By William Weiner August 4, 2026
The two earlier posts in this series – The Cookie That Never Expires and What 1,500 Emails Reveal About Tracking – described how a hashed email address became the ad industry’s favorite way to connect you across companies, and then showed that happening in one person’s real mail. This post looks at the same problem from the other side: what happens when you try to get out from under it.
You switch to an email aliasing service. Over the next few weeks you work through every account you have and swap the old address for a fresh alias – the bank, the airline, the pharmacy, the streaming service, fifty places in all. It feels like real work, and it is. When you finish, you feel unlinked: the old address is retired, the new ones are scattered across dozens of services, and nothing ties them together but a list only you can see.
Is that actually true? For a specific, useful minority of those fifty accounts, yes. For most of them, the honest answer is closer to no.

What actually matters here
Three things decide whether this works, and none of them is how clever the alias itself is.
- Whether a company still recognizes you and whether that recognition reaches outside the company are two different questions. The first is always true and not the problem. The second is the actual one.
- Editing the email on an account you’re keeping protects less than it feels like it should. A genuinely new account is a stronger move, for reasons the next few sections lay out.
- Phone number is usually doing more of the linking than email, and most people guard it far less.
Everything below is the evidence for those three points, plus a set of questions at the end for deciding, service by service, whether migrating is worth the effort at all.
Why this is worth caring about at all
This post has an assumption built into it: that a data broker or ad platform connecting your accounts is bad for you. That’s not universal. If you don’t think it matters whether a stranger’s database can tie your pharmacy purchases to your job search to a political donation from three years ago, everything below is still accurate, it just may not be worth the effort for you.
If you’re not sure, here’s the concrete version. The FTC’s own review of the industry found brokers building and selling lists of people sorted into categories like “Financially Challenged” or “Consumer with Clinical Depression,” and using the same underlying data for credit, insurance, and employment eligibility decisions, not just ad targeting. A joined profile also concentrates risk on its own: one breach or one subpoena now reaches everything tied together under it, not just whatever a single company had on you. And for some readers – anyone dealing with a stalker, an abusive ex, or work that makes them a target – the stakes run well above pricing or ad relevance. If any of that is why you’re here, keep reading; the rest of this post assumes you’re already convinced and gets straight to what to do about it.
The company already knows
Start with the claim that’s always true and never the point: the company you just handed a fresh alias to still knows exactly who you are. Your bank knows because it’s routing statements to your mailing address and charging a card with your name on it. None of that depends on which email happens to be on the account this month. That’s first-party recognition, and it’s boring by design – it isn’t data leaving the company, it’s the company doing the thing you signed up for it to do.
The question that matters is narrower: when you swap the old address for a new alias, does that reach a third party – an ad platform, a data broker, an identity-resolution vendor – in a form that reconnects your new identity to your old one? For a meaningful slice of the internet, yes, and the next two sections explain how.
How the match actually happens
The obvious worry is that some tracking token follows you across the change, that the same UID2 or a similar hashed identifier survives an email swap. It doesn’t: UID2 is a deterministic hash of the raw address, so a new email produces a new, unrelated token, full stop. If that were the whole story, migration would work exactly the way it feels like it should.
It isn’t the whole story, because ad platforms don’t match people on a single field. Google’s own Customer Match program lists email, phone, and mailing address, as name plus zip code, as interchangeable match keys, and recommends uploading as many as a business has on file, because more shared fields raise the match rate. Matching on any one of those shared fields is enough on its own: Aerospike, a vendor that builds this kind of matching infrastructure, describes deterministic matches on “hashed email addresses, login names, or loyalty numbers” as holding with “near-perfect certainty.”
That’s the actual mechanism, and it’s more mundane than a graph piecing together scraps of circumstantial evidence. When you edit the email on an account you’re keeping, email is usually the only field that changed. Your phone number, your name, your shipping address, your login – whatever else that company has on file – stayed exactly the same. The next time that company refreshes whatever it uploads to an ad platform, the new email rides in on a record that still matches the old one perfectly on every other field. No inference is required and no pattern has to be noticed; the match is deterministic. You didn’t escape being recognized. You just confirmed which company the recognition came from.
A brand-new account is a stronger move, because there’s no shared record for a match to land on in the first place – but it isn’t automatically clean either. LiveRamp’s own documentation for its operator customers describes a new email initially getting its own identifier, unconnected to anything, until the system observes enough of those same other signals – a shared postal address, a shared device, a matching name – and merges it into an existing profile anyway. Email-change-of-address matching, sold commercially by vendors like AtData under the name ECOA, exists specifically to catch this even when a company never explicitly links the two emails itself. The FTC’s 2014 data-broker report described the general version of this as “onboarding”: folding updated contact information into an existing profile, standard industry practice, not an edge case.
