I've filed 165 of these. Here's what I've learned about doing it right.
The short version
Open the email's full headers. If you see X-SFDC-LK, it came through Salesforce. Email
abuse@salesforce.com with that org ID in the subject line and the full headers pasted into the body.
One account per report. Ask them to shut the account down, not just take you off the list.
Step 1: Check that it really came through Salesforce
A lot of cold email goes out through Salesforce without saying so anywhere you can see. The only way to know is the full headers, the technical record that travels with every email.
Gmail: open the email, click the three dots next to Reply, then Show original.
Outlook (desktop): open the email, then File, Properties, and look in Internet headers.
Outlook on the web: the three dots, then View, then View message source.
Apple Mail:View, then Message, then All Headers.
Mail sent through Salesforce has lines like these. This is from a real one I got:
If you see a Received line ending in mta.salesforce.com and any X-SFDC- lines, Salesforce delivered it.
What the X-SFDC headers mean
X-SFDC-LK
The Salesforce org ID, meaning the customer account that sent it. It always starts with 00D. This is the single most useful thing to put in your report, because it tells Salesforce exactly which customer to look at.
X-SFDC-User
The user inside that account who sent it. It starts with 005.
X-SFDC-Binding
An identifier for the sending pool the mail went out on. Many unrelated customers can share one, so two emails with the same binding didn't necessarily come from the same company. It's still worth including: it shows Salesforce how much of the problem runs through one pool. More on X-SFDC-Binding.
X-SFDC-EmailCategory
How it was sent. apiMassMail means bulk mail sent by a program, not one person typing one email.
Step 2: Report it to Salesforce
Send it to abuse@salesforce.com, or use Salesforce's abuse report form. On the form, pick Unsolicited Commercial Email (UCE) / Missing Unsubscribe Link and paste the headers into the Email Headers box. Their policies are at salesforce.com/company/legal/abuse.
Put the org ID in the subject line, like "Unsolicited bulk email from org 00Dd500000CqY6j."
Paste the full headers into the body of your email (or the form's headers box). Don't rely on an attachment, because some abuse desks strip or ignore them. If Salesforce writes back asking for the original message, forward it as an attachment then.
One org per report. Salesforce told me this outright: it's "simplest if you send one org per email." Reports covering many accounts at once got an automatic reply and nothing else. Single-account reports are the only ones that ever got action from them.
Say you never opted in. Salesforce's own Anti-Spam Policy says customers may only email people who "expressly consented (opted-in)." Say plainly that you didn't.
Ask for the account to be shut down. Their policy says violations "may result in termination." If you only ask to be removed, the most you'll get is a removal, and the sender keeps mailing everyone else.
Tell them not to share your details with the sender. Say it in writing. Salesforce once closed one of my reports by having the sender remove my address. In my view, that meant letting the sender know somebody had complained.
Step 3: Know what to expect
You'll get an automatic reply with an 8-digit case number. Keep it. In my experience, that's usually all you'll get: out of 165 cases, somebody at Salesforce told me they'd done something 6 times. Every one of my cases is listed here.
If the same sender comes back on a new account, report the new org ID and mention the old case numbers. A record of repeat reports matters if you go further.
Step 4: Report it to Amazon too, if you want a record
Salesforce runs its mail servers on Amazon Web Services, so most of this mail comes from Amazon's network. You can report it through Amazon's abuse form or to trustandsafety@support.aws.com. Be realistic: in my experience AWS almost always answers that the mail came from its customer Salesforce and that you should report it to Salesforce. It's still a written record that AWS was told.
The exception is mail that went out through Amazon SES, Amazon's own email service. You'll see amazonses.com in the headers. That one is squarely Amazon's to deal with.
Step 5: Go past the abuse desks
Spamhaus. They run the blocklists that most mail servers check. Registered users can submit spam and the domains behind it through the Spamhaus submission portal. This is the one step that can stop the sender from reaching other people's inboxes.
The FTC. File a complaint at ReportFraud.ftc.gov and paste the email, headers included, into the comments box. The FTC no longer takes forwarded spam, so don't bother with the old spam@uce.gov address. Fake meeting requests and fake "Re:" replies to conversations that never happened are worth reporting as deceptive.
Your state Attorney General. Most have an online consumer complaint form. State AGs can enforce the federal CAN-SPAM Act against the senders themselves.
What not to do
Don't reply to the sender, not even "stop." It tells them your address is real and read.
Don't click links in the email. Many are tracked, and the unsubscribe link on an obvious spam run does the same thing a reply does.
Don't edit the headers before you send them. If you want to hide your own address, say so, but leave everything else exactly as it was, or the report is worthless.