Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 18, 2026 · 7 min read

DecryptAds: A Free Tool That Maps Who Tracks You

The advertising industry publishes its own membership roster in plain text on millions of websites, and almost nobody reads it. A new free service from threat researcher Zach Edwards does, and it turns those files into a named list of the companies sitting behind any site or app you use.

Every time you load a news article, the page you see is the front of a transaction involving dozens of companies you have never heard of. You cannot see them. But the publisher, by industry rule, has to write their names down in a file anyone can fetch with a browser. That file has been sitting there since 2017.

Key Takeaways

  • DecryptAds, launched publicly in August 2026 and covered by Brian Krebs on 14 August, parses the public ads.txt, app-ads.txt, sellers.json and buyers.json files that websites and apps are required to publish.
  • Zach Edwards, a threat researcher at Infoblox, is a cofounder and Chief Research Officer of the service, which is free to use with some advanced functions gated behind enterprise accounts.
  • Running ESPN.com through the tool surfaced 143 declared ad partners and 19 registered data broker domains, with close to half of those brokers collecting geolocation data and three disclosing device fingerprint collection.
  • DecryptAds flags partners registered in what it calls geo-risk jurisdictions including China, Russia, the UAE, Cyprus and Panama, and tracks quiet removals of sellers from exchange files.
  • The files map only authorized sellers on the open exchange, so they say nothing about first party analytics, mobile SDKs that never touch a bid request, or email tracking pixels.

What Is DecryptAds?

DecryptAds is a free web service at decryptads.com that crawls the advertising transparency files published by websites and mobile apps, cross references them, and renders the result as a readable map of who is authorized to sell and buy access to you on a given property.

Its published feature list includes an auto investigate mode that returns a supply and risk brief for a single hostname, a supply chain map graphing a publisher's declared partners, a legal dossier matching adtech entities against corporate registry records, and an app store catalog covering mobile and connected TV apps. Researchers get an API.

Edwards told Krebs that the interesting failures are relational, not local: "Supply-chain integrity issues rarely live in a single file. They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files." That is the design thesis. One file is a list. Four files cross referenced against a corporate registry is an investigation.

What Are ads.txt and sellers.json?

They are plain text and JSON files that publishers and ad exchanges host at fixed, predictable paths so that buyers can verify who is legitimately allowed to sell a given site's inventory. The IAB Tech Lab published the ads.txt specification in 2017, app-ads.txt followed for mobile and CTV apps in 2019, and sellers.json arrived to let buyers resolve the identity of every intermediary in a chain.

Fetch example.com/ads.txt and you get lines shaped like this, one per authorized seller:

google.com, pub-0000000000000000, DIRECT, f08c47fec0942fa0
openx.com, 540000000, RESELLER, 6a698e2ec38604c6

Four fields: the exchange domain, the publisher's account ID there, whether the relationship is DIRECT or RESELLER, and the exchange's certification authority ID. A ten line shell script can parse it.

Here is the part worth sitting with. None of this was built for you. The IAB created ads.txt to kill domain spoofing, where a fraudster sells worthless traffic while claiming to be a premium publisher. Privacy was never the goal. The transparency is a byproduct of an anti fraud control, and it is the single largest voluntary disclosure of tracking relationships that exists, produced entirely by accident.

What Do You Actually See When You Run a Site?

You see a count, and the count is the thing that lands. Krebs reported that ESPN.com's declarations resolved to 143 ad partners and 19 registered data broker domains. Roughly half of those brokers collect geolocation. Three disclose that they gather device fingerprints and sensitive personal information.

Reframe that number. A reader visiting ESPN believes they have entered one commercial relationship, with ESPN. The declarations describe 143, and these are only the contractually authorized ones a publisher will sign its name to in a file regulators can read.

The service also runs a quiet removals feed, watching for sellers that vanish from an exchange's sellers.json without announcement. Edwards described how enforcement actually works in this market: "The ban is just removing them from the sellers.json file, but they told nobody." Diffing those files over time turns a silent enforcement action into a public, timestamped event. This is the same category of visibility that mattered when an Adform ad script was hijacked to steal cryptocurrency, where the compromise reached users through a partner nobody had enumerated.

A person at a wooden desk marking entries with a pen on a long printed list of company names, an open laptop beside them in soft daylight

Why Does a Partner's Country Matter?

Because a bid request is not a notification that an ad slot exists. It is a packet of data about you, broadcast to every authorized participant in the auction, and the ones that lose the auction keep the data anyway.

A typical request carries a device identifier, an IP address resolving to a neighborhood, device model, the page being loaded, location where permissions allow, and whatever audience segments a data partner has attached to that identifier. Every authorized partner receives it. Winning is optional. Receiving is not.

DecryptAds flags partners registered in China, Russia, the UAE, Cyprus and Panama, the last of which it treats as an ownership secrecy haven rather than a surveillance jurisdiction. The distinction matters: some flags mean a government with legal reach into the data, others mean you cannot determine who owns the entity receiving your location. Edwards also flagged firms operating on both sides of the auction: "It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties." The same plumbing shows up in mobile, where InMobi and three other ad SDKs were found leaking Android location data by default.

What Can't This Tool See?

A great deal, and being straight about that is what makes the tool worth using rather than overselling. The transparency files enumerate authorized sellers of ad inventory. That is one layer of one system.

Absent from any ads.txt file:

  • First party analytics and session recording scripts the publisher runs itself.
  • Mobile and CTV SDKs that phone home directly and never enter an open exchange auction.
  • Server to server data sharing agreements, which leave no client side trace at all.
  • CRM and identity resolution vendors that match a hashed email to a profile after you log in.
  • Email tracking pixels, which run on entirely separate infrastructure.

Krebs notes a further structural gap. The SupplyChain object data that would let the industry trace malvertising end to end stays server side, shared between platforms rather than published. So even the mapped layer is mapped incompletely. Treat a DecryptAds report as a floor on how many companies are involved, never a ceiling.

The Email Angle Is the Inverse of This

The web advertising supply chain is unusual precisely because it publishes a roster, and it does that to stop fraudsters from stealing revenue. No equivalent pressure exists in email, so no equivalent file exists either.

No sender declares which analytics vendor handles its open tracking. No marketing platform publishes the list of partners that receive read events. When a message loads a one pixel image from a tracking domain, that request records the open, an approximate location from your IP, and the client you read it in, and nothing in the exchange transparency regime describes it, because a bid request was never involved. The only way to enumerate it is to inspect the message source yourself.

That is the honest contrast, and it cuts against the intuition most people have. The advertising ecosystem, the one with the worst reputation, is the one you can audit from a text file. The inbox, which feels private, publishes nothing.

What to Do With the Output

Start with the properties where you spend real time: your daily news sites, the apps you open without thinking, any app your kids use. Read the partner list rather than the score. The value is not a verdict, it is the specific names, because a name is something you can search, look up in a registry, and block.

Then pair it with something that intervenes. Mapping is diagnosis, a content blocker is treatment. Our rundown of the best anti tracking browser extensions covers what to install once you know what you are up against.

The larger point outlasts the tool. For nine years the adtech industry has been publishing a machine readable confession on millions of domains, and the barrier to reading it was never access or law or a court order. It was that nobody had built the parser. Somebody finally did, and the answer to who is watching you turns out to have been a plain text file the whole time.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.