By
Gigabit Systems
September 28, 2026
•
20 min read

Spam Filters May Have Cost Republicans $117 Million
A spam filter can quietly become a political gatekeeper.
We normally think about spam filters as cybersecurity tools.
They stop phishing emails, malware, scams and the endless flood of junk that would otherwise make email nearly unusable.
But a new academic working paper raises a much bigger question:
What happens when an automated security system accidentally decides which political messages millions of Americans actually see?
Researchers Cameron Ellis of the University of Iowa and Lars Powell of the University of Alabama estimate that Republican fundraising campaigns missed approximately 142,126 first-time donations worth about $117 million during two periods in 2025 when emails containing WinRed donation links were disproportionately routed to spam.
The New York Post reported the findings this morning, describing one period in which first-time WinRed donations dropped roughly 75%, and another involving Outlook in which they fell roughly 83%.
That is an extraordinary number.
But there’s an equally important sentence buried in the story:
The study did not conclude that the filtering was caused by political bias.
Exclusive | Email spam filters cost GOP fundraisers estimated $117M in donations.pdf
That’s where this story becomes much more interesting than another argument about Big Tech and politics.
What Researchers Say Happened
The underlying working paper, Real Impacts of Political Spam Filtering, examines political fundraising and inbox-placement data.
The researchers identified two particularly significant episodes during 2025.
The first lasted 78 days.
During that period, according to the paper, Gmail, Outlook and Yahoo were routing emails containing WinRed fundraising links to spam while otherwise-identical emails containing ActBlue links reached inboxes.
WinRed is widely used for Republican fundraising; ActBlue serves Democratic and progressive campaigns.
During that episode, the researchers calculated that first-time WinRed donations declined 74.6%.
A separate Outlook-only episode between February and April was associated with an 83.2% decline in first-time WinRed donors.
Combined, the researchers estimated:
142,126 missing first-time donations.
The $117 million figure requires an important explanation.
It isn’t $117 million that researchers directly observed disappearing from campaign bank accounts.
The researchers estimated the longer-term value of those missing donors using Federal Election Commission donation records. Their paper reports that new WinRed donors gave an average of $461 initially and $827 cumulatively over eight months.
The Post describes the methodology similarly: researchers separated first-time and repeat donors using FEC records and compared donation activity with inbox-placement rates during the filtering periods.
Exclusive | Email spam filters cost GOP fundraisers estimated $117M in donations.pdf
So the accurate description is:
Researchers estimate the filtering resulted in $117 million in lost donor value.
Not:
Google was caught stealing $117 million from Republicans.
Those are very different claims.
The Link Appears to Have Mattered
One of the most intriguing pieces of evidence involves the fundraising link itself.
According to the Post, Targeted Victory tested messages containing ActBlue links using the same text as their Republican counterparts and reported that those messages were delivered without the same problem.
Exclusive | Email spam filters cost GOP fundraisers estimated $117M in donations.pdf
The researchers similarly concluded that inbox-placement data and paired testing supported the idea that WinRed links were triggering the filtering.
Exclusive | Email spam filters cost GOP fundraisers estimated $117M in donations.pdf
That’s technically fascinating.
Because modern spam filtering doesn’t simply read an email and decide whether its political language sounds suspicious.
Filters can consider enormous numbers of signals.
Sender reputation.
Domain reputation.
Authentication.
Sending patterns.
User complaints.
Message structure.
URLs.
Link reputation.
Previous behavior associated with domains.
Potentially malicious infrastructure.
And countless other signals.
A message can therefore contain completely legitimate text and still get caught because of a URL inside it.
Sometimes the most consequential part of an email isn’t what it says. It’s where the link goes.
Then Something Changed
According to the Post, Google eventually stopped using SURBL, a third-party service used to identify potentially problematic URLs.
The article says that happened on September 15, 2025.
Ellis and Powell found that Republican email placement subsequently “normalized.”
Exclusive | Email spam filters cost GOP fundraisers estimated $117M in donations.pdf
That timing is important evidence that filtering technology was involved.
It still doesn’t establish why the underlying link reputation differed.
That’s the unanswered question.
