The problem

Agent swarms and the inbox: why no email is one-to-one anymore

The spam of the 2000s was easy to spot. The outreach of 2026 reads like it was written for you, because in a sense it was, along with fifty thousand other people.

AGENT 1 SENDER
Every message unique, every one personalised, none of them one-to-one.

From spray-and-pray to personalised-and-pray

Classic spam was one message sent to millions of addresses. Filters learned to catch it by spotting identical content, bad sender reputation and suspicious links. Cold outreach used to be a different category: slower, written by a person, sent to a short list.

AI agents merged the two. A sales agent can look up a recipient's company, recent posts and job history, write a plausible personal note, and send it. Then it does the same for the next fifty thousand people. Each message is unique. Each one mentions something true about you. None of it involved a person deciding you, specifically, were worth writing to.

That is the change that makes email feel dead for so many people. It is not that the messages are bad. It is that none of them are one-to-one. When every message is written for you and sent to everyone, personalisation stops meaning anything.

Why filters don't stop it

  • No repeated content. Every message is generated fresh, so content fingerprints don't match.
  • Clean infrastructure. Outreach platforms spread sending across many real mailboxes and domains, each warmed up and properly authenticated.
  • Low volume per sender. Google and Yahoo's bulk-sender requirements apply to senders of around 5,000 messages a day to their users. A swarm of mailboxes each sending a few dozen stays below every threshold.
  • No malicious payload. There is nothing to scan. The message is simply unwanted, at scale.

Filters answer the question "is this spam?" The useful question is different: "did someone decide that I, specifically, was worth their effort?"

The same technology writes the fraud

Business email compromise, where a criminal impersonates an executive, supplier or lawyer to redirect a payment, cost US victims more than $3 billion in 2025 according to the FBI. The FBI's 2025 report was the first to track AI as its own category, with over 22,000 complaints and nearly $900 million in losses. Fluent, error-free, context-aware messages used to be a sign of a real correspondent. They no longer are.

What restores the signal

You can't tell a person from an agent by reading the message. You can make breadth expensive. A refundable deposit on first contact costs someone writing one message a few dollars, returned if you reply. It costs a campaign writing to fifty thousand people fifty thousand deposits. The signal comes back without anyone judging the content, and agents acting for a real person with a real reason remain welcome. The economics in detail.

Sources

  1. FBI Internet Crime Complaint Center, 2025 IC3 Annual Report
  2. Google, Email sender guidelines
  3. Thales Imperva, 2026 Bad Bot Report: Bad Bots in the Agentic Age