Nobody keeps a register of the companies holding your email address, and the party least likely to have one is you. The address has gone into checkout forms, into a discount code, into a conference sign-up sheet, into a password reset on a site you last opened in 2017. Some of those companies still trade. Some sold the customer list on the way out.
A complete answer does not exist, and any method promising one is selling something. What does exist is a good enough list, buildable in an evening, separating the accounts you use from the accounts you forgot and the accounts that should not still hold your details. The order below matters: each step is cheaper than the one after it and takes work off it.
Open a plain text file or a spreadsheet before you start. The output of the evening is that file, and every step adds rows to it.
Start with the password manager
For most people this is already the most complete inventory they own, and they have never looked at it as one. A password manager holds a row for every site that once prompted you to save a login, including sites you would not have recalled under interrogation. Reading it takes minutes rather than hours.
Bitwarden documents its export under Tools then Export, offering plaintext .json and .csv alongside encrypted JSON, and it warns not to store or send an unencrypted export over insecure channels such as email, and to delete the file immediately after use. Take that seriously, because while it exists a plaintext vault export is the most dangerous file on your machine. If you would rather not export at all, sorting the vault by site name and reading it on screen does the same job; you need the domains, not the passwords. Anyone who never installed a manager but let Chrome or Android save logins has one anyway, at passwords.google.com.
Copy the domain of every entry into your file and ignore the credentials entirely. You are building a list of companies, not auditing your security.
The gap here is specific and worth naming early. A password manager only records places where you created a password. It has nothing on newsletters, receipts, guest checkouts, or any site where you pressed a social sign-in button instead. Two later steps exist to cover exactly that.
Search your own mailbox by the footer, not the subject line
The instinct is to hunt for welcome emails, which works and is worth doing. In Gmail, in:anywhere widens a search to include Spam and Trash, and the productive phrases are the ones marketing teams have used unchanged for fifteen years: "welcome to", "verify your email", "confirm your email address", "your receipt", "thanks for signing up". Quotation marks match an exact phrase, and a plus sign in front of a word matches that word exactly, as in +unicorn.
The better search is the footer. Google's own bulk sender guidelines require senders of more than 5,000 messages a day to Gmail to support one-click unsubscribe and to include a clearly visible unsubscribe link in the message body. That requirement binds only senders above that threshold, so the word is a wide net rather than a complete one, but it appears in far more messages than any subject-line phrase. A query such as in:anywhere unsubscribe older_than:1y surfaces most of the senders a welcome-email search missed. Gmail also documents list:, which matches mail from a mailing list, and older_than: and newer_than:, which take d, m or y.
Outlook uses different keywords for the same work. Microsoft documents from:, subject:"exact phrase", hasattachment:yes and received:"last week", along with AND, OR and NOT typed in capitals, and its guidance covers Outlook.com, new Outlook for Windows and the desktop versions back to 2016. Microsoft also states that a plain word search scans the sender name, subject, message body or attachments, which is what makes a bare search for unsubscribe work there as well.
Work by sender domain rather than by message. You are not reading your email; you are collecting company names, and one sender earns one row however many messages it sent.
Breach indexes find the accounts you forgot existed
Have I Been Pwned answers a different question from your mailbox: not who wrote to you, but who lost your address. It routinely names companies you have no memory of, because the signup was a decade old or the brand was absorbed by whoever actually leaked. Its FAQ states that searches are not logged, so there is no collection of the addresses people look up, and that breaches marked sensitive cannot be searched publicly at all; those appear only after you verify ownership of the address by signing in to the dashboard. If you have not run this before, our guide on what to do with your Have I Been Pwned results covers reading the list without panicking about an entry from 2013.
The sign-in buttons that left nothing in your mailbox
This is the step most audits skip, and it reaches a category of account that no mailbox search or password manager can see. Sign up with a social button and the site often sends no welcome email, stores no password in your manager, and leaves nothing to search for. Both providers publish the list anyway.
