Skip to content
DnsLister Forum

Where domain hunters compare notes

Data Brokers & DMPs: Why They’re Worth Blocking

Data brokers are companies that collect, combine, and sell personal information people never agreed to share. There are an estimated 4,000+ of them in the US alone, and together they hold detailed profiles on nearly every person with an internet-connected device — address history, estimated income, health-related inferences, political leanings.

I spent time mapping the actual domain infrastructure behind this industry (aggregators, people-search sites, and DMPs — data management platforms that track browsing behavior in real time and sell "audience segments") and turned it into a DNS blocklist. Sharing both the reasoning and the list here.

How this actually works

Three overlapping categories:

Aggregators

Pull data from public records (property, voter, court), retailer loyalty programs, and web scraping, then sell combined profiles.

People-search sites

Turn that data into a searchable, usually subscription-based product — this is the branch most directly tied to stalking and harassment risk.

DMPs

Sit on websites via tracking pixels, monitor your browsing behavior in real time, and sell "in-market" or "likely condition" segments to advertisers within milliseconds of a page load.

Most of this is legal in the US, since there's no comprehensive federal privacy law covering it — it operates in the gap between what GDPR restricts in the EU and what exists (or doesn't) elsewhere.

Real incidents worth knowing about

Exactis (2018)

Left a database of 340 million people and businesses publicly accessible with no password (400+ attributes per person). No fine was ever issued — their position was that without SSNs or card numbers, it wasn't "sensitive."

https://www.infosecurity-magazine.com/news/340-million-records-exposed-in/

https://haveibeenpwned.com/Breach/Exactis

Epsilon (2011)

Breached, exposing 60M+ email addresses tied to specific brands (Chase, Target, Best Buy, etc.), enabling highly targeted phishing.

https://krebsonsecurity.com/2015/03/feds-indict-three-in-2011-epsilon-hack/

https://abcnews.go.com/Technology/epsilon-email-breach/story?id=13291589

Deep Root Analytics (2017)

An RNC contractor left 198 million voter records — including modeled political scores — open on an unsecured AWS bucket.

https://www.upguard.com/breaches/the-rnc-files

https://www.cbsnews.com/news/nearly-200-million-americans-hit-by-massive-voter-data-leak/

Cambridge Analytica (2018)

Combined Facebook data with voter files bought from data brokers to build psychographic profiles used in the 2016 US election and Brexit campaigns.

https://www.cnbc.com/2018/04/10/facebook-cambridge-analytica-a-timeline-of-the-data-hijacking-scandal.html

https://www.axios.com/2018/04/04/facebook-sa87-million-people-impacted-in-cambridge-analytica-1522867383

Premera Blue Cross (2015)

Breached, exposing medical and financial records for 11M people. The company ultimately paid roughly $91M combined across a class-action settlement, a multistate settlement, and a federal HIPAA penalty.

https://www.techtarget.com/healthtechsecurity/news/366595555/Premera-Pays-OCR-685M-to-Settle-HIPAA-Violations-Breach-of-104M

https://oag.ca.gov/node/148821

ChoicePoint (2005)

Sold data to identity thieves posing as legitimate businesses. 163,000 people's SSNs and credit reports were exposed, leading to 800+ confirmed identity theft cases. Paid $15M to the FTC — the largest civil penalty the agency had imposed at the time.

https://www.ftc.gov/news-events/news/press-releases/2009/10/consumer-data-broker-choicepoint-failed-protect-consumers-personal-data-left-key-electronic

https://www.nbcnews.com/id/wbna11030692

Target's pregnancy-prediction program (2012)

The most-cited example of inference-based profiling.

Target built a model that scored shoppers' likelihood of pregnancy purely from purchase patterns. The famous anecdote behind it (a father learning of his teenage daughter's pregnancy from Target's coupons) has been disputed by some analysts, but the fact that Target built and used such a system is not in question.

https://www.forbes.com/sites/kashmirhill/2012/02/16/how-target-figured-out-a-teen-girl-was-pregnant-before-her-father-did/

https://www.kdnuggets.com/2014/05/target-predict-teen-pregnancy-inside-story.html

A quick note on "alleged": FTC settlements are typically resolved without the company admitting wrongdoing — that's standard procedure, not a sign the case was weak. What is real and enforceable is the outcome: the resulting order legally prohibits the company from continuing the practice, whether or not they agreed with the allegations.

