← Back to list

Check If Your Email Address Has Been Sold to Companies You’ve Never Heard Of

A free email setting tells you exactly who’s responsible

Sabit in Bash & DevOps & Life Lessons · 2026-06-19 15:27 · 1 claps · 3.6 min read paywalled
#privacy #technology #data-privacy #email #productivity
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity ⏱️ · Productivity

Check If Your Email Address Has Been Sold to Companies You’ve Never Heard Of

A free email setting tells you exactly who’s responsible

Photo by Kelly Sikkema on Unsplash

Photo by Kelly Sikkema on Unsplash

You sign up for one thing.

Maybe a contest, a coupon, or a free trial you forgot to cancel, and within weeks your inbox is full of emails from companies you never gave your address to directly.

You didn’t imagine it. Your email almost certainly got sold. Then, passed along to a data broker, and resold again to whoever was willing to pay for a list of real, active addresses.

Most people just assume there’s no way to know who actually did it. There is. And there’s also a real way to fight back now, not just unsubscribe and hope.

The trick that exposes exactly who sold you out

This works because most email providers, Gmail, Outlook, and iCloud included, let you quietly customize your own address without creating a new account.

On Gmail, you can add a plus sign and any word right before the @ symbol, and the email still lands in your normal inbox.

yourname+target@gmail.com

So instead of giving a sketchy coupon site your real address, you’d give them a variation by adding a plus sign and a word in front of “@gmail.com,” which still delivers to your real inbox. Use a different tag for every company you sign up with.

Here’s what that actually looks like in practice. Say your real address is johndoe@gmail.com. You'd hand out a slightly different version to each place you sign up.

johndoe+coupons@gmail.com       (for that coupon site)
johndoe+contest2026@gmail.com   (for a one-time contest entry)
johndoe+appname@gmail.com       (for a free trial app you're unsure about)

All three still land safely in your normal johndoe@gmail.com inbox, untouched.

Gmail ignores everything after the plus sign when delivering mail, but it keeps that tag visible in the "To" field of every email you receive. So the moment spam shows up addressed to johndoe+coupons@gmail.com, you know immediately it traces back to the coupon site. Even if the spam itself arrives from a completely different, unrelated-looking sender.

This trick works the same way in Outlook and iCloud too, so you’re not locked into Gmail to use it.

This single setting turns a vague suspicion into actual evidence. The kind you can point to instead of guessing.

Check if you’ve already been caught up in a breach

Before you even start tagging new signups, it’s worth checking what’s already out there.

“Have I Been Pwned” website lets you type in your email address and immediately see which companies holding your data have been breached, along with what specific information was exposed.

If your email shows up tied to a breach you don’t remember, that’s often the original leak point.

Search your own inbox for the paper trail

You likely already have evidence sitting in your inbox right now.

Search for “unsubscribe” and “privacy policy” across emails from the last few months. Cross-referencing the sending domains against known data broker names like Acxiom, Experian, and LiveRamp often reveals the pattern fast. Since legitimate marketing emails are legally required to disclose some of this in their footer text, even if it’s buried in fine print nobody reads.

What’s actually happening behind the spam

There’s a large industry behind this, worth billions of dollars, built almost entirely around collecting and reselling personal information most people never agreed to share knowingly.

Specific companies known as “people-search” brokers package up your name, address, phone number, email, and even estimated income, then sell that profile for a few dollars to anyone who asks.

That’s why a single forgotten signup years ago can still be generating spam today. Your information doesn’t just sit with the first company. It gets sold, then resold, sometimes for years after you’ve completely forgotten the original site existed.

The new option that didn’t exist before 2026

Here’s the part most articles on this topic haven’t caught up to yet.

California has built a state-hosted deletion platform called DROP, where you can submit one deletion request that reaches every registered data broker in the state at once, instead of contacting each one individually.

Starting August 2026, brokers are required to check this system every 45 days and actually delete your data within that window, or face real financial penalties.

Brokers that ignore deletion requests can be fined a couple hundred dollars per day per person affected. This is a real enforcement mechanism, not just a polite opt-out request that gets ignored.

What not to bother with

Skip browser extensions that promise to “scan for leaks.” Many of these work by harvesting the very email address you’re trying to protect, just from a different angle.

Be equally cautious of paid “data removal services” that ask for your full name, date of birth, and Social Security number upfront. Handing over more sensitive information to fix a smaller leak tends to create a bigger one.

What to actually do with what you find

Once you’ve identified the source through your tagged address or inbox search, you have a real choice to make.

Unsubscribe from the original sender. Check whether that company operates in a state with an opt-out law, and submit a request if so.

And going forward, start tagging your email address by default for anything that isn’t a company you already trust, so the next time this happens, you won’t need to investigate at all. You’ll already know.


메타데이터
post_id
cbffd3664692
slug
check-if-your-email-address-has-been-sold-to-companies-youve-never-heard-of-cbffd3664692
url
https://medium.com/my-lifes-mirrow/check-if-your-email-address-has-been-sold-to-companies-youve-never-heard-of-cbffd3664692
canonical_url
https://medium.com/my-lifes-mirrow/check-if-your-email-address-has-been-sold-to-companies-youve-never-heard-of-cbffd3664692
author_url
https://medium.com/@tibas
status
ok
fetched_at
2026-06-23 17:05:31