Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 01, 2026 · 8 min read

EFF's Doxxing Guide: Your Email Address Is the Pivot Key

Daly Barnett published both halves of EFF's doxxing safety guide on 31 August 2026, prevention and footprint management in Part I, incident response in Part II. Read both. Then notice what neither half says out loud: almost every technique on either list pivots through one email address.

A doxxing campaign rarely begins with a hack. It begins with one string of text someone already has, usually because you gave it to a mailing list in 2014. From there a determined person walks outward: a people search record with an old address, a breach dump, a signup form that quietly confirms you hold an account, a forgotten profile under the same handle.

EFF's new guide is the most practical writing on this problem published this year. It is also organised by surface rather than by key. Here is what it says, then the join that makes those surfaces one thing.

Key Takeaways

  • EFF published both parts of its doxxing safety guide on 31 August 2026, defining doxxing as "the deliberate disclosure of personal information in order to bully, harass, intimidate, or instigate a chain of harms against someone."
  • Part I audits your footprint across breach databases, open records, data brokers and reverse image search; Part II covers incident logs, account hardening, carrier PINs against SIM swapping and PACE contingency planning.
  • Consumer Reports found that people search removal services took down only 117 of 332 exposed data instances, 35 percent, within four months.
  • A July 2026 study of 322 data brokers measured roughly 20 hours of effort to file opt out requests, and found 70 percent of deletion requests went unanswered.
  • One reused email address is the join key across all of those data sets, which is why separating addresses by trust tier buys more than any single opt out.
A closed laptop, a phone face down, a notebook and a stack of opened paper envelopes on a dark wooden desk, lit by striped light through window blinds

What Did EFF Actually Publish?

Two posts released the same day, splitting the problem into before and after. Part I, prevention and footprint management, names tools rather than gesturing at categories: haveibeenpwned and DeHashed for breach exposure, What's My Name and Namechk to find where an old username is still registered, PimEyes and Lenso for reverse image search, Open Measures for tracking how hateful material spreads.

Part II, incident response, assumes it already happened: keep an incident log, assign roles so nobody monitors alone, read forums organising against you through Tor, harden public accounts, add a PIN to bank and cellular accounts because SIM swapping is "an attack where they contact your cellular provider pretending to be you," and write PACE documents, primary, alternate, contingency, emergency.

Both halves end on the same unglamorous note. EFF calls this a marathon rather than a race and repeats that "privacy is a team sport." The workload is the real obstacle, and the numbers below say why.

Why Is Your Email Address the Pivot Key?

Because it is the one identifier present in every data set a doxxer touches, which is what lets separate records be joined into a single person. Phone numbers change. Usernames vary by platform. The email address is the field brokers key on, breach corpora are sorted by, and account systems treat as identity. That last clause is not theoretical: in September 2026 attackers took over 5,000 Dropbox accounts opened with nothing but an email address, because a federated login partner vouched for the address and Dropbox believed it.

Volume settles the breach side. Troy Hunt indexed 1,957,476,021 unique email addresses from the Synthient credential stuffing corpus into Have I Been Pwned in November 2025, out of one dataset. EFF points you at that database defensively. The same lookup works offensively.

The account side is quieter. Where a signup or password reset form answers differently for an address that exists, your address becomes a membership test anyone can run against any site. OWASP documents this in Testing for Account Enumeration and Guessable User Account, noting that even response timing gives it away, since sending a recovery mail "can add several hundred milliseconds to the response." A harasser with your address and an afternoon can map which forum, which dating site, which pharmacy you hold an account with, without ever logging in as you. Recovery screens finish the job: a masked partial phone number confirms a link a stranger only suspected.

What Does Opening a Message Give Away?

An IP address and a device fingerprint, handed to whoever sent it, the moment a remote image loads. This is one thread in a doxxing threat model rather than the centre of it, but it is real: once someone has your address, they do not need you to reply, only to look.

The mechanism is the ordinary marketing pixel, an image one pixel across whose request carries your IP address and user agent by default. Englehardt, Han and Narayanan's Princeton study I never signed up for this! examined more than 12,000 messages from roughly 900 senders and found 85 percent carried embedded third party content, 70 percent of it classed as trackers. It is commodity technique, which is why harassment bait is so often a message built to be opened: a fake unsubscribe confirmation, a fake account alert, something dressed as your employer. Blocking remote images and stripping tracking redirects closes that door, and our breakdown of whether DuckDuckGo Email Protection blocks trackers covers what a relay strips on the way through.

