The signup form is where the exposure happens, and it takes about sixty seconds to handle properly. Give the site its own email address rather than your real one, fill in only the fields marked required, un-tick every marketing and "partner" box, and skip the optional profile details that turn a bare address into a resellable record. Do that consistently and the spam problem stops growing from today.
The form, field by field
Email โ an address specific to this site
The single highest-value decision on the page. One address per site means a leak is contained, identifies its source, and can be revoked without touching anything else. How to run it.
Optional fields โ leave them
Birthday, phone number, postcode, gender, job title. Each one you complete upgrades your record from "an email address" to "a profile", which is the difference between a cheap bulk list and a valuable segmented one.
If a field isn't marked required, it's there because the data is worth something to somebody. That's not sinister, but it's not free either.
Phone number โ only if the service genuinely needs it
Delivery, two-factor authentication, yes. "For account security" on a newsletter signup, no. A phone number is harder to change than an email address and there's no alias equivalent for most people.
The checkboxes
Read them, including the pre-ticked ones. The two patterns to watch:
- "Send me offers" โ that's the sender's own marketing, which you can unsubscribe from later.
- "Share with carefully selected partners" โ that's onward distribution, and it's much harder to undo. Once your address is with the partners, unsubscribing from the original company doesn't reach them.
The second is the one that matters. Un-tick it even if you're happy to hear from the company itself.
Where signups happen that you don't think of as signups
- Wifi captive portals in airports, hotels and cafรฉs.
- Receipt-by-email at a physical till.
- Competitions and prize draws, where list-building is often the point.
- Gated downloads โ the report is the price of acquiring you.
- Warranty registration for something you bought.
- Event and conference registration, where attendee lists are sometimes shared with sponsors.
Each of these is a permanent new holder of whatever address you give it. They're also the ones people most often can't account for later โ how did this company get my email?
Social sign-in
"Continue with Google" or "Continue with Apple" is genuinely better than a password, and Sign in with Apple can hide your address for you. Two things to keep in mind: Google sign-in shares your real address with the site, and social sign-in creates a dependency โ losing that account can lock you out of everything attached to it.
A reasonable compromise is social sign-in for low-stakes accounts, and email plus a password manager for anything you'd hate to lose.
What this doesn't cover
It isn't anonymity. You gave them your real name, and often your address and card. The alias controls which inbox their mail reaches; it doesn't disguise who signed up.
It doesn't help retroactively. Every form you filled in before today already happened. This changes the trajectory from here, which is the only part still available to you.
The sixty-second routine
- Invent an address for this site and type it in.
- Fill only what's marked required.
- Un-tick marketing, and especially "partners".
- Save it in your password manager, which records the address for you.
More: should you give websites your real email? ยท the email privacy checklist