Reducing the volume you receive starts with where the address is published.
WHERE ADDRESSES ARE HARVESTED
Published in plain text on a website, where automated scrapers collect them Public WHOIS records for your domain Directory listings and social profiles A contact who was themselves compromised, exposing their address book Lists bought and sold between spammers
PRACTICAL MEASURES
Use a contact form on your website rather than publishing an address in plain text Enable domain privacy so WHOIS does not expose your address Use plus addressing or aliases when signing up for services, so you can see who leaked it Do not use your main address for online sign-ups; keep a separate one
WHAT DOES NOT WORK
Writing the address as "name at domain dot com". Scrapers have handled that for twenty years. Images of an address, which also defeat legitimate visitors.
ONCE AN ADDRESS IS ON A LIST
It stays there. Filtering is the answer, not trying to undo the exposure. In severe cases, retiring the address and publishing a new one is the practical fix.