Skip to content
DnsLister Forum

Where domain hunters compare notes

Data Brokers & DMPs: Why They’re Worth Blocking

Data brokers are companies that collect, combine, and sell personal information people never agreed to share. There are an estimated 4,000+ of them in the US alone, and together they hold detailed profiles on nearly every person with an internet-connected device — address history, estimated income, health-related inferences, political leanings.

I spent time mapping the actual domain infrastructure behind this industry (aggregators, people-search sites, and DMPs — data management platforms that track browsing behavior in real time and sell "audience segments") and turned it into a DNS blocklist. Sharing both the reasoning and the list here.

How this actually works

Three overlapping categories:

Aggregators Pull data from public records (property, voter, court), retailer loyalty programs, and web scraping, then sell combined profiles.

People-search sites Turn that data into a searchable, usually subscription-based product — this is the branch most directly tied to stalking and harassment risk.

DMPs Sit on websites via tracking pixels, monitor your browsing behavior in real time, and sell "in-market" or "likely condition" segments to advertisers within milliseconds of a page load.

Most of this is legal in the US, since there's no comprehensive federal privacy law covering it — it operates in the gap between what GDPR restricts in the EU and what exists (or doesn't) elsewhere.

Real incidents worth knowing about

Exactis (2018) Left a database of 340 million people and businesses publicly accessible with no password (400+ attributes per person). No fine was ever issued — their position was that without SSNs or card numbers, it wasn't "sensitive."

https://www.infosecurity-magazine.com/news/340-million-records-exposed-in/

https://haveibeenpwned.com/Breach/Exactis Epsilon (2011) Breached, exposing 60M+ email addresses tied to specific brands (Chase, Target, Best Buy, etc.), enabling highly targeted phishing.

https://krebsonsecurity.com/2015/03/feds-indict-three-in-2011-epsilon-hack/

https://abcnews.go.com/Technology/epsilon-email-breach/story?id=13291589

Deep Root Analytics (2017) An RNC contractor left 198 million voter records — including modeled political scores — open on an unsecured AWS bucket.

https://www.upguard.com/breaches/the-rnc-files

https://www.cbsnews.com/news/nearly-200-million-americans-hit-by-massive-voter-data-leak/

Cambridge Analytica (2018)

Combined Facebook data with voter files bought from data brokers to build psychographic profiles used in the 2016 US election and Brexit campaigns.

https://www.cnbc.com/2018/04/10/facebook-cambridge-analytica-a-timeline-of-the-data-hijacking-scandal.html

https://www.axios.com/2018/04/04/facebook-sa87-million-people-impacted-in-cambridge-analytica-1522867383

Premera Blue Cross (2015)

Breached, exposing medical and financial records for 11M people. The company ultimately paid roughly $91M combined across a class-action settlement, a multistate settlement, and a federal HIPAA penalty.

https://www.techtarget.com/healthtechsecurity/news/366595555/Premera-Pays-OCR-685M-to-Settle-HIPAA-Violations-Breach-of-104M

https://oag.ca.gov/node/148821

ChoicePoint (2005)

Sold data to identity thieves posing as legitimate businesses. 163,000 people's SSNs and credit reports were exposed, leading to 800+ confirmed identity theft cases. Paid $15M to the FTC — the largest civil penalty the agency had imposed at the time.

https://www.ftc.gov/news-events/news/press-releases/2009/10/consumer-data-broker-choicepoint-failed-protect-consumers-personal-data-left-key-electronic

https://www.nbcnews.com/id/wbna11030692

Target's pregnancy-prediction program (2012)

The most-cited example of inference-based profiling.

Target built a model that scored shoppers' likelihood of pregnancy purely from purchase patterns. The famous anecdote behind it (a father learning of his teenage daughter's pregnancy from Target's coupons) has been disputed by some analysts, but the fact that Target built and used such a system is not in question.

https://www.forbes.com/sites/kashmirhill/2012/02/16/how-target-figured-out-a-teen-girl-was-pregnant-before-her-father-did/

https://www.kdnuggets.com/2014/05/target-predict-teen-pregnancy-inside-story.html

A quick note on "alleged": FTC settlements are typically resolved without the company admitting wrongdoing — that's standard procedure, not a sign the case was weak. What is real and enforceable is the outcome: the resulting order legally prohibits the company from continuing the practice, whether or not they agreed with the allegations.

