The Form Nobody Wanted
You want to read a recipe, download a spec sheet, use a calculator, or see a price. Between you and the thing sits a box asking for your email address.
It is worth understanding why that box is there, because "they want to spam you" is only a small part of the answer — and the rest explains a lot about how the modern web is financed.
Reason 1: It Is the Last Reliable Identifier
This is the big one, and it is fairly recent.
For two decades the web tracked people with third-party cookies. Those are now blocked by default in Safari and Firefox, are heavily restricted on mobile, and are steadily disappearing everywhere. The old plumbing for recognising a visitor across sites has largely stopped working.
An email address does not have that problem. It is stable for years, it is the same string everywhere, and — critically — it can be hashed. Convert your address to a fixed-length fingerprint and two companies can compare fingerprints to confirm they are dealing with the same person, without either sending the address in the clear.
That is the mechanism behind a large share of modern advertising. Your address has quietly become the identifier the cookie used to be, which is exactly why every site wants it.
Reason 2: Email Is the Only Channel They Own
A company's social following belongs to the platform. Change the algorithm and their reach halves overnight. Search rankings belong to Google. Their app is one store policy away from a problem.
A mailing list belongs to them. Nobody can take it away, throttle it, or charge them for access to their own audience. In marketing terms that makes it the most valuable asset a business can build, and it is why the popup appears three seconds after you land.
Reason 3: It Is Genuinely Cheap and Effective
Sending email costs almost nothing. Even a poor response rate is profitable when the marginal cost per message is a fraction of a penny. Compared to advertising, it is close to free.
So the calculation is simple: annoy some visitors with a form, convert a percentage into a list, monetise that list indefinitely. It is not sinister. It is just arithmetic that happens not to have your convenience in it.
Reason 4: Sometimes They Actually Need It
Worth being fair about. There are legitimate cases:
- Account recovery. Without a way to reach you, a forgotten password locks you out permanently.
- Transactional messages. Receipts, shipping updates, appointment reminders.
- Security alerts. Telling you about a login from a new device.
- Abuse control. Requiring a working address raises the cost of creating accounts in bulk, which is a real defence against spam and fraud.
The distinction that matters is whether they need it for you or for them. A password reset is for you. A form guarding a PDF is not.
Reason 5: The Data Is Worth More Than the Product
The uncomfortable one. For some businesses the address is not a means to selling something — it is the thing being sold.
"We may share your information with trusted partners" in a privacy policy typically means the address goes into a data marketplace. Combine it with your name, rough location and a few behavioural signals, and it becomes a profile with a market price.
This is legal in most places if disclosed, and the disclosure is in a document written to be skimmed. You did consent. You just consented in nine-point type at the bottom of a page you were trying to leave.
How to Answer the Box
The useful question is not "should I give my address" but "which address should this get?" Three buckets, and sorting them takes a second:
Your real address — a short list
Banking, tax, medical, employer, government, subscriptions you pay for, and the recovery address on your important accounts. If losing access would be a serious problem, it gets the real address.
The goal is a list short enough to count. Most people's real address is on hundreds of lists, which is precisely why their inbox is unusable.
An alias — the middle
Shops, newsletters, apps, communities. Anything you want to hear from now and may not want to hear from later. A separate alias per company means you can switch off any one of them, and if it starts receiving junk you know exactly who leaked it.
A temporary address — the rest
The one-off download, the forum you will post in once, the wifi portal, the coupon, the site that will not show you an article without a form. A temporary address gets you through and then removes itself, so the list it joined has nothing to send to.
The one rule: never use a disposable address for something you might need to log back into. The reset link would go to an inbox that no longer exists.
Reading a Signup Form
A few tells that indicate what is coming:
- A pre-ticked marketing box. Unlawful in much of Europe. Elsewhere it means opt-out was chosen deliberately.
- "Offers from our partners" as a separate checkbox. Explicit notice that your address is going elsewhere. Untick it.
- Required fields that make no sense. A newsletter does not need your date of birth. That is profiling.
- No unsubscribe promise anywhere. Reputable senders say how to leave, because they are required to.
- Confirmation required before anything is sent. A good sign — double opt-in is what responsible senders do.
Common Questions
Is it illegal to enter a fake email address?
No. There is no law requiring you to hand your permanent address to every website. What matters is what you do afterwards — fraud and impersonation are unlawful regardless of which address you used. Declining to give a shop your personal address is not.
Why do some sites reject temporary addresses?
Because a proportion of people use them to create repeat accounts, dodge trial limits or evade bans. Sites that care about one account per person block known disposable domains. That is a legitimate business decision, and if a form rejects the address instantly, that is what happened.
Do they know if I never open their emails?
Usually, roughly. Open tracking uses a remote image and is defeated by image blocking, but link clicks are tracked reliably. Many senders eventually stop mailing unengaged addresses because inactive subscribers hurt their deliverability.
What actually happens after I unsubscribe?
From a legitimate sender, you are suppressed within a few days and that is genuinely the end of it. From an operation that bought your address, nothing — except confirming a human read the message. The test is whether you could plausibly have given them the address in the first place.
Should I just use one address for everything?
It is the default and it is why inboxes decay. One address everywhere means one breach exposes your identity across every service, no way to tell who leaked it, and no way to switch off a single source. Splitting across three tiers costs almost no effort and prevents most of it.
The Short Version
Websites want your address because third-party cookies are dying and email has become the identifier that replaced them, because a mailing list is the only audience a company truly owns, and because sending mail is nearly free. Some genuinely need it; many are collecting an asset.
You do not have to refuse. You just have to decide which of your three addresses this particular form has earned.
