How Did This Company Get My Email Address?

The realistic ways a company you've never heard of ends up with your address — and how to find out which one applies.


A company you've never dealt with has your address for one of seven reasons: it was sold or shared by a company you did deal with, exposed in a breach, scraped from somewhere public, bought from a data broker, acquired when they bought another business, guessed, or given to them by you via something you've forgotten. With one address for everything you can rarely tell which. With a different address per company, the address itself names the source.

The seven routes

1. A company you used sold or shared it

The most common route, and usually lawful. It's often disclosed in a privacy policy under "partners" or "affiliates", and consented to by a pre-ticked box or by continuing to use the service. The FTC's consumer guidance says it directly: giving a company your address means "it might share or sell it to third parties." Source: FTC. Checked: 2026-08-19.

2. A breach

A company's database was stolen and traded. Breached data circulates indefinitely, so mail from a breach can start years after the event.

3. Scraping

Your address was published somewhere and harvested automatically. If you've ever put it on a personal site, a forum profile, a public repository, a job board, or a document that ended up indexed, assume it's been collected.

4. A data broker

Brokers compile records from many sources and sell them. The company emailing you may have bought a list segmented by location, age, or purchase history and never have interacted with you at all. See data brokers explained.

5. An acquisition

Customer lists are assets. When a company is bought, or goes under, the list transfers. You subscribed to a small newsletter in 2019; a marketing group bought the publisher in 2024; you are now on their list, legitimately as far as they're concerned.

6. Guessing

Dictionary attacks against common address patterns at large providers. No leak involved. If your address is predictable, some of your spam arrived this way.

7. You gave it to them

Worth checking honestly before assuming the worst. Competition entries, wifi captive portals, in-store receipt-by-email, warranty registrations, and event signups all create relationships people genuinely forget. This is also the route where a "partner offers" checkbox was ticked by default.

How to narrow it down

Without per-company addresses you're doing forensics with very little evidence, but these help:

What you observeWhat it suggests
They have your correct full nameA list with real profile data — a breach or a form you filled in, not a guess
Address only, no nameA bulk list, scraping, or guessing
They know your city or approximate ageBroker data or a company that collected it
They reference a real past purchaseAn acquisition, or a genuine sharing partner of that retailer
An old address of yours that you retired years agoAn old breach or an old list still in circulation
A misspelling of your name that you know you typed onceTraces to that specific signup — a rare gift

Also worth checking: whether your address appears in any known breach, via a breach-notification service. A hit doesn't prove causation but it narrows the field considerably.

The version where you just know

All of the above is inference from thin evidence. There's a setup where the question doesn't arise.

Give every company a different address. When a company you've never heard of emails gardencentre@yourdomain.com, exactly one organisation was ever given that address. They either sold it, shared it, lost it, or were acquired by whoever is now using it. Which of those it was is sometimes ambiguous; who was responsible never is.

That's the whole idea behind a unique email address for every website. It converts an unanswerable question into a fact you can read off the To: line.

What this doesn't tell you

Knowing which company is responsible doesn't tell you whether they sold your address deliberately, were breached, or were bought by someone with different ideas about marketing. It also doesn't get your data deleted from anywhere. It tells you where to direct your attention, and it lets you cut off the mail — which is more than the alternative offers.

What to do once you know

  • Unsubscribe if the sender is legitimate. In the US they must honour it within 10 business days, and afterwards may not sell or transfer your address. Source: FTC, CAN-SPAM Compliance Guide. Checked: 2026-08-19.
  • Disable the alias if you're finished with the company that leaked it. Mail stops without anyone's cooperation — see what that actually does.
  • Consider removal if the problem is broader than email — your name, address and phone on people-search sites is a different problem with a different fix. Removal vs prevention explains which you have.
  • Don't bother arguing. Asking a company how they got your address rarely produces a useful answer, and in most jurisdictions they aren't obliged to give you one in a form you'd find satisfying.

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started — free

Keep reading