Location data brokers (recent FTC enforcement)

InMarket (2024) FTC alleged InMarket collected precise location data via its own apps and third-party SDKs, using it for targeted advertising without adequately informing users. Under the settlement, InMarket is now banned from selling or licensing precise location data — a first for the FTC.

https://www.ftc.gov/news-events/news/press-releases/2024/05/ftc-finalizes-order-inmarket-prohibiting-it-selling-or-sharing-precise-location-data

https://www.washingtonpost.com/technology/2024/01/18/ftc-location-data-privacy/

X-Mode Social / Outlogic (2024)

The FTC's first settlement specifically over the sale of sensitive location data. The company sold location data revealing visits to medical/reproductive health clinics, religious worship sites, domestic violence shelters, and LGBTQ+-associated locations, without stripping out these sensitive locations.

https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-prohibits-data-broker-x-mode-social-outlogic-selling-sensitive-location-data

https://themarkup.org/privacy/2024/01/11/federal-trade-commission-sanctions-location-data-broker-x-mode

Gravy Analytics + Venntel (2024–2025)

FTC alleged the companies sold location data revealing medical conditions, religious worship, and political activity — including sales to government contractors. Separately, in January 2025, Gravy Analytics was hacked and its data leaked on a cybercrime forum.

https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-finalizes-order-prohibiting-gravy-analytics-venntel-selling-sensitive-location-data

https://en.wikipedia.org/wiki/Gravy\_Analytics

Mobilewalla (2024–2025)

Settled alongside Gravy Analytics. FTC alleged the company collected consumer location data from real-time bidding ad exchanges even when it didn't win the ad auction — the first FTC case targeting this specific collection method.

https://epic.org/ftc-takes-action-against-data-brokers-for-selling-sensitive-location-data/

https://www.adexchanger.com/data-privacy-roundup/reflecting-on-the-ftcs-latest-settlements-with-sellers-of-sensitive-location-data/

Why block this at the DNS level Browser extensions catch some of this, but a lot of DMP tracking happens through first-party-looking pixel calls or server-side syncing that extensions don't always see. Blocking at the DNS level stops the connection before it's made, across every app and browser on the network — not just one browser tab.

Raw links:

For basic list

https://raw.githubusercontent.com/CorleoneSalute/SHADOW-BLOCKER-BLOCKLIST/refs/heads/main/dist/basic/hosts/DMP-Data-Broker.txt

For aggressive list

https://raw.githubusercontent.com/CorleoneSalute/SHADOW-BLOCKER-BLOCKLIST/refs/heads/main/dist/aggressive/hosts/DMP-Data-Broker.txt

Here's the list of domains worth blocking:

“`

DMP & Data Broker Blocklist

Total domains: 244

Note: domains marked with "!" carry a small risk of side effects (e.g. breaking a login flow or feature) – block these only if you're comfortable troubleshooting

🔴 DATA BROKERS & DMP

ACXIOM

acxiom.com acxiom.net acxiom.uk acxiom.co.uk acxiom.de acxiom.fr acxiom.asia acxiom.com.au acxiom.jp acxiom-online.com acxiomdigital.com recognicorp.com cdn.acxiom.com data.acxiom.com abilitec.acxiom.com identitylink.acxiom.com t.acxiom-online.com

EXPERIAN

experianmarketingservices.com ! audienceiq.com hitwise.com eccmp.com ! ats.eccmp.com

ORACLE DATA CLOUD (BlueKai DMP)

bkrtx.com tags.bluekai.com ! tags.bkrtx.com oracleinfinity.io data.oracleinfinity.io datalogix.com api.datalogix.com pixel.datalogix.com

LOTAME

lotame.com ! lotame.io crwdcntrl.net tags.crwdcntrl.net bcp.crwdcntrl.net sync.crwdcntrl.net pixel.crwdcntrl.net ad.crwdcntrl.net id.crwdcntrl.net td.crwdcntrl.net td2.crwdcntrl.net meez.crwdcntrl.net multiply.crwdcntrl.net ltmsphrcl.net c.ltmsphrcl.net bcp.st.crwdcntrl.net c.st.ltmsphrcl.net ts.crwdcntrl.net