Google gathers them at myaccount.google.com/linkedapps, grouped into Sign in with Google, linked accounts, and apps with access to your Google Account. Pick a connection type, pick the app, then choose See details to review or remove it. Apple keeps the equivalent list in your account settings: on iPhone or iPad, Settings then your name then Sign in with Apple; on a Mac, System Settings then your name then Sign in with Apple; on the web, sign in at account.apple.com, go to Sign-In & Security and select Sign in with Apple. Selecting an app shows the information you originally shared with it, and deleting the entry stops using Sign in with Apple for that app or developer.
Two cautions. Revoking a connection does not delete the account at the far end, and it sometimes removes the only way you had of signing in, so write the name into your file before you touch anything. Where you chose to hide your address during an Apple signup, the developer holds a forwarding address rather than your real one, which is a materially better position and worth marking as such.
| Source | What it finds | What it misses |
|---|---|---|
| Password manager | Every site you saved a login for | Newsletters, guest checkouts, social signups |
| Mailbox search | Anyone who has emailed you | Companies that never wrote, and deleted mail |
| Breach indexes | Companies that lost your data | Breaches undisclosed or unpublished |
| Google and Apple sign-in lists | Accounts with no email trail | Sites where you set a password instead |
| Data broker registries | Names of registered brokers | Whether any given one holds you |
Data brokers are the category you cannot enumerate
Everything above finds companies you dealt with. Data brokers are the ones you did not: they bought, scraped or inferred your address, so there is no welcome email, no login, and no way to list them from your own records. Honesty is the only useful position here.
The nearest thing to a list is a public register. California requires any business meeting its definition of a data broker to register with the state annually between 1 and 31 January, and the regulator publishes those submissions as a searchable registry. It also runs DROP, the Delete Request and Opt-out Platform: California residents have been able to file a single deletion request against all active registered brokers since 1 January 2026, and brokers were required to begin processing those requests from 1 August 2026. Living elsewhere, the registry is still worth reading as a list of names, though you will be filing with each broker individually. We are not lawyers and none of this is legal advice.
Triage the list into keep, delete and dormant
Sort your file into three columns. The sorting is the point of the evening; the list on its own changes nothing.
- Keep: you use the account, you want the mail, and you would choose this company again today.
- Delete: you do not use it, or you would not sign up now. This column is the input to a deletion request, and our guide on how to request data deletion covers who to write to, what to ask for, and what to do when the reply is silence.
- Dormant: you cannot delete it without losing something, the company has vanished, or you genuinely cannot tell. Unsubscribe, remove any stored card, and strip whatever else the account lets you strip.
One distinction deserves pedantry. Unsubscribing stops the mail arriving; it does not remove your address from the company's database, and it does not stop that address travelling with the customer list if the business is sold. Only the delete column changes what a company actually holds.
The ceiling on any audit like this
The method finds what you can find, which is not everything. It cannot show you a company that bought your address from someone else, a subsidiary processing on a brand's behalf, a breach nobody disclosed, or a signup whose only trace was a welcome email you deleted in 2019. Tracing one piece of unwanted mail back to its source is a separate exercise with its own limits, covered in who leaked my email address, and it works cleanly only when the address was unique to a single company. Treat your file as a floor rather than a census, and revisit it when something new arrives.
Making the next audit trivial rather than archaeological
The reason tonight is archaeology is that one address went everywhere, so the record of who holds it lives in other people's systems instead of yours. The structural fix only helps going forward: give each company its own address at the moment you sign up. The inventory then maintains itself, because the address is the record. Every message names the company that handed it over, a company you no longer deal with can be cut off at the address rather than negotiated with, and the next audit is reading a sorted list. Email masking explained covers the mechanics, and pairing the practice with a password manager is what makes it survive contact with real life.
None of that helps with the sprawl you already have. That still takes one evening, one file, and three columns.