FaceSift

Doxxing: How to Know You've Been Doxxed and What to Do

Β·11 min read

Doxxing is the publication of your private information β€” home address, phone number, workplace, family details β€” without your consent, usually to enable harassment or intimidation. It rarely involves hacking. Almost all of it is built from public records, data broker listings, and posts you or others made years ago and forgot about.

This guide covers how doxxing actually happens, the early signs it's underway before it's fully public, exactly what to do in the first hour after you find it, how to get the information removed, and how to reduce what's available for someone to compile next time.

If you've confirmed your information is already posted publicly:

βš‘Screenshot everything before it's edited or deleted
βš‘Do not engage or respond to the poster
βš‘Change passwords and enable app-based 2FA immediately
βš‘Set all social profiles to private
βš‘Warn family, friends, or employers who may be contacted
βš‘Report through the platform's specific doxxing category
βš‘Contact police if any threat accompanies the post
βš‘Do not delete your own accounts β€” you'll need the evidence
01

How Doxxing Actually Happens

Doxxing is the act of researching and publishing someone's private information β€” home address, phone number, workplace, family members, daily routine β€” without their consent, usually to enable harassment, intimidation, or violence. Almost none of it requires hacking. Most doxxes are built entirely from data you or a data broker already made available.

Data broker aggregation

Sites like Spokeo, Whitepages, BeenVerified, and dozens of lesser-known brokers compile your name, current and past addresses, phone numbers, relatives, and age from public records β€” voter rolls, property deeds, court filings β€” and sell it as a searchable profile. A doxxer's first stop is almost always one of these sites, not a hacking forum.

Old posts and forgotten accounts

A LinkedIn post from eight years ago listing your employer, a Reddit comment mentioning your city, a Yelp review tied to your real name β€” a determined person cross-references dozens of small, individually harmless disclosures across old accounts you may have forgotten existed.

Reused usernames across platforms

If you use the same handle on a pseudonymous forum and on an account that includes your real name, that username becomes a bridge. Tools built specifically for username correlation (Sherlock, WhatsMyName) exist for legitimate research but are routinely used to unmask people who believed a platform gave them anonymity.

EXIF and metadata in photos

Photos uploaded outside of major social platforms (which usually strip metadata automatically) can still carry embedded GPS coordinates, device information, and timestamps. A single unstripped photo posted to a personal blog or niche forum can reveal a home address directly.

Breach data and credential dumps

Emails, passwords, and account details leaked in past corporate data breaches circulate on forums and marketplaces. Combined with your email address, breach data often reveals which other services you use β€” each one a further source to mine for identifying details.

Domain WHOIS records

If you registered a personal website or domain without WHOIS privacy protection, your name, address, and phone number may be publicly queryable through WHOIS lookup tools β€” a detail many people never think to check.

02

Signs You've Been Doxxed β€” or Are About To Be

Doxxing sometimes arrives all at once, as a single post listing everything about you. More often it builds gradually, and the early signs are easy to dismiss individually. Watching for the pattern, not just a single incident, is what allows you to act before the exposure is complete.

A sudden spike in unfamiliar contact

A wave of messages, friend requests, or comments from accounts you don't recognise β€” especially hostile ones β€” often means your identity or contact information was just shared somewhere you can't see, such as a forum thread or group chat.

Someone references details you never told them

A stranger mentioning your home neighbourhood, your workplace, your daily schedule, or family members' names is the clearest sign that your information has already been compiled and shared, even if you haven't found the source yet.

Unusual mail, deliveries, or account activity

Unordered packages, prank food deliveries, or sign-ups for services you never requested are a known follow-on tactic once an address is exposed β€” sometimes used to intimidate, sometimes as a precursor to more serious harassment.

A screenshot or post is circulating out of context

If a post, photo, or comment of yours is being shared and recirculated far outside its original audience β€” particularly on forums associated with harassment campaigns β€” that circulation is often the trigger event that leads directly to a dox.

You find a compiled profile before it's shared widely

Occasionally you catch it early: a pastebin, a forum post, or a document listing your details that hasn't yet been widely circulated. This is the best-case scenario for acting fast β€” treat it with the same urgency as a fully public dox.

03

What to Do in the First Hour

If you've confirmed your information has been posted publicly, the first hour is about containment and documentation β€” not confrontation. Acting in the right order prevents you from losing evidence or missing a step that becomes harder to undo later.

Screenshot everything before it's taken down

Capture the full post, the URL, the username or account that posted it, timestamps, and any surrounding comments or replies. Posts get deleted or edited quickly once attention arrives β€” you need your own record before that happens.

