Privacy guide · 8 min read

How to Find Out Which Companies Have Your Email Address

A workable order for one evening: the password manager, mailbox footers, breach indexes, the sign-in lists nobody checks, and the part nobody can list.

YeyMail Team ·

Nobody keeps a register of the companies holding your email address, and the party least likely to have one is you. The address has gone into checkout forms, into a discount code, into a conference sign-up sheet, into a password reset on a site you last opened in 2017. Some of those companies still trade. Some sold the customer list on the way out.

A complete answer does not exist, and any method promising one is selling something. What does exist is a good enough list, buildable in an evening, separating the accounts you use from the accounts you forgot and the accounts that should not still hold your details. The order below matters: each step is cheaper than the one after it and takes work off it.

Open a plain text file or a spreadsheet before you start. The output of the evening is that file, and every step adds rows to it.

Start with the password manager

For most people this is already the most complete inventory they own, and they have never looked at it as one. A password manager holds a row for every site that once prompted you to save a login, including sites you would not have recalled under interrogation. Reading it takes minutes rather than hours.

Bitwarden documents its export under Tools then Export, offering plaintext .json and .csv alongside encrypted JSON, and it warns not to store or send an unencrypted export over insecure channels such as email, and to delete the file immediately after use. Take that seriously, because while it exists a plaintext vault export is the most dangerous file on your machine. If you would rather not export at all, sorting the vault by site name and reading it on screen does the same job; you need the domains, not the passwords. Anyone who never installed a manager but let Chrome or Android save logins has one anyway, at passwords.google.com.

Copy the domain of every entry into your file and ignore the credentials entirely. You are building a list of companies, not auditing your security.

The gap here is specific and worth naming early. A password manager only records places where you created a password. It has nothing on newsletters, receipts, guest checkouts, or any site where you pressed a social sign-in button instead. Two later steps exist to cover exactly that.

Search your own mailbox by the footer, not the subject line

The instinct is to hunt for welcome emails, which works and is worth doing. In Gmail, in:anywhere widens a search to include Spam and Trash, and the productive phrases are the ones marketing teams have used unchanged for fifteen years: "welcome to", "verify your email", "confirm your email address", "your receipt", "thanks for signing up". Quotation marks match an exact phrase, and a plus sign in front of a word matches that word exactly, as in +unicorn.

The better search is the footer. Google's own bulk sender guidelines require senders of more than 5,000 messages a day to Gmail to support one-click unsubscribe and to include a clearly visible unsubscribe link in the message body. That requirement binds only senders above that threshold, so the word is a wide net rather than a complete one, but it appears in far more messages than any subject-line phrase. A query such as in:anywhere unsubscribe older_than:1y surfaces most of the senders a welcome-email search missed. Gmail also documents list:, which matches mail from a mailing list, and older_than: and newer_than:, which take d, m or y.

Outlook uses different keywords for the same work. Microsoft documents from:, subject:"exact phrase", hasattachment:yes and received:"last week", along with AND, OR and NOT typed in capitals, and its guidance covers Outlook.com, new Outlook for Windows and the desktop versions back to 2016. Microsoft also states that a plain word search scans the sender name, subject, message body or attachments, which is what makes a bare search for unsubscribe work there as well.

Work by sender domain rather than by message. You are not reading your email; you are collecting company names, and one sender earns one row however many messages it sent.

Breach indexes find the accounts you forgot existed

Have I Been Pwned answers a different question from your mailbox: not who wrote to you, but who lost your address. It routinely names companies you have no memory of, because the signup was a decade old or the brand was absorbed by whoever actually leaked. Its FAQ states that searches are not logged, so there is no collection of the addresses people look up, and that breaches marked sensitive cannot be searched publicly at all; those appear only after you verify ownership of the address by signing in to the dashboard. If you have not run this before, our guide on what to do with your Have I Been Pwned results covers reading the list without panicking about an entry from 2013.

The sign-in buttons that left nothing in your mailbox

This is the step most audits skip, and it reaches a category of account that no mailbox search or password manager can see. Sign up with a social button and the site often sends no welcome email, stores no password in your manager, and leaves nothing to search for. Both providers publish the list anyway.

Google gathers them at myaccount.google.com/linkedapps, grouped into Sign in with Google, linked accounts, and apps with access to your Google Account. Pick a connection type, pick the app, then choose See details to review or remove it. Apple keeps the equivalent list in your account settings: on iPhone or iPad, Settings then your name then Sign in with Apple; on a Mac, System Settings then your name then Sign in with Apple; on the web, sign in at account.apple.com, go to Sign-In & Security and select Sign in with Apple. Selecting an app shows the information you originally shared with it, and deleting the entry stops using Sign in with Apple for that app or developer.

Two cautions. Revoking a connection does not delete the account at the far end, and it sometimes removes the only way you had of signing in, so write the name into your file before you touch anything. Where you chose to hide your address during an Apple signup, the developer holds a forwarding address rather than your real one, which is a materially better position and worth marking as such.

