Data brokers are companies that collect, combine, and sell personal information people never agreed to share. There are an estimated 4,000+ of them in the US alone, and together they hold detailed profiles on nearly every person with an internet-connected device — address history, estimated income, health-related inferences, political leanings.
I spent time mapping the actual domain infrastructure behind this industry (aggregators, people-search sites, and DMPs — data management platforms that track browsing behavior in real time and sell "audience segments") and turned it into a DNS blocklist. Sharing both the reasoning and the list here.
How this actually works
Three overlapping categories:
Aggregators Pull data from public records (property, voter, court), retailer loyalty programs, and web scraping, then sell combined profiles.
People-search sites Turn that data into a searchable, usually subscription-based product — this is the branch most directly tied to stalking and harassment risk.
DMPs Sit on websites via tracking pixels, monitor your browsing behavior in real time, and sell "in-market" or "likely condition" segments to advertisers within milliseconds of a page load.
Most of this is legal in the US, since there's no comprehensive federal privacy law covering it — it operates in the gap between what GDPR restricts in the EU and what exists (or doesn't) elsewhere.
Real incidents worth knowing about
Exactis (2018) Left a database of 340 million people and businesses publicly accessible with no password (400+ attributes per person). No fine was ever issued — their position was that without SSNs or card numbers, it wasn't "sensitive."
https://www.infosecurity-magazine.com/news/340-million-records-exposed-in/
https://haveibeenpwned.com/Breach/Exactis Epsilon (2011) Breached, exposing 60M+ email addresses tied to specific brands (Chase, Target, Best Buy, etc.), enabling highly targeted phishing.
https://krebsonsecurity.com/2015/03/feds-indict-three-in-2011-epsilon-hack/
https://abcnews.go.com/Technology/epsilon-email-breach/story?id=13291589
Deep Root Analytics (2017) An RNC contractor left 198 million voter records — including modeled political scores — open on an unsecured AWS bucket.
https://www.upguard.com/breaches/the-rnc-files
https://www.cbsnews.com/news/nearly-200-million-americans-hit-by-massive-voter-data-leak/
Cambridge Analytica (2018)
Combined Facebook data with voter files bought from data brokers to build psychographic profiles used in the 2016 US election and Brexit campaigns.
Premera Blue Cross (2015)
Breached, exposing medical and financial records for 11M people. The company ultimately paid roughly $91M combined across a class-action settlement, a multistate settlement, and a federal HIPAA penalty.
https://oag.ca.gov/node/148821
ChoicePoint (2005)
Sold data to identity thieves posing as legitimate businesses. 163,000 people's SSNs and credit reports were exposed, leading to 800+ confirmed identity theft cases. Paid $15M to the FTC — the largest civil penalty the agency had imposed at the time.
https://www.nbcnews.com/id/wbna11030692
Target's pregnancy-prediction program (2012)
The most-cited example of inference-based profiling.
Target built a model that scored shoppers' likelihood of pregnancy purely from purchase patterns. The famous anecdote behind it (a father learning of his teenage daughter's pregnancy from Target's coupons) has been disputed by some analysts, but the fact that Target built and used such a system is not in question.
https://www.kdnuggets.com/2014/05/target-predict-teen-pregnancy-inside-story.html
A quick note on "alleged": FTC settlements are typically resolved without the company admitting wrongdoing — that's standard procedure, not a sign the case was weak. What is real and enforceable is the outcome: the resulting order legally prohibits the company from continuing the practice, whether or not they agreed with the allegations.
Location data brokers (recent FTC enforcement)
InMarket (2024) FTC alleged InMarket collected precise location data via its own apps and third-party SDKs, using it for targeted advertising without adequately informing users. Under the settlement, InMarket is now banned from selling or licensing precise location data — a first for the FTC.
https://www.washingtonpost.com/technology/2024/01/18/ftc-location-data-privacy/
X-Mode Social / Outlogic (2024)
The FTC's first settlement specifically over the sale of sensitive location data. The company sold location data revealing visits to medical/reproductive health clinics, religious worship sites, domestic violence shelters, and LGBTQ+-associated locations, without stripping out these sensitive locations.
Gravy Analytics + Venntel (2024–2025)
FTC alleged the companies sold location data revealing medical conditions, religious worship, and political activity — including sales to government contractors. Separately, in January 2025, Gravy Analytics was hacked and its data leaked on a cybercrime forum.
https://en.wikipedia.org/wiki/Gravy\_Analytics
Mobilewalla (2024–2025)
Settled alongside Gravy Analytics. FTC alleged the company collected consumer location data from real-time bidding ad exchanges even when it didn't win the ad auction — the first FTC case targeting this specific collection method.
https://epic.org/ftc-takes-action-against-data-brokers-for-selling-sensitive-location-data/
Why block this at the DNS level Browser extensions catch some of this, but a lot of DMP tracking happens through first-party-looking pixel calls or server-side syncing that extensions don't always see. Blocking at the DNS level stops the connection before it's made, across every app and browser on the network — not just one browser tab.
