Gmail security guide

Gmail Spam Filter Not Working? Fix It - and Catch What It Misses

Gmail blocks millions of spam emails every day — but a growing wave of targeted phishing, AI-written scams, and business email compromise passes straight through its filter and lands in your inbox.

🔒 No email content stored · Instant results · Works in Gmail

Featured by Google 5-star rated on Chrome Web Store Privacy-first & GDPR compliant

What Gmail's Spam Filter Actually Does

Gmail's spam filter is one of the most sophisticated bulk-email filters ever built. It analyses hundreds of signals before you ever see a message: sender reputation, domain age, sending volume patterns, SPF and DKIM authentication records, links compared against known malicious URL databases, and content patterns matching previously identified spam campaigns.

For mass-blast spam — generic phishing templates, unsolicited marketing, and known fraud campaigns — Gmail's filter performs extremely well. It was designed specifically for this threat: high-volume, low-personalisation email that shares identifiable patterns across thousands of instances.

The problem is that the most dangerous email threats today are no longer mass-blast campaigns. Targeted phishing, AI-written scams, and business email compromise attacks are individually crafted, delivered once, and arrive from addresses Gmail has never flagged before. The same signals that make Gmail excellent at catching bulk spam are entirely irrelevant against a targeted attack — and attackers know it.

Gmail Spam Filter Not Working? 6 Fixes to Try First

If spam keeps landing in your inbox, work through these steps in order. They fix the vast majority of "Gmail stopped filtering spam" cases.

  1. Report spam instead of deleting it. Select the message and click the Report spam icon. Deleting a spam email teaches Gmail nothing; reporting it trains the filter on your mailbox specifically.
  2. Check your filters for accidental allow rules. Go to Settings, then "Filters and Blocked Addresses". A filter set to "Never send it to Spam" on a broad match can wave through whole categories of junk. Delete any filter you do not recognize.
  3. Block repeat offenders. Open the message, click the three-dot menu, and choose "Block sender". Future mail from that address goes straight to Spam.
  4. Create your own filter for recurring junk. Use the search bar's filter options to match the sender domain or subject pattern, then choose "Delete it" or "Send to Spam".
  5. Check where else your mail flows. If another app fetches your Gmail over POP or IMAP, or forwarding is set up, spam may be pulled in before Gmail classifies it. Review Settings, "Forwarding and POP/IMAP".
  6. On a work account, ask your admin. Google Workspace spam policies are set at the organization level and can override what you see in personal settings.

Gmail Spam Filter Too Aggressive? Keep Good Email in Your Inbox

The opposite problem is just as common: legitimate email quietly disappearing into Spam. Three fixes:

  1. Rescue and mark "Not spam". Check the Spam folder weekly. Selecting a wrongly flagged message and clicking "Not spam" both restores it and trains the filter.
  2. Add trusted senders to Contacts. Gmail almost never sends mail from your saved contacts to Spam.
  3. Whitelist important domains with a filter. Create a filter matching the sender's domain and tick "Never send it to Spam". Use exact domains, not broad keywords, so you do not reopen the door to junk.

These steps tune how Gmail handles volume. What they cannot do is judge whether an individually crafted email is genuine. That is a different problem, and it is the one that matters most - because the emails designed to fool you are exactly the ones Gmail's filter lets through.

The Threats Gmail's Spam Filter Can't Catch

Gmail's filter is optimised for known, high-volume attacks. These four threat types are specifically structured to defeat it.

Targeted spear phishing

Spear phishing emails address you by name, reference your employer, recent purchases, or colleagues. They are sent once from a fresh domain with no prior sending history — so Gmail has no reputation data to act on. Gmail's filter passes the email; the recipient reads a convincing, personalised impersonation.

AI-written phishing emails

Emails drafted by ChatGPT, Claude, or Gemini have no known signature. They are grammatically perfect, contextually coherent, and stylistically convincing. Spam filters work by recognising patterns — AI writing produces entirely novel text that doesn't match any pattern on file.

Business email compromise (BEC)

BEC attacks impersonate executives, vendors, or IT departments to request urgent wire transfers or credential resets. These emails often contain no links at all — just text — and arrive from convincingly named domains. Gmail has no mechanism to detect the social manipulation written into the message body.

Phishing via legitimate services

Attackers send phishing via Google Docs share notifications, DocuSign links, and SharePoint invitations. The sending domain is legitimate — Google or Microsoft — so Gmail's reputation checks pass the email. The phishing is inside the linked document, not the email itself.

Gmail Spam Filter vs. TrustScan — Side by Side

Gmail's filter and TrustScan protect against different threats. Together, they cover everything.