Location data brokers (recent FTC enforcement)

InMarket (2024)

FTC alleged InMarket collected precise location data via its own apps and third-party SDKs, using it for targeted advertising without adequately informing users. Under the settlement, InMarket is now banned from selling or licensing precise location data — a first for the FTC.

https://www.ftc.gov/news-events/news/press-releases/2024/05/ftc-finalizes-order-inmarket-prohibiting-it-selling-or-sharing-precise-location-data

https://www.washingtonpost.com/technology/2024/01/18/ftc-location-data-privacy/

X-Mode Social / Outlogic (2024)

The FTC's first settlement specifically over the sale of sensitive location data. The company sold location data revealing visits to medical/reproductive health clinics, religious worship sites, domestic violence shelters, and LGBTQ+-associated locations, without stripping out these sensitive locations.

https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-prohibits-data-broker-x-mode-social-outlogic-selling-sensitive-location-data

https://themarkup.org/privacy/2024/01/11/federal-trade-commission-sanctions-location-data-broker-x-mode

Gravy Analytics + Venntel (2024–2025)

FTC alleged the companies sold location data revealing medical conditions, religious worship, and political activity — including sales to government contractors. Separately, in January 2025, Gravy Analytics was hacked and its data leaked on a cybercrime forum.

https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-finalizes-order-prohibiting-gravy-analytics-venntel-selling-sensitive-location-data

https://en.wikipedia.org/wiki/Gravy_Analytics

Mobilewalla (2024–2025)

Settled alongside Gravy Analytics. FTC alleged the company collected consumer location data from real-time bidding ad exchanges even when it didn't win the ad auction — the first FTC case targeting this specific collection method.

https://epic.org/ftc-takes-action-against-data-brokers-for-selling-sensitive-location-data/

https://www.adexchanger.com/data-privacy-roundup/reflecting-on-the-ftcs-latest-settlements-with-sellers-of-sensitive-location-data/

Here's the list of domains worth blocking:

! Title: DMP & Data Broker Blocklist

! Note: Lines marked "! ⚠ risky" directly above a filter indicate a domain that carries a small risk of side effects (e.g. breaking a login flow or feature). Remove those filters if you run into issues.