Was this political discrimination?
Was WinRed’s domain reputation legitimately worse?
Were recipient complaints different?
Was some characteristic of Republican fundraising email creating stronger spam signals?
Was a third-party blacklist producing an unintended downstream effect?
Or was some combination of factors responsible?
The researchers themselves do not claim to have established partisan intent.
Google Says the Study Is Wrong
Google strongly disputes the research.
A Google spokesperson told the Post that the study relies on “deeply flawed methodology that fundamentally misunderstands how Gmail works.”
Exclusive | Email spam filters cost GOP fundraisers estimated $117M in donations.pdf
Google also says its spam protections apply equally regardless of political affiliation and argues that users ultimately control their inboxes by marking messages as spam, blocking senders and unsubscribing.
The company specifically disputes the $117 million figure, saying it represents a theoretical estimate of donor value rather than directly observed losses. Microsoft declined to comment to the Post, while Yahoo did not respond.
Exclusive | Email spam filters cost GOP fundraisers estimated $117M in donations.pdf
Those qualifications matter.
Especially because accusations of intentional political censorship have been litigated before.
Republicans Have Made Similar Accusations Before
This dispute predates the new study.
The Republican National Committee previously sued Google, alleging Gmail intentionally diverted Republican fundraising emails to spam.
A federal judge ultimately dismissed the case with prejudice in 2024.
The ruling did not establish that Gmail never disproportionately filtered Republican email.
Rather, the court concluded the RNC had failed to establish viable legal claims.
An earlier order is particularly interesting.
The court discussed a study finding Gmail placed 67.6% of Republican campaign emails into spam compared with 8.2% of Democratic campaign emails in the study’s test accounts.
But the judge concluded that disparity alone wasn’t sufficient to reasonably infer intentional political animus by Google.
The Federal Election Commission had separately dismissed an RNC complaint in 2023, concluding that available information indicated Google’s spam filter existed for commercial rather than electoral purposes.
So there are really two separate questions:
Did Republican email experience different filtering outcomes?
And:
Did Google intentionally create those outcomes because the emails were Republican?
Evidence for the first does not automatically prove the second.
But Intent Isn’t the Only Important Question
This is where I think the cybersecurity lesson becomes far more important.
Suppose, for argument’s sake, nobody at Google, Microsoft or Yahoo intended any political outcome whatsoever.
An algorithm looked at technical signals.
It made a classification.
Spam.
And millions of emails disappeared from people’s primary inboxes.
If the new research is approximately correct, that technical classification may have produced an economic impact measured in tens of millions of dollars.
Nobody had to press a button marked:
BLOCK REPUBLICANS.
That’s exactly why automated systems deserve scrutiny.
Algorithms don’t need political opinions to produce politically consequential outcomes.
A Spam Filter Has Enormous Power
Think about what actually happens when you send an email.
You click Send.
But you don’t decide whether the recipient sees it.
Their email provider does.
An automated system standing between sender and recipient decides:
Inbox.
Promotions.
Spam.
Quarantine.
Blocked entirely.
For ordinary marketing email, that’s mostly a commercial problem.
For political communication, those same decisions can affect fundraising, organizing and which messages voters encounter.
The researchers’ broader finding is therefore worth considering regardless of whether one accepts every dollar in their estimate.
A handful of enormous private email providers operate infrastructure through which much of America’s digital political communication travels.
A relatively narrow technical decision involving a URL reputation system can potentially have very large downstream consequences.
Infrastructure becomes power when everybody depends on it.
Spam Filters Also Exist for a Very Good Reason
There is another side to this.
Political emails aren’t entitled to someone’s inbox merely because they’re political.
Spam filters protect users.
And political fundraising organizations can send extraordinary volumes of email.
The RNC’s earlier litigation itself acknowledged that Gmail filters unwanted or potentially harmful messages as part of the service. The court noted that merely having interacted with an organization once doesn’t necessarily mean a person wants every subsequent marketing email it sends.
That’s an important point.
Imagine the opposite policy:
Every registered political campaign automatically bypasses spam filtering.
Your inbox could become practically unusable during an election.