EYEOTA

eyeota.net eyeota.com ! ps.eyeota.net api.eyeota.net match.eyeota.net sync.eyeota.net

TRANSUNION (TruAudience + Neustar)

truoptik.com signal.truoptik.com

WILAND

wiland.com api.wiland.com

MERKLE (Dentsu Aegis)

merkle.com merkleinc.com api.merkle.com merkleresponse.com merkury.dentsu.com dentsu.com dentsu.co.jp m1.merkle.com 4cite.com

BOMBORA (B2B intent data)

bombora.com api.bombora.com surge.bombora.com tag.bombora.com netfactor.com !

ZOOMINFO

zoominfo.com zoom.info discoverorg.com api.zoominfo.com websights.zoominfo.com ws.zoominfo.com tag.zoominfo.com formcomplete.zoominfo.com clickagy.com

CLEARBIT (HubSpot Breeze Intelligence)

risk.clearbit.com !

FULLCONTACT (Ziff Davis)

fullcontact.com api.fullcontact.com resolve.fullcontact.com img.fullcontact.com tag.fullcontact.com cr.fullcontact.com streme.fullcontact.com

TOWERDATA / ATDATA

towerdata.com ! rapleaf.com ! atdata.com !

INFUTOR

infutor.com !

STIRISTA

stirista.com api.stirista.com

TAPAD (Cross-device — Experian)

tapad.com api.tapad.com tapestry.tapad.com

ANALYTICS IQ

analytics-iq.com api.analytics-iq.com

PERMUTIVE (DMP)

permutive.com ! permutive.app api.permutive.app cdn.permutive.app amp.permutive.app edge.permutive.app

NIELSEN MARKETING CLOUD / EXELATE

exelate.com exelate.info mrpdata.net

DATA AXLE (Infogroup)

data-axle.com adstradata.com

NAVEGG (LATAM DMP)

navegg.com navegg.com.br www2.navegg.com navdmp.com tag.navdmp.com cdn.navdmp.com sync.navdmp.com sync2.navdmp.com usr.navdmp.com cus.navdmp.com cus2.navdmp.com view.navdmp.com opi.navdmp.com amp.navdmp.com j.navdmp.com mx.navdmp.com www.navdmp.com cd.navdmp.com mcd.navdmp.com acd.navdmp.com mcdn.navdmp.com acdn.navdmp.com iscd.navdmp.com iscdn.navdmp.com isapp.navdmp.com asapp.navdmp.com musr.navdmp.com vht.navdmp.com

THROTLE (Identity resolution)

throtle.io

🟠 MOBILE DATA BROKERS (Location Tracking)

FACTUAL / FOURSQUARE

factual.com !

SAFEGRAPH

safegraph.com ! safegraph.io !

CUEBIQ

cuebiq.com api.cuebiq.com sdk.cuebiq.com events.cuebiq.com

MOBILEWALLA (FTC December 2024 restricted)

mobilewalla.com api.mobilewalla.com sdk.mobilewalla.com

ADSQUARE

adsquare.com api.adsquare.com exchange.adsquare.com rtb.adsquare.com match.adsquare.com

UBIMO → VERICAST

ubimo.com !

VERVE GROUP

verve.com ! vervemobile.com vrvm.com api.verve.com adcel.vrvm.com ad.vrvm.com analytics-api.vervemobile.com smaato.com smaato.net pubnative.net dataseat.com ! captify.co captify.co.uk jungroup.com

UNACAST + GRAVY ANALYTICS (FTC January 2025 restricted)

unacast.com api.unacast.com gravyanalytics.com api.gravyanalytics.com venntel.com

OUTLOGIC (Legacy X-Mode — FTC April 2024 restricted)

outlogic.io

INMARKET (FTC January 2024 restricted)

inmarket.com sdk.inmarket.com “`

Source: r/dns · by /u/Corleone612

Leave a Reply

Your email address will not be published. Required fields are marked *