Put simply: whatever fields stay the same are what re-attach you, whichever way the new email arrives.
The field you didn’t think to guard
Given that, one field deserves special attention: phone number is usually the stronger identifier of the two, not email.
One identity-resolution vendor puts it plainly about its own methods: phone numbers create a stronger real-world link than email addresses, “which can be created anonymously in seconds,” functioning as something close to a universal identifier, more persistent than email tends to be. Epsilon, another major identity-resolution vendor, describes email in almost the same terms from its own side: email is “among the most common anchors used across the industry, but it is also one of the weakest.”
If breaking the link is the actual goal, that reorders where the effort belongs: a masked or forwarding phone number, or simply declining to give the real one where it’s optional, does more than rotating email addresses at accounts where the phone number on file never moves. Or, more simply: don’t bother swapping the email if the company still has your real phone number.
What aliases still win
None of this makes aliasing pointless. It means the payoff is compartmentalization, not disappearance. Before you adopted aliases, one address connected you across every company you gave it to and every broker downstream of them. After, each service holds an identifier that’s useless for connecting you to any other service, because nothing ties one alias to another.
Two of the plainest benefits don’t depend on any of the backend mechanics above at all. A unique alias per company tells you exactly which one leaked the moment spam starts arriving or a breach notice goes out, and it’s the alias that’s exposed, not an address you actually need, so you switch it off and move on rather than starting over. And a message claiming to be your bank that shows up at the alias you gave to a completely different company is an immediate, unambiguous tell that it isn’t your bank – no data broker, matching algorithm, or identity graph has to be involved for either of those to work.
The backend question is a separate layer on top of that. Even where a company’s other fields re-attach your identity in a broker’s records (the previous two sections), a tracker-stripping relay paired with unique per-service aliases still starves the behavioral feed that makes an old link valuable – the broker’s profile may still correctly point to you, but it stops accumulating fresh signal from your email activity specifically. A static identity edge with no fresh signal riding on it decays. Compartmentalization and behavioral starvation are both real, they just answer different questions: does the profile still identify you, and does it keep learning anything new about you. The first can stay true while the second stops being true, and that second win is worth having on its own.
The size of the group sharing a value matters too. A commercial domain like gmail.com doesn’t block tracking in any general sense – Google tracks its own users plenty by other means. What it blocks is domain-as-linking-key between otherwise unrelated addresses, because billions of people share it, so the domain itself carries no identifying signal on its own. A value shared by enough people carries less information about any one of them, an idea privacy researchers have formalized since at least Latanya Sweeney’s early reidentification work, which found that zip code, birth date, and gender alone uniquely identify 87 percent of Americans. A domain used by one person, or one household, sits at the opposite end of that scale.
The domain is a different kind of exposure
Everything so far is about matching on hashed fields, where what matters is which fields stay the same, not what any single one says. Domain choice is a different mechanism entirely, because a domain is something other people can simply read, no hashing or matching involved. If you’re the only person using a personal or family domain, anyone who ever sees one of your addresses in plain text – another recipient on a message, a company employee, a data leak – can tell at a glance that every address on that domain belongs to the same small group.
Privacy Guides, an independent nonprofit with no ad-tech affiliation to protect, states this directly in its own guidance on email aliasing: using a custom domain carries a real privacy drawback, because if you’re the only person using it, your activity can be tracked across every site simply by reading the domain off the address. A second writeup, from Mark Pitblado, adds a related point: even paying for WHOIS privacy on the domain only narrows the gap, since it remains fairly trivial for anyone motivated to work out who owns it.
The family exception – “we’re a household, surely that’s different” – deserves a direct answer, because it’s the version promoted most often. It isn’t a safe exception. A shared family domain’s anonymity set is two to six people, smaller than a single stranger’s custom domain, and the fact that a set of addresses all belong to one household is exactly the signal a family wanted to keep to itself. The same mechanism already exists as a commercial product one level up: B2B data vendors sell “domain affiliation linking” – splitting an email at the @ and using the domain alone to identify which company someone works for. A family domain is the same trick working against a group of two to six people instead of a company of thousands, which makes it a far stronger signal, not a weaker one.
EMail Parrot’s own aliases run on the shared emparrot.com domain by default, the configuration we recommend to anyone optimizing for privacy rather than a customer’s own custom domain – the same big-shared-domain category as Firefox Relay’s or SimpleLogin’s shared domains, for the reason above.
Deletion doesn’t undo the link either
A natural next thought is to skip the account question and just ask companies to delete the old record. That gets you partway. The identifier a broker holds is derived from your data, not stored as some independent secret, so deleting one record doesn’t remove the capability to reconstruct it – the next sync that touches an identifier you’re still using anywhere regenerates it and the profile reappears. Erasure without changing what feeds it is a revolving door, not a closed one.
