If you use one address for everything, you usually can't find out — you can only narrow it down. The useful evidence is what the sender knows about you beyond the address, whether your address appears in a known breach, and any typo or variant you only ever used once. If you want a definite answer rather than an inference, the only reliable method is to have given each company a different address in the first place, so the address that received the spam names its own source.
What evidence actually exists
The spam message itself gives you very little. Sender addresses and display names are forged routinely, and the content is deliberately generic. But a few things do carry signal:
| What you notice | What it narrows to |
|---|---|
| They have your correct full name | A list with profile data attached — a form you filled in, or a breach. Rules out scraping and guessing. |
| Address only, no name at all | Bulk list, harvesting, or a dictionary attack. |
| They know your city, age or rough income | Broker data, or a company that collected those fields directly. |
| They reference a genuine past purchase | That retailer, a sharing partner of theirs, or whoever acquired them. |
| An old address you retired years ago | An old breach or an old list still circulating. Dates the leak. |
| A misspelling you know you typed once | Traces directly to that one signup. The strongest evidence available. |
| The mail is in a language you don't use | Generic bulk list, resold internationally. Little signal about origin. |
Check the breach databases
Run your address through a breach-notification service. A hit tells you which companies are known to have lost data containing your address, with dates. It doesn't prove that any of them caused the spam you're seeing — but a recent breach at a company you used is strong circumstantial evidence, and it's free to check. How to read the result properly.
Check the message headers
Worth setting expectations honestly: the headers will tell you which servers relayed the message, which occasionally identifies the mailing platform being used. That's mildly interesting and it will not tell you who supplied the list. Sending infrastructure and list provenance are unrelated. Don't spend an evening on this.
Why one address makes it unanswerable
The structural problem is that a single address is compatible with every hypothesis. Every company you ever dealt with holds the same string, and so does every party they passed it to. There is no observation that distinguishes "the hardware shop sold it" from "the airline was breached", because both produce identical evidence: spam at that address.
You can narrow the field. You cannot close it. Anyone claiming a tool that identifies the leaker from a single shared address is describing something that isn't possible.
The version where the answer is unambiguous
Give each company its own address. When mail arrives at gardencentre@yourdomain.com from a company that is not the garden centre, exactly one organisation was ever told that address. The chain of custody has one link.
Note what this does and doesn't resolve. It identifies who was responsible with certainty. It doesn't tell you how — sold deliberately, breached, or acquired by someone new. That distinction usually matters less than people expect: in all three cases the practical response is the same.
- Decide whether you still want the relationship. If not, disable the alias and the mail stops — what that actually does.
- If you do, change the address on that account first, confirm the new one works, then disable the old one.
- Unsubscribe from the new sender if it's legitimate. In the US they must honour it within 10 business days and may not sell your address afterwards. Source: FTC, CAN-SPAM Compliance Guide. Checked: 2026-08-19.
- Don't bother asking the original company. "Where did you get my address?" rarely produces a useful answer, and in most jurisdictions they have no obligation to give you one in a satisfying form.
Starting from where you are
You can't retrofit attribution onto addresses you've already handed out — that data is gone. What you can do is make the question answerable going forward, which takes effect immediately for every new signup and gradually for old accounts as you migrate them.
Six months in, the situation inverts: instead of wondering who leaked you, you get an address telling you. How to set it up, and the seven routes a company can take to your inbox.