Thanks for flagging this, and also for using a compartmentalized address in the first place. Reports like this are exactly the kind of signal we want to hear about, so we appreciate you raising it. To address the direct concern: we have no evidence of any new intrusion or unauthorized access to Roll20 systems. We take reports like this seriously, though, and will be performing a review and audit. That said, there a couple of common ways a unique address can start receiving spam without any breach at all, and it may be useful to walk through them: 1. Alias guessing. If your address is something like <a href="mailto:roll20@yourdomain.com" rel="nofollow">roll20@yourdomain.com</a> on a catch-all domain, spammers routinely send to common brand names at catch-all domains. This is by far the most frequent cause of "my unique address got spam" incidents. Plus-addressing ( <a href="mailto:you+roll20@provider.com" rel="nofollow">you+roll20@provider.com</a> ) is similarly easy to guess. 2. A compromise on the receiving side. This could be in the form of malware or browser extensions with mail access on your side, but also could be a compromised forwarding/alias service can expose addresses in a way that looks like a sender-side leak. 3. A compromised mail hop. Email isn't end-to-end encrypted (except under certain circumstances), so every server that legitimately handles a message in transit (like an alias or forwarding service, a filtering gateway, a mail provider) can see the recipient address. If any one of those is compromised, your address can leak, and from your side it would look identical to a sender-side breach. Alias and forwarding services are the most notable case here, since they hold the full mapping of unique addresses by design. But again, we take things like this very seriously. If you're willing, could you please forward one of the spam messages with full headers to us? I will DM you an email address to forward to, if so. The headers can give hints as to whether this is untargeted dictionary spam or something that warrants deeper investigation. We'll follow up in this thread if our review turns up anything users need to act on. If we ever confirm an incident affecting user data, we will notify affected users directly, as we did in 2024. Sincerely, Mike Todd Roll20 CTO