How Do Data Brokers Get Your Email Address?

Email is the industry's preferred join key. That's why it spreads further than anything else you hand over.


Four routes, in rough order of volume: companies you gave it to share or sell it; it's scraped from anywhere it appears publicly; it arrives in breach data that leaks into circulation; and brokers buy and trade it among themselves. Email matters more than other fields because it's the industry's preferred join key — stable, unique and easy to match across datasets, which is exactly what makes a profile assemblable from fragments.

Why email specifically

Start with why brokers want it, because that explains the rest.

Aggregation only works if records can be matched. Names are ambiguous — thousands of people share yours. Postal addresses change when you move. Phone numbers change. An email address is unique, stable for years, and used by the same person across hundreds of unrelated services.

That makes it the ideal identifier for merging a retail purchase history with a property record with an app's location data. Your address isn't valuable because someone wants to email you. It's valuable because it's the key that turns fragments into a profile.

This is also the single strongest argument for a different address per service. An address only one company holds is worthless as a join key — there's nothing to join it to.

Route 1 — Companies you gave it to

The largest source, and mostly lawful. The FTC's consumer guidance says it directly: "When you give a company your email address, it might share or sell it to third parties." Source: FTC. Checked: 2026-08-19.

The usual channels:

  • Loyalty schemes. The discount is payment for the data. That's the business model, disclosed in the terms.
  • Competitions and prize draws. Frequently list-building exercises with a real prize attached.
  • Free downloads and gated content. The white paper is the cost of acquiring you.
  • Wifi captive portals. Airport, hotel and café logins that ask for an address.
  • Receipt-by-email at checkout. Convenient, and it links your address to your purchase history.
  • "Partner offers" checkboxes, sometimes pre-ticked, which is the explicit consent to onward sharing.
  • Acquisitions. Customer lists are assets. When a company is sold or wound up, the list transfers.

Route 2 — Scraping

Automated crawlers collect addresses published anywhere in plain text. The places people forget: forum profiles, public code repositories and commit metadata, CVs on job boards, conference attendee lists, community directories, PDFs that got indexed, and WHOIS records for domains registered without privacy protection.

Obfuscation like "name [at] example [dot] com" was mildly effective two decades ago and is parsed trivially now. If an address needs to be public, make it one you're prepared to burn.

Route 3 — Breach data

Not a legitimate source, but leaked datasets circulate indefinitely and don't reliably stay separate from legitimate ones. This is why spam can begin years after a breach and arrive from operators with no idea where the data originated.

How to check whether yours is in one.

Route 4 — Broker-to-broker trade

The industry trades internally. One broker's dataset becomes part of another's, which is why opting out of one has limited effect on the others, and why a record you deleted can reappear from a source you never dealt with.

It's also why removal is recurring rather than a one-off job — the mechanism explained.

What this means for what you can do

RouteCan you prevent it?What helps
Companies sharing or sellingYes, going forwardA different address per company. The one they sell is then worthless as a key.
ScrapingYesNever publish your real address; use a burnable alias where one must be public.
BreachesNoContainment — one address per company limits the blast radius.
Broker-to-broker tradeNoRemoval requests, repeated. Free via DROP for California residents.

Two of the four are genuinely preventable and both are prevented by the same habit. The other two are containment problems, where the question isn't whether it happens but what it costs you when it does.

The uncomfortable part

None of this helps with the address you've already been using. It's in circulation, it will stay there, and no service can recall it. Removal requests reduce your presence among brokers who honour them; they don't take the data out of existence.

What changes is the next fifteen years. If every company gets its own address, the join key stops working — each broker holds a fragment that matches nothing else, and any leak names its own source.

More: data brokers explained · a unique address for every website · how to remove your email from brokers

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started — free

Keep reading