Data Brokers

Changing Your Email Tells Them Who You Became

The two earlier posts in this series – The Cookie That Never Expires and What 1,500 Emails Reveal About Tracking – described how a hashed email address became the ad industry’s favorite way to connect you across companies, and then showed that happening in one person’s real mail. This post looks at the same problem from the other side: what happens when you try to get out from under it.

You switch to an email aliasing service. Over the next few weeks you work through every account you have and swap the old address for a fresh alias – the bank, the airline, the pharmacy, the streaming service, fifty places in all. It feels like real work, and it is. When you finish, you feel unlinked: the old address is retired, the new ones are scattered across dozens of services, and nothing ties them together but a list only you can see.

Continue reading

What 1,500 Emails Reveal About Tracking

The earlier posts on this blog – The Cookie That Never Expires and UID2: The Standard That Replaced the Cookie – made an argument about how the ad industry replaced the cookie with your email address. This post is not an argument. It is what happened when that argument got pointed at one person’s actual mail.

The corpus is two personal mailboxes, a handful of single-service aliases, and a script that never once touches the network – it only reads what senders already embedded in the message. What came back is a specific, traceable answer to the industry’s favorite defense, that tracking pixels are harmless aggregate telemetry counting opens. The mail says otherwise, and it says something stranger besides.

Continue reading