SourceWhat it findsWhat it misses
Password managerEvery site you saved a login forNewsletters, guest checkouts, social signups
Mailbox searchAnyone who has emailed youCompanies that never wrote, and deleted mail
Breach indexesCompanies that lost your dataBreaches undisclosed or unpublished
Google and Apple sign-in listsAccounts with no email trailSites where you set a password instead
Data broker registriesNames of registered brokersWhether any given one holds you

Data brokers are the category you cannot enumerate

Everything above finds companies you dealt with. Data brokers are the ones you did not: they bought, scraped or inferred your address, so there is no welcome email, no login, and no way to list them from your own records. Honesty is the only useful position here.

The nearest thing to a list is a public register. California requires any business meeting its definition of a data broker to register with the state annually between 1 and 31 January, and the regulator publishes those submissions as a searchable registry. It also runs DROP, the Delete Request and Opt-out Platform: California residents have been able to file a single deletion request against all active registered brokers since 1 January 2026, and brokers were required to begin processing those requests from 1 August 2026. Living elsewhere, the registry is still worth reading as a list of names, though you will be filing with each broker individually. We are not lawyers and none of this is legal advice.

Triage the list into keep, delete and dormant

Sort your file into three columns. The sorting is the point of the evening; the list on its own changes nothing.

  • Keep: you use the account, you want the mail, and you would choose this company again today.
  • Delete: you do not use it, or you would not sign up now. This column is the input to a deletion request, and our guide on how to request data deletion covers who to write to, what to ask for, and what to do when the reply is silence.
  • Dormant: you cannot delete it without losing something, the company has vanished, or you genuinely cannot tell. Unsubscribe, remove any stored card, and strip whatever else the account lets you strip.

One distinction deserves pedantry. Unsubscribing stops the mail arriving; it does not remove your address from the company's database, and it does not stop that address travelling with the customer list if the business is sold. Only the delete column changes what a company actually holds.

The ceiling on any audit like this

The method finds what you can find, which is not everything. It cannot show you a company that bought your address from someone else, a subsidiary processing on a brand's behalf, a breach nobody disclosed, or a signup whose only trace was a welcome email you deleted in 2019. Tracing one piece of unwanted mail back to its source is a separate exercise with its own limits, covered in who leaked my email address, and it works cleanly only when the address was unique to a single company. Treat your file as a floor rather than a census, and revisit it when something new arrives.

Making the next audit trivial rather than archaeological

The reason tonight is archaeology is that one address went everywhere, so the record of who holds it lives in other people's systems instead of yours. The structural fix only helps going forward: give each company its own address at the moment you sign up. The inventory then maintains itself, because the address is the record. Every message names the company that handed it over, a company you no longer deal with can be cut off at the address rather than negotiated with, and the next audit is reading a sorted list. Email masking explained covers the mechanics, and pairing the practice with a password manager is what makes it survive contact with real life.

None of that helps with the sprawl you already have. That still takes one evening, one file, and three columns.

The YeyMail takeaway
Where YeyMail fits

YeyMail is for the next list rather than this one. You create a separate forwarding address for each company, so the inventory writes itself: the address on the envelope names whoever passed it on, and the kill switch refuses mail at SMTP time, meaning the sender gets a rejection instead of a message quietly accepted and dropped. There is a free 7-day trial with no card, then Starter at $0.99 a month or $9.48 a year. Addresses on domains you own are unlimited; on the shared yeymail.com domain Starter allows 500 in total, counting every address ever created there including deleted ones. We hold no third-party audit and make no certification claims.

Start free — one alias per signup7-day trial · No credit card

Sources

Common questions

How long does this audit actually take?

An evening for most people, if you keep to the order. The password manager pass is minutes, the mailbox searches are the longest part because you are skimming senders rather than reading messages, and the Google and Apple sign-in lists take a few minutes each. Triage is the slow half, since it involves decisions rather than searching.

Is unsubscribing the same as being deleted?

No. Unsubscribing stops the marketing mail arriving, but the company keeps your address in its database, and that database travels with the business if it is sold or breached. Only an explicit deletion request changes what the company holds, which is why the audit sorts addresses into a delete column rather than an unsubscribe column.

Why check the Google and Apple sign-in lists separately?

Because signing up with a social button frequently produces no welcome email and saves no password, so the account is invisible to both a mailbox search and a password manager. Google lists these connections at myaccount.google.com/linkedapps, and Apple shows them under Sign in with Apple in your account settings on iPhone, Mac or account.apple.com.

Can I find out which data brokers hold my address?

Not reliably. Brokers acquire addresses without contacting you, so nothing in your own records points to them. California publishes a registry of businesses that have registered as data brokers, and its DROP platform lets California residents file one deletion request to all active registered brokers, with brokers required to process those requests from 1 August 2026. Elsewhere you are contacting brokers one at a time.

What should I do when the same address turns up in a breach index?

Change the password for that account first, and change it anywhere you reused it. Then decide whether the account belongs in your keep column at all, because a company that lost your data once still holds it. If the account is genuinely finished with, it belongs in the delete column and gets a deletion request rather than a password change.

Does using a separate address per company fix this retroactively?

No, and that is the honest limit. Per-site addresses make future inventories trivial because the address itself records who received it, but they do nothing about the companies already holding the address you have used for years. That sprawl needs the audit once, after which the new addresses keep the list from re-forming.

Keep reading

Privacy guide
How to Make a Company Delete Your Data
Breach response
Have I Been Pwned: How It Works and What Results Mean
Guide
Email Masking Explained: Masks and Aliases