Raw links:
For basic list
For aggressive list
Here's the list of domains worth blocking:
“`
DMP & Data Broker Blocklist
Total domains: 244
Note: domains marked with "!" carry a small risk of side effects (e.g. breaking a login flow or feature) – block these only if you're comfortable troubleshooting
🔴 DATA BROKERS & DMP
ACXIOM
acxiom.com acxiom.net acxiom.uk acxiom.co.uk acxiom.de acxiom.fr acxiom.asia acxiom.com.au acxiom.jp acxiom-online.com acxiomdigital.com recognicorp.com cdn.acxiom.com data.acxiom.com abilitec.acxiom.com identitylink.acxiom.com t.acxiom-online.com
EXPERIAN
experianmarketingservices.com ! audienceiq.com hitwise.com eccmp.com ! ats.eccmp.com
ORACLE DATA CLOUD (BlueKai DMP)
bkrtx.com tags.bluekai.com ! tags.bkrtx.com oracleinfinity.io data.oracleinfinity.io datalogix.com api.datalogix.com pixel.datalogix.com
LOTAME
lotame.com ! lotame.io crwdcntrl.net tags.crwdcntrl.net bcp.crwdcntrl.net sync.crwdcntrl.net pixel.crwdcntrl.net ad.crwdcntrl.net id.crwdcntrl.net td.crwdcntrl.net td2.crwdcntrl.net meez.crwdcntrl.net multiply.crwdcntrl.net ltmsphrcl.net c.ltmsphrcl.net bcp.st.crwdcntrl.net c.st.ltmsphrcl.net ts.crwdcntrl.net
EYEOTA
eyeota.net eyeota.com ! ps.eyeota.net api.eyeota.net match.eyeota.net sync.eyeota.net
TRANSUNION (TruAudience + Neustar)
truoptik.com signal.truoptik.com
WILAND
wiland.com api.wiland.com
MERKLE (Dentsu Aegis)
merkle.com merkleinc.com api.merkle.com merkleresponse.com merkury.dentsu.com dentsu.com dentsu.co.jp m1.merkle.com 4cite.com
BOMBORA (B2B intent data)
bombora.com api.bombora.com surge.bombora.com tag.bombora.com netfactor.com !
ZOOMINFO
zoominfo.com zoom.info discoverorg.com api.zoominfo.com websights.zoominfo.com ws.zoominfo.com tag.zoominfo.com formcomplete.zoominfo.com clickagy.com
CLEARBIT (HubSpot Breeze Intelligence)
risk.clearbit.com !
FULLCONTACT (Ziff Davis)
fullcontact.com api.fullcontact.com resolve.fullcontact.com img.fullcontact.com tag.fullcontact.com cr.fullcontact.com streme.fullcontact.com
TOWERDATA / ATDATA
towerdata.com ! rapleaf.com ! atdata.com !
INFUTOR
infutor.com !
STIRISTA
stirista.com api.stirista.com
TAPAD (Cross-device — Experian)
tapad.com api.tapad.com tapestry.tapad.com
ANALYTICS IQ
analytics-iq.com api.analytics-iq.com
PERMUTIVE (DMP)
permutive.com ! permutive.app api.permutive.app cdn.permutive.app amp.permutive.app edge.permutive.app
NIELSEN MARKETING CLOUD / EXELATE
exelate.com exelate.info mrpdata.net
DATA AXLE (Infogroup)
data-axle.com adstradata.com
NAVEGG (LATAM DMP)
navegg.com navegg.com.br www2.navegg.com navdmp.com tag.navdmp.com cdn.navdmp.com sync.navdmp.com sync2.navdmp.com usr.navdmp.com cus.navdmp.com cus2.navdmp.com view.navdmp.com opi.navdmp.com amp.navdmp.com j.navdmp.com mx.navdmp.com www.navdmp.com cd.navdmp.com mcd.navdmp.com acd.navdmp.com mcdn.navdmp.com acdn.navdmp.com iscd.navdmp.com iscdn.navdmp.com isapp.navdmp.com asapp.navdmp.com musr.navdmp.com vht.navdmp.com
THROTLE (Identity resolution)
throtle.io
🟠 MOBILE DATA BROKERS (Location Tracking)
FACTUAL / FOURSQUARE
factual.com !
SAFEGRAPH
safegraph.com ! safegraph.io !
CUEBIQ
cuebiq.com api.cuebiq.com sdk.cuebiq.com events.cuebiq.com
MOBILEWALLA (FTC December 2024 restricted)
mobilewalla.com api.mobilewalla.com sdk.mobilewalla.com
ADSQUARE
adsquare.com api.adsquare.com exchange.adsquare.com rtb.adsquare.com match.adsquare.com
UBIMO → VERICAST
ubimo.com !
VERVE GROUP
verve.com ! vervemobile.com vrvm.com api.verve.com adcel.vrvm.com ad.vrvm.com analytics-api.vervemobile.com smaato.com smaato.net pubnative.net dataseat.com ! captify.co captify.co.uk jungroup.com
UNACAST + GRAVY ANALYTICS (FTC January 2025 restricted)
unacast.com api.unacast.com gravyanalytics.com api.gravyanalytics.com venntel.com
OUTLOGIC (Legacy X-Mode — FTC April 2024 restricted)
outlogic.io
INMARKET (FTC January 2024 restricted)
inmarket.com sdk.inmarket.com “`
Source: r/dns · by /u/Corleone612