A stack of identical X password reset request emails, one per minute, being swept by Premail into a Quarantine folder holding ten messages
← Blog

Twitter (X) Users Are Being Flooded With Password Reset Emails. This Is Exactly Why Premail Exists.

On September 1, users of X, the platform most people still call Twitter, started reporting something strange: password reset emails. Lots of them. Some people received eight or ten Twitter password reset emails within minutes or hours, and the obvious question was whether X had suffered another breach.

So far, X says no. An X product engineer said the company was investigating and had found no evidence of a breach. More interestingly, he suggested a reason the activity may have intensified: attackers appear to believe X accounts are more valuable now that X Money is widely available.

The timing is hard to ignore. Twitter has never had payments built in before. X Money expanded to Premium and Premium+ subscribers in the United States just before the password-reset flood began. Adding payments changes the economics of account theft. A Twitter account is no longer necessarily just a social-media account. For some users, it can now have money attached to it.

But there is another part of this story that I find especially interesting: the emails themselves aren't necessarily spam.

That exposes a fundamental weakness in the way email filtering usually works.

The attacker doesn't have to send the email

The current reports indicate that attackers can repeatedly invoke X's password-recovery process using publicly available Twitter usernames. X then sends the password-reset message itself.

That distinction matters because the attacker isn't necessarily sending you a badly formatted phishing email from some obviously fake domain. They may simply be causing X's own infrastructure to send a legitimate security email to you over and over again.

Reports indicate that initiating a reset does not necessarily mean the attacker knows the email address associated with the account. A public Twitter handle may be enough to trigger the process.

From the perspective of traditional email security, these messages can look perfectly legitimate. They can come from the real company, use legitimate sending infrastructure, pass authentication checks, contain valid links, and accurately describe themselves as password-reset emails.

The problem is not necessarily that the email is fake. The problem is that you didn't ask for it, and that distinction is one of the reasons I built Premail.

Spam isn't defined by who sent it

Email filtering has historically spent enormous effort answering questions like, “Is this sender legitimate?” That is certainly important, but it is not the same question as, “Do I want this message in my inbox?”

Premail is built around the second question. It sits on top of your existing Gmail, iCloud, or Outlook inbox and evaluates incoming mail using rules and AI classification. Instead of forcing every unwanted email into the simplistic bucket of “spam,” Premail can decide what should actually happen to it.

A message can be genuine and still be unwanted. A newsletter you accidentally subscribed to might be genuine. A recruiter blasting the same job to thousands of people might be genuine. A company's seventh marketing follow-up might be genuine. An automated password-reset message generated because someone on the Internet is hammering a recovery form can also be completely genuine.

None of that means it deserves your attention.

How I'd handle the Twitter password-reset flood with Premail

I would not automatically delete security notifications like these. If someone really is trying to get into an account, the existence of those attempts is useful information, and someday you may legitimately request your own password reset.

Instead, this is a perfect use case for quarantine.

Premail supports custom rules and actions including archiving, labeling, moving messages to folders, trashing them, and sending them to a dedicated Premail Quarantine. The goal is to remove unwanted messages from the attention economy of your inbox without pretending they never existed.

For example, I could create a rule that identifies Twitter password-reset messages from X and sends them to quarantine. Instead of ten emails screaming for my attention, my inbox stays quiet. If I want to investigate what happened, the messages are still there.

Premail's Activity view also records what it processed, how it classified the message, which rule matched, and what action it took. That is much safer than blindly deleting account-security messages, and much less annoying than leaving every automated reset request sitting in the inbox.

The bigger problem: legitimate infrastructure can be weaponized

This incident illustrates something that extends far beyond Twitter. Think about every automated system capable of emailing you: password resets, verification codes, login notifications, account invitations, comment notifications, contact forms, support systems, calendar invitations, document shares, and e-commerce notifications.

Every one of those systems represents a potential mechanism somebody else can use to generate email. Sometimes abuse is trivial: enter an email address into a form, hit submit, repeat.

The resulting message can pass every technical authenticity test because the legitimate company really did send it. DKIM cannot solve that. SPF cannot solve that. DMARC cannot solve that. Those systems are largely designed to answer whether an email was legitimately sent by the domain claiming to have sent it.

In an abuse case like this, the answer can be yes. That's the problem.

Email needs an intent layer

This is the broader idea behind Premail. Your email provider handles transport. It receives messages, authenticates senders, detects known malware and spam campaigns, and puts messages into folders.

Premail adds another layer: intent.

Was this something you wanted? Is it valuable? Is it repetitive? Does it belong in your inbox? Should it be quarantined? Should messages like it be handled automatically next time?

Those decisions cannot always be reduced to “good sender” versus “bad sender.” Modern inbox abuse increasingly happens in the enormous gray area between the two.

Premail isn't a replacement for securing your Twitter account

Filtering the resulting emails does not stop someone from requesting resets, so Twitter users should still secure the account itself. That means enabling two-factor authentication, using X's password-reset protections where available, and verifying that account-security emails really came from X.

Premail solves a different part of the problem. Security controls protect the account, while Premail protects your attention. When somebody discovers a way to make a legitimate service generate ten unwanted emails in your inbox, both protections matter.

Premail is a privacy-first inbox defense layer for Gmail, iCloud, and Outlook. It classifies and filters unwanted email while letting you control exactly what gets through.