JDB124,
As I think you understand, my first response was directed at the most recent poster, though I always write them in a general manner to try and aid future readers.
I understand the confusion that most people have dealing with such technical details, since along with what I just mentioned in another reply above, I spent much of my early career in network support of users including as an administrator, which gave me direct access to all of the misdirected email that often contained early versions of the same types of Spam/Scam messages (think Nigerian scam) that exist today.
In fact, as my career progressed deeper into security, I eventually created a manual set of operations for testing an organization's susceptibility to phishing emails, which the developers in my company then worked with me to automate and sell as a service to companies and government and is still in operation today at the security services company that later purchased it.
Based on that background, there are various truths relating to email and the malicious attacks against it that to me are obvious. One is that fixing the problems after they've occurred never works, only prevention can keep the issues from getting out of hand, since once the cat's out of the bag, there's simply no getting it back in there whatever is attempted.
In the case of Spam of any sort, that means the only way to truly resolve this is to keep your email address close and only provide it to a trusted few, in many cases using a separate email address for less trustworthy people or organizations as a throwaway (mine actually contains this word, though I've never needed to do it), and ensure that the address doesn't get posted publicly or distributed on any sort of lists.
Once the email address is out to the public or distributed widely to spam lists, it's too late to fix and only dropping the address and switching to another can quickly resolve that issue. If you must inherently publish the address for use in a business for example, then use a service like Microsoft's that's specifically designed for this purpose and includes the much better filtering and source server vetting processes that those like Verizon, Aol, cable companies and other non-computer communications companies don't provide.
One way to tell how bad your situation might be is to verify whether your email address(es) have been included in any past breaches of websites or databases on the HaveIBeenPwned.com website. This is a known safe and fast lookup through the literally billions of (overlapping) known individual recorded breached identities.
Though being on those lists doesn't automatically mean you're still at risk if you've changed passwords, it does tell you whether your personal information is potentially compromised and associated with your email address, which will only make you more popular with spammers and others due to the breadth of additional information they may have about you. If the site says, 'Oh no - Pwned!' then look below on that same page for descriptions of the breaches your address was found within and what types of data like name, address, etc. the entire world really has access to.
Though you can't ever get that historical data back, by changing your email and dropping the old one, along with following best practices to protect the new one including good password hygiene and limiting to whom you give the new one, you can at least partially 'break' the links to you that the spam/scam message purveyors now have. If you wish, you can retain the old account for now as the 'throwaway', only truly doing that once you're sure all of your important contacts are no longer using that vs. the new one you've created.
Also note, you should recognize from the above that the choice of an email service is really the most critical decision, since trying to patch their problems after they've broken simply doesn't work. I've had the same email address at Microsoft for exactly 20 years, initially used for dial-up and later as my email and account identity here. Though it got on spam lists early on, my careful handling of these (no opening outside Junk, etc.) meant I slowly exited most of these and to this day receive less than one true spam message a day.
This is a good time to mention that how exactly an email app treats the preview pane or others like the Junk folder is really specific to that app. Though in general most now avoid opening things like images by default, since those can contain 'web bugs' that indicate to the sender they've been opened, the current Mail app in Windows 10 for example doesn't even display the existence of attachments for messages in the Junk folder along with images, since these messages are likely malicious and so they don't wish to allow their users to open them by mistake. That's why I stated not to remove messages from this folder unless you know they're truly 'good', since you're not protected as well if you do.
I realized ling ago that your email account is an important part of your identity, so I treated mine as such from early on, avoiding as many pitfalls as I could and limiting not only who had access to it, but also teaching those who did not to do things like send email blasts of things like jokes with everyone's email addresses CC'd for example. I not only limit which individuals have this, but also organizations, to limit the chance I'll be involved in a breach, which so far seems to have worked. I also have the tightest security (2FA, Authenticator, multiple alternate verification methods as backup) on both that and my mobile phone accounts, since those are how your identity can most easily be stolen.
Note that I know I'm far different from the average person with my background but doing even the most obvious and easiest of the things I've mentioned will typically avoid the worst situations. I'm truly no different than any other person now, since I'm retired and do little within the technical world other than post here. However, dropping the highly secure profile I've created to protect myself and thus the others I communicate with as well would simply be stupid, so the day I do that is the day I die or become incapacitated.
And my identity will still be safer after that happens as a result.
Rob