages
Where they come from
Harvesters need to crawl a lot of pages cheaply, so they almost always run from rented servers in datacenters, often rotating through proxy networks to avoid rate limits. Real visitors reading your team page come from home and mobile connections.
That difference is what makes network-level blocking work so well here.
Protect the pages that matter
You don't need to lock down your whole site. Check the visitor's IP on the few pages that show contact details. If the request comes from a datacenter, proxy or known crawler network, show the page without raw email addresses. A contact form works just as well for anyone who genuinely needs to reach you.
One important exception: let real search engines through. Googlebot and Bingbot run from their own networks and identify themselves. You want them to index your pages, and you can verify them with a reverse DNS lookup before deciding what to show.
Layer in the classics
- Use a contact form instead of a raw address where you can.
- Build visible addresses with a bit of JavaScript, so they don't appear in the page source.
- Use role addresses like hello@ instead of personal ones, so spam doesn't land in one person's inbox.
Why marketers should care
Spam to your own domain is not just annoying. Harvested addresses get used to send phishing that pretends to be from colleagues, and a domain that receives a lot of junk often has a harder time with its own deliverability. Keeping crawlers off your contact pages protects your inbox and your sending reputation at the same time.