How Do You Split the Key Before You Need To?

Stop having one key. EFF's guide does not discuss aliases or relay addresses, so treat this as our addition rather than a summary of theirs: the highest leverage change available to you is that your public identity, your financial accounts and your throwaway signups stop sharing an address.

  • Three tiers, minimum. A public address for your byline. A private one for banking, government and your password manager, published nowhere. A disposable tier for everything else. The public address is the one that ends up in a breach dump, so make sure it unlocks nothing.
  • Use real aliases, not plus addressing. Anything after a plus sign strips back to your real address in one step. We compared two options in Brave email aliases versus Hide My Email, and flagged a caveat when Apple's Hide My Email addresses became identifiable. Rebuilding the private tier starts with our comparison of private email providers.
  • Audit what exists. Run every address through Have I Been Pwned, then run your handles through the username search engines EFF names. Close what you can, change the address on what you cannot.
  • Strip the recovery hints. Point account recovery at the private tier and delete stale phone numbers from live accounts. EFF flags the Google Advanced Protection Program for people at elevated risk.
  • File broker opt outs by hand. Yael Grauer's Big Ass Data Broker Opt-Out List, maintained on GitHub and cited by both EFF and the Freedom of the Press Foundation, is the free route.

Two numbers explain why EFF frames removal as a marathon. Consumer Reports and Tall Poppy tracked 332 exposed data instances belonging to 28 people and found only 117, or 35 percent, taken down within four months. A July 2026 study, Let My Data Go, filed requests with 322 brokers and clocked roughly 20 hours of form filling for opt outs plus 25 hours for deletions, with 70 percent of deletions never answered. That is a working week of unpaid labour for about a third of the exposure. Splitting your addresses takes an evening, and it shrinks the grind you inherit next year, because records collected after the split cannot be joined back to one person.

What Does EFF Say to Do First?

Document, then harden, then remove. Part II puts the incident log first because platform reports, employer conversations and any eventual police report all fail without times, screenshots and links captured before the posts vanish.

  1. Start the incident log: times, places, people, links, screenshots.
  2. Hand monitoring to someone else. Reading your own harassment for hours is what breaks people.
  3. Set Google Alerts on your name, or Open Measures if the campaign spans platforms.
  4. Turn on two factor authentication, flip public accounts private, delete the ones being used against you.
  5. Call your bank and mobile carrier and add a PIN or port freeze. This is the step that stops a doxxing becoming an account takeover.
  6. Move account recovery off any address that appeared in the dox.
  7. Restart broker and public records removals, this time with the published addresses.

One ordering conflict is worth planning for. Changing your email address is the right long term move and the wrong first move, because reset mail, alias migrations and "was this you?" alerts all arrive while you are least able to tell a real notification from bait. Log first. Migrate on day three.

What This Means for Your Inbox

Most inbox privacy advice is written against a commercial adversary. A marketing platform wants to know whether you opened the newsletter so it can tune a send time, and losing that fight costs you a better targeted ad. The adversary EFF describes wants your city, your employer and your street, and reaches for the same commodity tooling because it is cheap and it works. Our reporting on ad tech location data and the risk to journalists traced that pattern through a different pipe.

So read the ordinary features of email differently. A read receipt is a location ping when the sender is hostile. A password reset form is a membership oracle. A breach dump is a join table, and sometimes a charge sheet: when hackers took the donor lists of two Russian charities supporting Ukrainians and political prisoners, no card numbers leaked and the email addresses alone were the damaging part. None of these were built as doxxing infrastructure and all of them serve as it, which is why the fix is structural rather than tactical: reduce what a single address unlocks, and the value of every one of those techniques falls at once.

If you write, organise, moderate or work anywhere near a public dispute, do the boring version this week. Separate your addresses into tiers, stop remote images loading automatically, add a carrier PIN. Then read both EFF posts properly, because the parts skipped here, the reverse image searching, the open records work, the PACE planning, are the ones that matter once a campaign is already running.

Sources: EFF: Doxxing Safety Pt. I and Part II, Daly Barnett, 31 August 2026; OWASP WSTG on account enumeration; Troy Hunt on the Synthient corpus, 5 November 2025; Let My Data Go, arXiv, July 2026; The Record on the Consumer Reports study and the Consumer Reports report page; Princeton CITP: I never signed up for this!. EFF's guide does not cover email aliases or relays; that section is ours and is labelled as such.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.