Do not respond publicly or engage the poster

Replying, arguing, or trying to get the poster to take it down yourself often draws more attention to the post and can escalate the situation. Report through the platform instead β€” engagement rarely helps and frequently makes things worse.

Alert people who might be contacted about you

If family members, an employer, or close friends are named or could plausibly be contacted by a harasser, give them a heads-up so an unexpected call or message doesn't catch them off guard β€” and so they know not to confirm any details.

Lock down your accounts immediately

Change passwords, enable two-factor authentication using an authenticator app (not SMS), and set social profiles to private. If your information is out, the next likely step is an attempt to access your accounts directly.

If there is a credible threat, contact police

Doxxing paired with explicit threats of violence, stalking, or an incitement for others to "visit" your address is a criminal matter in most jurisdictions. File a police report and bring your screenshots β€” do this even if you're unsure whether the threat is credible.

If a threat of violence or a physical address disclosure is involved, contact local law enforcement rather than trying to resolve it yourself. Doxxing paired with threats or incitement is a criminal matter in most jurisdictions, and a police report strengthens every removal request you file afterward.

04

Getting Your Information Removed

Removal is rarely a single action β€” it's a checklist you work through methodically across the sources that expose you. Data broker opt-outs in particular need to be repeated periodically, since brokers frequently re-scrape and relist information after it's removed.

Opt out of data broker sites

Submit removal requests directly to Spokeo, Whitepages, BeenVerified, MyLife, Intelius, and the dozens of smaller aggregators β€” each has its own opt-out form, usually under a 'privacy' or 'do not sell my info' link in the footer. Services like DeleteMe or Optery automate this across hundreds of brokers if doing it manually isn't practical.

Report the post through the platform's dedicated channel

Use the specific 'sharing private information' or 'doxxing' report category where available, not the generic abuse report β€” it routes to a specialised team and is typically actioned faster. Include your screenshots and the direct URL.

Request search de-indexing

Google's 'Results about you' tool (myaccount.google.com) lets you request removal of pages showing your address, phone number, or other personal information from search results, even if the underlying page itself isn't taken down.

Add WHOIS privacy to any personal domains

If you own a personal website or domain, enable WHOIS privacy protection through your registrar β€” usually free or a few dollars a year β€” to stop your registration details from being publicly queryable.

Request removal from screenshots and mirrors

Doxxing posts are often screenshotted and re-shared even after the original is removed. Search for the exact text or your name on the platforms where it's circulating and file a fresh removal report against each copy you find.

05

Reducing Your Exposure Going Forward

You can't make yourself un-doxxable, but you can shrink the pool of information available for someone to compile in the first place β€” and that's what determines how bad a future attempt can get.

Audit what strangers can currently find about you

Search your own name, past usernames, phone number, and email address in quotes to see what's publicly indexed right now. Doing this quarterly catches new broker listings and old posts before someone else finds them first.

Separate your identities across platforms

Use a distinct username, email, and where possible a different photo for accounts you want to keep separate from your real name β€” pseudonymous forums, dating apps, hobby communities. Reused handles are the single easiest correlation point.

Strip metadata before posting photos anywhere

Most major social platforms strip EXIF data automatically, but personal blogs, forums, and some messaging apps do not. When in doubt, strip location metadata manually before uploading.

Check whether your photos are circulating under a different name

A reverse face search shows whether a photo of you has been reposted, scraped, or attached to an account you don't control β€” often the first sign that someone is building a profile on you before a dox is ever posted.

Set a recurring reminder to repeat broker opt-outs

Data brokers re-scrape public records on a rolling basis, which means information you had removed can reappear months later. Repeating the opt-out process every few months (or using an automated removal service) keeps exposure consistently low rather than fixed once and forgotten.

Full response checklist

  • 01Screenshot the post, URL, username, and timestamps before it's removed
  • 02Do not respond to or engage the person who posted it
  • 03Warn anyone named or likely to be contacted about you
  • 04Change passwords and enable authenticator-app 2FA on every account
  • 05Set social profiles to private
  • 06Report through the platform's dedicated doxxing or private-info category
  • 07File a police report if any threat accompanies the exposure
  • 08Submit opt-out requests to Spokeo, Whitepages, BeenVerified, and other brokers
  • 09Request de-indexing via Google's Results About You tool
  • 10Enable WHOIS privacy on any personal domains
  • 11Search for and report re-shared copies or screenshots
  • 12Set a recurring reminder to repeat broker opt-outs every few months

Related guides

Check where your photos are showing up online

A doxxing profile often starts with a photo pulled from somewhere you didn't expect. Upload a photo to FaceSift and see where your face appears across the public web.

Search My Photos β†’