Threat type Gmail spam filter TrustScan
Mass-blast spam campaigns ✓ Catches ✓ Catches
Known phishing domains ✓ Catches ✓ Catches
Targeted / spear phishing ✗ Misses ✓ Catches
AI-written scam emails ✗ Misses ✓ Catches
Business email compromise (BEC) ✗ Misses ✓ Catches
Social engineering language ✗ Misses ✓ Catches
Phishing via Google Docs / SharePoint ✗ Misses ✓ Catches
Trust score per email (0–100) ✗ Not available ✓ Every email

How TrustScan Fills Gmail's Security Gap

TrustScan doesn't replace Gmail's spam filter — it runs after it, scanning every email that makes it to your inbox.

1

Reads the language, not just the signals

Gmail checks sender authentication and link reputation. TrustScan reads the actual message — detecting manipulation tactics, urgency framing, credential requests, and social engineering patterns that reveal intent regardless of whether the sender's domain has any prior reputation.

2

Detects AI-written emails specifically

TrustScan checks whether the email was drafted by a language model such as ChatGPT or Claude. AI-written phishing is becoming the dominant attack vector precisely because spam filters cannot detect it by pattern matching. Learn how AI detects AI phishing →

3

Gives you a trust score — not just spam or not spam

Gmail's verdict is binary: spam folder or inbox. TrustScan produces a numeric trust score from 0 to 100, with a colour-coded badge and a plain-English explanation of exactly what it found — so you can make an informed decision, not just accept a binary label.

4

Works automatically inside Gmail — no extra steps

Unlike copy-paste phishing checkers, TrustScan scans every email the moment you open it. Install the Chrome extension once and it runs silently on every message — every time — with no manual action required.

Who Is Most at Risk from Gmail's Blind Spots?

The attacks that bypass Gmail's filter are targeted by design. These groups face the highest exposure.

💼

Finance and accounting teams

Business email compromise attacks specifically target employees with authority to approve payments. A convincing fake email from "the CEO" or "a vendor" requesting an urgent wire transfer will pass Gmail's filter without issue.

👤

Personal Gmail users

AI-generated fake parcel delivery notifications, bank account alerts, tax refund notices, and subscription renewal scams look identical to legitimate messages — and bypass Gmail's bulk-spam detection entirely because they are sent as individual messages.

🏢

Small businesses and freelancers

Fake invoices, impersonated client emails, and payment-redirect scams cost small businesses billions annually. Without enterprise security tooling, these businesses rely entirely on Gmail's spam filter — which is exactly what attackers count on.

Frequently Asked Questions

Why does phishing get through Gmail's spam filter?

Gmail's spam filter works by recognising bulk sending patterns, known malicious domains, and previously flagged URL signatures. Targeted phishing emails have none of these signals — they arrive from fresh or legitimate-looking domains, are sent just once, and contain no links that appear in Gmail's threat databases. Gmail's filter sees a normal email. TrustScan reads the language, intent, and manipulation tactics inside the message itself.

Does Gmail have any anti-phishing protection?

Yes. Gmail checks sender authentication records (SPF, DKIM, DMARC), compares links against known malicious URL databases, and flags emails from domains impersonating popular brands. These protections work well against known, mass-scale phishing campaigns. They do not catch novel phishing domains, AI-crafted spear phishing messages, or business email compromise attacks that use clean infrastructure.

What is the difference between spam filtering and phishing detection?

Spam filtering is volume-based: it identifies bulk unsolicited email by sender reputation, sending volume, and keyword pattern matching. Phishing detection is intent-based: it analyses the language and goal of a message to determine whether it is trying to manipulate the recipient into surrendering credentials, money, or personal information. Spam filters catch noise. Phishing detectors catch targeted deception.

Can I add extra phishing protection to Gmail?

Yes. TrustScan is a free Chrome extension that adds a real-time phishing scanner inside Gmail. It automatically scans every email you open and displays a trust score from 0 to 100 next to the subject line — green (safe), amber (caution), or red (high risk). No copy-pasting, no extra tabs, no configuration needed. See the pricing page for plan details.

Why is AI-generated phishing hard for Gmail's spam filter to catch?

AI-generated phishing emails are written by large language models like ChatGPT and have no prior signature. They arrive from fresh domains, contain no previously flagged links, and are grammatically perfect and contextually plausible. Gmail's filter has no pattern to match against. The only reliable way to identify them is by analysing the intent and language of the message itself — which requires AI-powered content analysis, not pattern matching. Read more about how AI detects AI-written phishing emails →

Is TrustScan compatible with Google Workspace?

Yes. TrustScan works with both personal Gmail accounts and Google Workspace (formerly G Suite) accounts accessed through a web browser. It is compatible with Google Chrome, Microsoft Edge, and Brave on Windows, macOS, and ChromeOS.

Related Email Security Resources

Close Gmail's Security Gap — Free

TrustScan adds a real-time phishing scanner inside Gmail that catches exactly what the spam filter misses. Install once — protected forever.

Install TrustScan for Chrome

Requires Google Chrome, Edge, or Brave. Free to start · Uninstall anytime.