What Your Email Address Reveals About You

More than you'd expect, and some of it before the message is even read.


Before anyone opens the message: usually your name, often your rough age, sometimes your employer, and a reasonable guess at your technical literacy and how long you've been online. None of it is catastrophic on its own. It matters because these are the attributes used to segment marketing lists and to make a phishing attempt convincing — and because an address is also the stable key that links your records across unrelated datasets.

What the parts give away

ComponentWhat it suggests
firstname.lastname@Your real name. Also highly guessable, so it attracts dictionary attacks with no leak required.
Birth year in the addressYour age, exactly. Common in addresses created as a teenager.
@company.comYour employer, and often your seniority from the format.
Older provider domainsRoughly when you created it, and a demographic guess follows.
A privacy-focused providerTechnical literacy. Sometimes triggers extra fraud scrutiny at signup.
A custom domainThat you own a domain — and if WHOIS privacy is off, your name and postal address.
Nickname or handleOften reused elsewhere, which links accounts across sites.

Why any of it matters

It makes phishing convincing

An attacker who can infer your name, employer and approximate age writes a far more plausible message. Combined with breach data — real purchase history, real account details — "convincing" stops being evidence of legitimacy. Recognising it anyway

It segments you

A bare address is a cheap bulk record. An address that implies age, location and employment is a segmented one, worth more and resold more often.

It's the join key

The most consequential property, and the least visible. Because an address is unique and stable for years, it's what lets separate datasets be matched into one profile. Your address isn't valuable because someone wants to email you — it's valuable because it links things. Why brokers want it specifically

A reused handle links your accounts

If the part before the @ is a handle you also use on forums and social platforms, anyone can connect those accounts by searching it. This is often a larger exposure than the address itself.

What to do

  1. Don't put your birth year in an address. If yours has one, that's a reasonable prompt to change it.
  2. Avoid perfectly predictable formats at large providers — firstname.lastname@gmail.com gets attacked without any leak.
  3. Don't reuse a handle you use publicly elsewhere.
  4. Turn on WHOIS privacy if you own a domain. Why
  5. Use per-organisation addresses, which breaks the join key: each company holds a fragment matching nothing else.

The counter-intuitive part

A custom domain reveals more, not less

An address at a big shared provider hides you in hundreds of millions of others. An address at @yourdomain.com is used by one person, is registered to someone, and links every account you use it on.

That's the same property that makes attribution work for you and correlation work for others. It's the right trade for spam control and the wrong tool for anonymity — and worth choosing deliberately rather than by accident. The boundary

More: protecting your address · the complete guide

Part of the Email Privacy guides.

The full picture: The Complete Guide to Email Privacy

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started — free

Keep reading