A company you've never dealt with has your address for one of seven reasons: it was sold or shared by a company you did deal with, exposed in a breach, scraped from somewhere public, bought from a data broker, acquired when they bought another business, guessed, or given to them by you via something you've forgotten. With one address for everything you can rarely tell which. With a different address per company, the address itself names the source.
The seven routes
1. A company you used sold or shared it
The most common route, and usually lawful. It's often disclosed in a privacy policy under "partners" or "affiliates", and consented to by a pre-ticked box or by continuing to use the service. The FTC's consumer guidance says it directly: giving a company your address means "it might share or sell it to third parties." Source: FTC. Checked: 2026-08-19.
2. A breach
A company's database was stolen and traded. Breached data circulates indefinitely, so mail from a breach can start years after the event.
3. Scraping
Your address was published somewhere and harvested automatically. If you've ever put it on a personal site, a forum profile, a public repository, a job board, or a document that ended up indexed, assume it's been collected.
4. A data broker
Brokers compile records from many sources and sell them. The company emailing you may have bought a list segmented by location, age, or purchase history and never have interacted with you at all. See data brokers explained.
5. An acquisition
Customer lists are assets. When a company is bought, or goes under, the list transfers. You subscribed to a small newsletter in 2019; a marketing group bought the publisher in 2024; you are now on their list, legitimately as far as they're concerned.
6. Guessing
Dictionary attacks against common address patterns at large providers. No leak involved. If your address is predictable, some of your spam arrived this way.
7. You gave it to them
Worth checking honestly before assuming the worst. Competition entries, wifi captive portals, in-store receipt-by-email, warranty registrations, and event signups all create relationships people genuinely forget. This is also the route where a "partner offers" checkbox was ticked by default.
How to narrow it down
Without per-company addresses you're doing forensics with very little evidence, but these help:
| What you observe | What it suggests |
|---|---|
| They have your correct full name | A list with real profile data — a breach or a form you filled in, not a guess |
| Address only, no name | A bulk list, scraping, or guessing |
| They know your city or approximate age | Broker data or a company that collected it |
| They reference a real past purchase | An acquisition, or a genuine sharing partner of that retailer |
| An old address of yours that you retired years ago | An old breach or an old list still in circulation |
| A misspelling of your name that you know you typed once | Traces to that specific signup — a rare gift |
Also worth checking: whether your address appears in any known breach, via a breach-notification service. A hit doesn't prove causation but it narrows the field considerably.
The version where you just know
All of the above is inference from thin evidence. There's a setup where the question doesn't arise.
Give every company a different address. When a company you've never heard of emails gardencentre@yourdomain.com, exactly one organisation was ever given that address. They either sold it, shared it, lost it, or were acquired by whoever is now using it. Which of those it was is sometimes ambiguous; who was responsible never is.
That's the whole idea behind a unique email address for every website. It converts an unanswerable question into a fact you can read off the To: line.
Knowing which company is responsible doesn't tell you whether they sold your address deliberately, were breached, or were bought by someone with different ideas about marketing. It also doesn't get your data deleted from anywhere. It tells you where to direct your attention, and it lets you cut off the mail — which is more than the alternative offers.
What to do once you know
- Unsubscribe if the sender is legitimate. In the US they must honour it within 10 business days, and afterwards may not sell or transfer your address. Source: FTC, CAN-SPAM Compliance Guide. Checked: 2026-08-19.
- Disable the alias if you're finished with the company that leaked it. Mail stops without anyone's cooperation — see what that actually does.
- Consider removal if the problem is broader than email — your name, address and phone on people-search sites is a different problem with a different fix. Removal vs prevention explains which you have.
- Don't bother arguing. Asking a company how they got your address rarely produces a useful answer, and in most jurisdictions they aren't obliged to give you one in a form you'd find satisfying.