And malicious actors would have an enormous incentive to impersonate campaigns.
Spam filtering is not the problem.
Opaque, high-impact filtering is the harder problem.
Google Has Now Changed the Rules for Political Email
There’s another fascinating development.
Google launched a new Verified Sender Program this month for eligible U.S. political committees.
Verified candidates, political parties, PACs and other qualifying political organizations can authenticate their identity and sending domains and receive different treatment designed to improve reliable delivery to Gmail users.
Recipients still retain the ability to mark those messages as spam, block the sender or unsubscribe.
This isn’t Google’s first attempt at such a system.
The FEC approved a Google political-email pilot back in 2022 that allowed participating committees to bypass normal algorithmic spam classification, leaving spam decisions more directly to recipients.
There are legitimate arguments on both sides of this design.
One approach says political speech shouldn’t quietly disappear because of an opaque algorithm.
The other says political organizations shouldn’t receive privileged inbox access unavailable to ordinary bulk senders.
Neither question requires believing that Google secretly favors one party.
It’s fundamentally a question about how much discretion automated infrastructure should exercise over important communications.
Businesses Should Pay Attention to This Story
Forget politics for a moment.
Imagine your business sends 100,000 legitimate emails.
Your invoices.
Appointment reminders.
Password resets.
Security alerts.
Customer notifications.
Marketing campaigns.
An automated reputation service decides your domain or one of your links looks suspicious.
Suddenly 70% of those messages disappear into spam.
Your server says:
Delivered.
Technically, that’s true.
Operationally, you may have a disaster.
This is why email security isn’t merely about stopping malicious email.
It’s also about ensuring legitimate email can prove that it is legitimate.
SPF.
DKIM.
DMARC.
Domain reputation.
List hygiene.
Complaint rates.
Authentication.
Monitoring.
Proper unsubscribe mechanisms.
And continuous deliverability testing.
“Sent” and “seen” are two completely different metrics.
There’s an Even Bigger Cybersecurity Lesson
Security systems constantly make decisions.
Allow or block.
Safe or malicious.
Human or bot.
Fraud or legitimate.
Authorized or unauthorized.
Spam or inbox.
We tend to think about the danger of a false negative:
The malware gets through.
The phishing email reaches somebody.
The attacker successfully logs in.
But false positives can also cause enormous damage.
A hospital security system blocks a legitimate medical application.
An EDR product quarantines critical business software.
A financial fraud system freezes legitimate transactions.
An identity system locks out the administrator during an emergency.
Or an email filter prevents thousands of legitimate fundraising messages from reaching recipients.
Security isn’t simply about blocking more.
It’s about blocking the right things.
The $117 Million Number Isn’t the Most Important Part
The number makes the headline.
And it should be treated as what it is: an academic estimate based on modeled missing donations and expected donor value, not an audited pile of $117 million that disappeared.
The researchers report a striking association between specific filtering episodes and WinRed fundraising declines.
Google disputes their methodology.
Republican organizations allege political suppression.
The study itself does not conclude that partisan bias caused the filtering.
Exclusive | Email spam filters cost GOP fundraisers estimated $117M in donations.pdf
All of those facts can be true simultaneously.
But beneath the political argument is something much bigger.
A tiny technical decision inside infrastructure most people never think about can affect what millions of people see—and potentially move enormous amounts of money.
No conspiracy is required for that to matter.
No malicious engineer is required.
No executive has to issue an order.
Sometimes an algorithm simply decides:
Spam.
And everyone downstream lives with the consequences.
That’s why the most powerful algorithms may not be the ones generating headlines.
They’re the invisible ones quietly deciding what we’re allowed to see.
70% of all cyber attacks target small businesses, I can help protect yours.
#Cybersecurity #EmailSecurity #Gmail #Technology #DataProtection
One spam-filter decision may have cost Republican campaigns an estimated $117 MILLION. Researchers found first-time donations collapsed when WinRed emails stopped reaching inboxes. Google disputes the study—and the researchers did NOT conclude political bias. The bigger story is how much power an invisible algorithm can have.
Exclusive | Email spam filters cost GOP fundraisers estimated $117M in donations.