!—————————————————————–

! DATA BROKERS & DMP

!—————————————————————–

! === ACXIOM ===

||acxiom.com^

||acxiom.net^

||acxiom.uk^

||acxiom.co.uk^

||acxiom.de^

||acxiom.fr^

||acxiom.asia^

||acxiom.com.au^

||acxiom.jp^

||acxiom-online.com^

||acxiomdigital.com^

||recognicorp.com^

||cdn.acxiom.com^

||data.acxiom.com^

||abilitec.acxiom.com^

||identitylink.acxiom.com^

||t.acxiom-online.com^

! === EXPERIAN ===

! ⚠ risky

||experianmarketingservices.com^

||audienceiq.com^

||hitwise.com^

! ⚠ risky

||eccmp.com^

||ats.eccmp.com^

! === ORACLE DATA CLOUD (BlueKai DMP) ===

||bkrtx.com^

! ⚠ risky

||tags.bluekai.com^

||tags.bkrtx.com^

||oracleinfinity.io^

||data.oracleinfinity.io^

||datalogix.com^

||api.datalogix.com^

||pixel.datalogix.com^

! === LOTAME ===

! ⚠ risky

||lotame.com^

||lotame.io^

||crwdcntrl.net^

||tags.crwdcntrl.net^

||bcp.crwdcntrl.net^

||sync.crwdcntrl.net^

||pixel.crwdcntrl.net^

||ad.crwdcntrl.net^

||id.crwdcntrl.net^

||td.crwdcntrl.net^

||td2.crwdcntrl.net^

||meez.crwdcntrl.net^

||multiply.crwdcntrl.net^

||ltmsphrcl.net^

||c.ltmsphrcl.net^

||bcp.st.crwdcntrl.net^

||c.st.ltmsphrcl.net^

||ts.crwdcntrl.net^

! === EYEOTA ===

||eyeota.net^

! ⚠ risky

||eyeota.com^

||ps.eyeota.net^

||api.eyeota.net^

||match.eyeota.net^

||sync.eyeota.net^

! === TRANSUNION (TruAudience + Neustar) ===

||truoptik.com^

||signal.truoptik.com^

! === WILAND ===

||wiland.com^

||api.wiland.com^

! === MERKLE (Dentsu Aegis) ===

||merkle.com^

||merkleinc.com^

||api.merkle.com^

||merkleresponse.com^

||merkury.dentsu.com^

||dentsu.com^

||dentsu.co.jp^

||m1.merkle.com^

||4cite.com^

! === BOMBORA (B2B intent data) ===

||bombora.com^

||api.bombora.com^

||surge.bombora.com^

||tag.bombora.com^

! ⚠ risky

||netfactor.com^

! === ZOOMINFO ===

||zoominfo.com^

||zoom.info^

||discoverorg.com^

||api.zoominfo.com^

||websights.zoominfo.com^

||ws.zoominfo.com^

||tag.zoominfo.com^

||formcomplete.zoominfo.com^

||clickagy.com^

! === CLEARBIT (HubSpot Breeze Intelligence) ===

! ⚠ risky

||risk.clearbit.com^

! === FULLCONTACT (Ziff Davis) ===

||fullcontact.com^

||api.fullcontact.com^

||resolve.fullcontact.com^

||img.fullcontact.com^

||tag.fullcontact.com^

||cr.fullcontact.com^

||streme.fullcontact.com^

! === TOWERDATA / ATDATA ===

! ⚠ risky

||towerdata.com^

! ⚠ risky

||rapleaf.com^

! ⚠ risky

||atdata.com^

! === INFUTOR ===

! ⚠ risky

||infutor.com^

! === STIRISTA ===

||stirista.com^

||api.stirista.com^

! === TAPAD (Cross-device — Experian) ===

||tapad.com^

||api.tapad.com^

||tapestry.tapad.com^

! === ANALYTICS IQ ===

||analytics-iq.com^

||api.analytics-iq.com^

! === PERMUTIVE (DMP) ===

! ⚠ risky

||permutive.com^

||permutive.app^

||api.permutive.app^

||cdn.permutive.app^

||amp.permutive.app^

||edge.permutive.app^

! === NIELSEN MARKETING CLOUD / EXELATE ===

||exelate.com^

||exelate.info^

||mrpdata.net^

! === DATA AXLE (Infogroup) ===

||data-axle.com^

||adstradata.com^

! === NAVEGG (LATAM DMP) ===

||navegg.com^

||navegg.com.br^

||www2.navegg.com^

||navdmp.com^

||tag.navdmp.com^

||cdn.navdmp.com^

||sync.navdmp.com^

||sync2.navdmp.com^

||usr.navdmp.com^

||cus.navdmp.com^

||cus2.navdmp.com^

||view.navdmp.com^

||opi.navdmp.com^

||amp.navdmp.com^

||j.navdmp.com^

||mx.navdmp.com^

||www.navdmp.com\^

||cd.navdmp.com^

||mcd.navdmp.com^

||acd.navdmp.com^

||mcdn.navdmp.com^

||acdn.navdmp.com^

||iscd.navdmp.com^

||iscdn.navdmp.com^

||isapp.navdmp.com^

||asapp.navdmp.com^

||musr.navdmp.com^

||vht.navdmp.com^

! === THROTLE (Identity resolution) ===

||throtle.io^

!—————————————————————–

! MOBILE DATA BROKERS (Location Tracking)

!—————————————————————–

! === FACTUAL / FOURSQUARE ===

! ⚠ risky

||factual.com^

! === SAFEGRAPH ===

! ⚠ risky

||safegraph.com^

! ⚠ risky

||safegraph.io^

! === CUEBIQ ===

||cuebiq.com^

||api.cuebiq.com^

||sdk.cuebiq.com^

||events.cuebiq.com^

! === MOBILEWALLA (FTC December 2024 restricted) ===

||mobilewalla.com^

||api.mobilewalla.com^

||sdk.mobilewalla.com^

! === ADSQUARE ===

||adsquare.com^

||api.adsquare.com^

||exchange.adsquare.com^

||rtb.adsquare.com^

||match.adsquare.com^

! === UBIMO → VERICAST ===

! ⚠ risky

||ubimo.com^

! === VERVE GROUP ===

! ⚠ risky

||verve.com^

||vervemobile.com^

||vrvm.com^

||api.verve.com^

||adcel.vrvm.com^

||ad.vrvm.com^

||analytics-api.vervemobile.com^

||smaato.com^

||smaato.net^

||pubnative.net^

! ⚠ risky

||dataseat.com^

||captify.co^

||captify.co.uk^

||jungroup.com^

! === UNACAST + GRAVY ANALYTICS (FTC January 2025 restricted) ===

||unacast.com^

||api.unacast.com^

||gravyanalytics.com^

||api.gravyanalytics.com^

||venntel.com^

! === OUTLOGIC (Legacy X-Mode — FTC April 2024 restricted) ===

||outlogic.io^

! === INMARKET (FTC January 2024 restricted) ===

||inmarket.com^

||sdk.inmarket.com^

Source: r/Adguard · by /u/Corleone612

Leave a Reply

Your email address will not be published. Required fields are marked *