No. That is the lens I read this through: I run AliasFleet, an email-alias service, because I watched what happens to addresses after the signup and stopped handing mine out. The honest answer is also the fix: no single address should ever sit in every database.
The question looks simple. It is not, because "websites" are not one thing. Your bank, your newsletter, the shoe store that offered 10 percent off: all three ask for the same field, and all three do very different things with it. What they share is this: the moment you type your address in, you stop being its only custodian. And the database does not forget.
Where your address goes
There are four exits out of a website's database. Most addresses leave through more than one.
| Exit | What happens | Scale |
|---|---|---|
| The breach | The database is stolen and the addresses start circulating | Have I Been Pwned: 1,039 breaches, 17.8 billion addresses |
| The broker trade | Data is sold or shared with partners, brokers, and lead sellers | The FTC found brokers holding billions of data elements on almost every US consumer (summary) |
| The spam list | Addresses land in working lists that get rented, bought, or stolen | An actual spam operation's list of 393.4 million addresses sits in HIBP |
| The phish kit | Your address is paired with your name for targeted fraud | See the DTU and Hana Bank breaches |
Is every website going to sell my email?
No. Most sites do not have a sell button, and plenty of businesses guard customer data properly. But "not selling" is not the same as safe. Privacy policies routinely allow sharing with "marketing partners" and service providers, the address sits in a database for years, and databases get breached. Selling is only one of the four exits.
Some companies are explicit about it. Marketing-leads firms exist to hold contact lists as inventory: LimeLeads kept 17.8 million records until an exposed server lost them, and the breach entered HIBP this September. A company whose business was contact data lost its contact data. When your address is inside a database like that, the privacy policy of the site you originally gave it to stops mattering.
What do data brokers actually do with email addresses?
They buy, combine, and resell consumer data. They trade with each other, too. The FTC's 2014 study of nine brokers found "billions of data elements pertaining to almost every U.S. consumer", shared between brokers and used to draw "potentially sensitive inferences". Consumers, the FTC found, mostly had no idea the market existed. The trade is still going.
That was 2014, and enforcement since has only confirmed the picture. In January 2024 the FTC banned data broker X-Mode and its successor Outlogic from selling sensitive location data, the first order of its kind. The FTC's account reads like a map of the whole trade: data collected from third-party apps, bought from other brokers, sold to hundreds of clients, never anonymized. Where brokers build datasets from web signups, the email is usually the cheapest join key: the same string sits on the store receipt, the app signup, and the broker's spreadsheet, so linking records takes little effort.
Why do breaches keep getting worse for addresses?
Because addresses do not expire. A password gets reset; an address stays yours for years, and every signup adds another database holding it. HIBP now counts 1,039 breaches and 17.8 billion pwned addresses, and its table is full of breaches that surfaced years after they happened. An address you gave away in 2016 can start costing you in 2026.
That lag is the part nobody plans for. You do not get to declare a signup "over". The address keeps circulating long after you forgot the site existed.
What does the second wave look like?
It looks like a message that knows things about you: your name, your bank, the service you actually use. Familiar details. From a stranger. Breach data is the raw material of targeted phishing: the DTU breach put national ID numbers next to work email addresses, and the Hana Bank leak handed fraudsters names, workplaces, and phone numbers.
The usual advice, checking for typos, dies here, because the details are real and nothing about the message looks wrong except the ask itself. That is why the To field matters. It is the one detail that names the source you gave the address to.
The middle path: never hand out the real one
You are not going to stop signing up for things, and neither am I. So change what the signup receives.
- Keep your real address for a short list: bank, government, employer, family. Everything else gets an alias. If the difference is not clear, start with what an email alias is.
- One alias per site, named after the site. Your alias list reads like a map of who holds what. Our guide to using aliases has twelve places to start.
- When spam or phishing lands on an alias, read the To field: it names the site that leaked or sold it, so you know exactly which signup to kill. The leak stops at that address and your real inbox never knew it existed. The leak-tracing guide walks through the mechanism.
- Check HIBP for your real address today and turn on its notifications. If it is already out there, the breach response guide is the order of operations.
An alias is not a second inbox you have to check. It is a forwarding rule: mail to the alias lands in your real inbox, and the site never learns the real address. Pause it, kill it, replace it, and the signup that caused the problem is the only one affected. And no, this is not a disposable-email trick. An alias is permanent and yours, which is exactly what makes the tracing work. The setup guide takes a couple of minutes, the docs explain the mechanics, and the free tier covers 10 aliases. That is enough for the basic split: banking, shopping, social, news.
Make one alias, use it for the next signup, and watch the To field for a week. Then the next site, and the next. Within a month of starting, most people barely hand out the real address at all.
Where this stops working
Three places where aliases do not help, stated plainly.
If malware is on your own machine, it takes the address straight from you. No alias survives that. In June 2026, HIBP absorbed 56.3 million email addresses stolen by infostealers from infected devices, not from websites (PCWorld). A problem on your own machine, not a signup problem.
Phishing sent to the correct alias passes the To-field test: if attackers breach the actual store and email you at that store's alias, the check says fine. Aliases shrink the attack surface; they do not remove it.
And phone calls. The Hana Bank fraud playbook is a caller who already knows your name, your workplace, and your address. No product fixes a phone call. Verify through a channel you opened yourself, never through the one that contacted you.
I do not know which of your signups will be the one that leaks. Neither do you, and neither does the site. That is the whole point: the risk is unknowable per signup, which is why containment beats trust.
You will never control the database. But you control what the database holds. Make it an address you can kill, and the worst a website can do with it has an expiry date.
Top comments (0)