How to Stop Data Brokers Getting Your Email in the First Place

Removal fights the output. This is about the inputs, which is the half you control.


You can't stop public records, but you can stop being easy to match โ€” and that's most of what matters. Brokers want your email address specifically because it's the join key that links your records across unrelated datasets. Give each company a different address and the key stops working: each broker holds a fragment that matches nothing. Combined with giving away less at signup, that addresses the inputs rather than fighting the output.

Why they want the address

Not to email you. To match you.

Aggregation only works if records can be joined. Names are ambiguous, postal addresses change when you move, phone numbers change. An email address is unique, stable for years, and used by the same person across hundreds of unrelated services โ€” which makes it the ideal identifier for merging a retail purchase history with a property record with an app's location data.

That's the whole reason it appears in nearly every broker dataset. The four routes it takes to get there

The four inputs, and what you control

RoutePreventable?What to do
Companies you gave it to sharing or sellingYes, going forwardA different address per company; decline "partner" boxes
Scraping from public pagesYesNever publish your real address; use a burnable alias
BreachesNoContainment โ€” one address per company limits the blast radius
Broker-to-broker tradeNoRemoval requests, repeated

Two of four are genuinely preventable, and the same habit prevents both.

What to actually do

1. A different address per organisation

The one with structural effect. An address only one company holds is near-worthless as a join key โ€” there's nothing to join it to. It can still be sold, but what's sold is an orphan fragment.

And when a broker does use it, the address names its source, so you know who sold you and can switch it off. How to run it

2. Never publish your address in plain text

Forum profiles, public code repositories and commit metadata, CVs on job boards, conference lists, PDFs, WHOIS records. Automated harvesters do nothing else. Obfuscation like "name [at] example [dot] com" was mildly effective two decades ago and is parsed trivially now.

3. Turn on WHOIS privacy

Registrant records are a standard harvesting source. If you register a domain for email privacy without this, you've published your name and postal address to fix an email problem. Details

4. Fill in required fields only

A bare address is a cheap bulk record. An address with a birthday, postcode and purchase history is a segmented profile worth reselling. Optional fields are how the second happens. The signup routine

5. Decline the loyalty-scheme trade knowingly

The discount is payment for data โ€” that's the arrangement, and it's usually disclosed. Worth taking sometimes; worth taking deliberately rather than by default.

What this doesn't reach

Honest limits
  • Public records stay public. Property, voter and court records are published by law. Nothing here changes that.
  • Your existing address is already out. This is prospective only โ€” it stops the problem growing, it doesn't shrink it.
  • Breaches still happen. You reduce what each one exposes, not whether they occur.

If records already in circulation are your problem, that's removal, and it's a different tool. The distinction ยท Free removal routes

More: data brokers explained ยท people-search sites

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started โ€” free

Keep reading