A category of service exists specifically to fight this from the deletion side, automating opt-out and removal requests across people-search and broker sites at scale. It’s worth knowing what independent testing shows, because the category’s own marketing tends to overstate it: Consumer Reports tracked several hundred pieces of personal information across dozens of volunteers and seven paid removal services over four months in 2024, and found an average removal rate of 35 percent, with a wide spread between the best and worst performers – manual removal by expert researchers did better, about 70 percent, mostly a measure of how much time the paid services save you rather than how thorough they are. That’s a meaningfully-better-than-nothing track record, not a guarantee.
The revealing detail is the business model: every service in the category sells a subscription, typically re-running every sixty to ninety days, because a removal doesn’t stick while whatever originally fed the profile – an unrotated email, an unmasked phone number, an address at a company you still use – keeps re-feeding it. That’s exactly why pairing a removal service with alias hygiene is complementary rather than redundant: one drains what’s already collected, the other stops the next connection from forming. Neither does the other’s job. Erasure, jurisdiction, and the legal right to be forgotten are a bigger topic than fits here; a separate piece is coming.
So which accounts should you migrate
Start with the account question:
- Keeping an existing account and just editing the email field: treat this as unlikely to unlink you at any company with a real marketing operation behind it, whatever else is or isn’t attached to the account. That doesn’t make it worthless – a one-off alias per company still tells you which one is the source if it starts drawing spam or turns up in a breach, and it’s the alias that leaks, not your real address, since an alias can be switched off and a real inbox can’t. It just doesn’t buy the third-party unlinking the rest of this section is about.
- Opening a genuinely new account: the questions below decide whether it stays unlinked.
For a new account, walk through what the company will have on file:
- Your phone number, unmasked: assume it re-attaches you at any organization whose marketing stack touches a major ad platform, which is most of them past a certain size. A new email next to an old, unmasked phone number is close to symbolic, and this is the single biggest lever in the whole list – a service that insists on a real phone number undoes most of what a fresh email buys you no matter what else you do.
- Your name and shipping address: only a risk if the name is your real, verified one. Google’s own Customer Match program lists mailing address alongside email and phone as a supported match key, but the key is name plus zip together – a zip code paired with a name nobody checks doesn’t match anything. The tell is verification: if a company confirms your name against a payment card or an ID, assume the real name is on file regardless of what you typed elsewhere; if nothing checks it, a different name breaks the pairing even with a real shipping address underneath it.
- Paying by card: the card number itself isn’t the issue, PCI rules wall payment data off from marketing systems. The issue is what usually travels with it – card networks verify the billing name and zip against the cardholder on file, which is exactly the real, verified name-plus-zip pairing above. A card payment is often the thing that pins your real name to an otherwise pseudonymous account.
- Uncertainty about whether the company’s email vendor syncs to an ad platform: treat the email as already exposed the moment you hand it over, new account or not, since that’s the safe assumption for most companies past a certain size.
That leaves a real category where a fresh account is worth the effort: services that only need an email and a name nobody verifies – newsletters, forums, some media and content sites, a free-tier signup with no card, no shipping address, and no required phone field, started clean rather than grown out of an account you already had. For those, a unique alias paired with a name that isn’t your legal one is close to the strongest unlinking an ordinary person can manage. If a phone number turns out to be required after all, mask it or use a forwarding number – see above for why that single field matters more than the rest of this list combined. And wherever a fresh account is the right call, don’t reuse the alias anywhere else – reusing it across two services recreates the exact single-identifier problem this post is about.
What a well-designed alias setup actually buys you
None of this is an argument against aliasing. It’s an argument for spending the effort where it pays off, and for being honest about what migrating needs to mean.
- Pair a fresh alias with an actual new account, not an edited field in an old one – that’s what keeps old and new identifiers from being connected across the companies and brokers you deal with.
- Guard the phone number field at least as carefully as the email field; it’s usually doing more of the work.
- Expect real limits: no alias out-migrates a phone number you’re still handing out freely, a real name and address a company already uses for ad matching, or an account you kept instead of leaving behind.
That’s what EMail Parrot is built to give a list’s members by default, not as an upgrade. Every member gets an alias automatically, nothing to pre-create in a separate app first, on the shared emparrot.com domain rather than a beacon of a custom one. If a particular list turns out to be the source of spam, or ends up handled carelessly by whoever runs it, the alias is what was exposed, and the alias is what gets turned off – the real inbox underneath it was never handed out and was never at risk. Every message also gets the tracker-stripping treatment described earlier in this series, on every list, with no setup required from either the list owner or the member. We would rather describe that specifically than claim you’ll be untrackable in general, because the specific claim is the one we can actually keep, and this whole post has been an argument for why the general one, from anyone selling it, deserves a second look.
Questions about aliases? Email us at info@emparrot.com.
