Nice To E-Meet You!



    What marketing services do you need for your project?

    What Is Doxxing? How It Happens And What To Do About It

    Doxxing is the act of researching and publishing someone’s private identifying information online without their consent, usually so that other people can find, contact, intimidate or harm them. The information can be a home address, a phone number, an employer, a real name behind a pseudonym, the names of family members, or a daily routine.

    Almost none of that information is secret in the strict sense. Your county records your property. Your state records your voter registration. A people-search site scraped an old forum profile. Individually each fact is dull. The harm is assembly: someone collects the pieces, arranges them into one post, and hands the result to an audience that is already angry at you.

    This guide covers what doxxing is, why the spelling keeps changing, where the information comes from, why people do it, what happens to a target afterward, and how to make yourself harder to find. One thing it deliberately does not do is explain how to dox anyone, and no section below teaches it.

    Contents

    Doxxing definition: what the word actually means

    Doxxing means gathering private or personally identifying information about a person and publishing it without their permission, typically to expose, humiliate, intimidate or endanger them. To dox someone is to do that to them. To be doxxed is to have it done to you.

    It helps to break the behavior into three steps, because the law, the platform rules and the practical defenses attach to different ones.

    • Collection. Someone pulls facts about you from data brokers, public records, old breaches and your own posts. In isolation this is often legal, which is why it is so hard to stop.
    • Aggregation. The facts get assembled into one profile. Your name plus your street plus your employer plus a photo of your front door is a different object than any of those facts alone. This is where public records become a targeting package.
    • Publication. The profile is posted where an audience can see it, usually with framing that invites action: a grievance, an accusation, a call to contact the person or their employer, sometimes an explicit threat.

    That third step separates doxxing from ordinary research. A journalist checking a source, a landlord running a background check and a recruiter reading your LinkedIn all perform step one. Doxxing is defined by publication to an audience, and usually by the intent behind it.

    Dox, doxx, doxing or doxxing: which spelling is right?

    All of them are in use and none is wrong enough to argue about. The confusion comes from the word’s origin.

    Merriam-Webster records the headword as dox, lists doxx as a variant, and accepts both inflected forms: doxed or doxxed, doxing or doxxing. It traces the word to a respelling of “docs,” the plural of “doc,” from the earlier phrases “dropping docs” and “doc-dropping,” and gives 2009 as the first known use of the verb, although the practice circulated in hacker and bulletin board culture well before the word reached print. The original sense was literal: you had documents on someone, and you dropped them in public.

    Here is how the variants line up.

    Spelling

    Part of speech

    What it means and where you will see it

    dox

    Verb and noun

    The dictionary headword. As a noun it means the documents or the compiled information itself (“someone posted his dox”). As a verb, to publish that information.

    doxx

    Verb and noun

    Listed as a variant of the same word. The double-x spelling is common in online usage, probably because it looks less like the plural of “dock.”

    doxing

    Present participle or gerund

    The single-x form, preferred by many news style guides and academic writing.

    doxxing

    Present participle or gerund

    The double-x form. The most common spelling in general online usage and the one most people type into a search box.

    doxed / doxxed

    Past tense

    Both accepted. “I got doxxed” and “I got doxed” mean the same thing. The person doing it is a doxxer or doxer.

    A practical rule: for a general online audience use doxxing, because that is what most readers write themselves, and for a publication with a house style guide check it, because plenty of newsrooms standardize on doxing. If you are filing a complaint with a platform or a police department, spell it either way and describe the conduct in plain words, because “he published my home address and told his followers to visit” is far more useful to a moderator than any spelling of a slang verb. Search engines treat all four as the same concept, so you lose nothing by picking one.

    What counts as doxxing and what does not

    The term gets stretched in arguments, so it is worth drawing lines. These are not legal rulings, just the distinctions platforms, employers and reasonable observers tend to make.

    Clearly doxxing

    • Posting a private individual’s home address, apartment number, phone number or personal email to an audience already primed to be hostile toward them.
    • Publishing where someone’s children go to school, their commute, or photographs of their house from the street.
    • Unmasking the legal name behind a pseudonymous account so the person can be found offline.
    • Compiling and releasing a dossier of aggregated personal details with no purpose other than exposure, or posting a workplace phone line alongside a demand that readers call and complain.

    Generally not doxxing

    • Naming a public official or public figure in connection with their public role. A mayor’s name and office address are not private facts.
    • Reporting that a named person filed a lawsuit, was charged with a crime or holds a professional license, where the records are public and the reporting is about the record.
    • Quoting what someone said publicly under their own name and criticizing it, however harshly. Criticism is not exposure.

    The gray zone

    Most real disputes live here. Identifying an anonymous account that has been harassing people is accountability to one side and doxxing to the other. Tagging an employer in a complaint about public conduct sits between a consumer complaint and a pressure campaign. Two questions resolve the gray zone better than the label does. Is the information connected to the conduct being discussed, or is it just a way to locate the person? And what does the audience do with it? A post that ends with an address and no reason for including the address is functioning as a doxx regardless of what its author calls it.

    Platforms also enforce their own rules here, and those rules are usually stricter than the law, so content can be removable even where nothing illegal happened.

    Where doxxers actually get your information

    This section describes the sources so you know which to close. It is a defensive map, not a method.

    People-search sites and data brokers

    This is the single biggest source and the one most people underestimate. An industry buys, scrapes, merges and resells consumer records: names, current and former addresses, phone numbers, ages, relatives, neighbors and property ownership. Its consumer-facing end is the people-search site, where anyone can type a name and get a profile for free or a few dollars. The records come from public filings, marketing lists, loyalty programs, warranty registrations, credit header data and other brokers. Nobody asked your permission, and in most states nobody had to.

    Because these sites rank well in search, one name query often surfaces a usable address on the first page. Almost all of them have an opt-out process, and almost all make it tedious on purpose. Our guide to opting out of Whitepages shows what that looks like, and the pattern repeats across the industry.

    Old breach data

    Breached databases circulate indefinitely and get combined into searchable collections. An old email address is a pivot point: it links a throwaway handle to a real name, a real name to a phone number, a phone number to a delivery address. Password reuse compounds it, because a credential from a dead service can open a live account that holds shipping addresses and receipts. You cannot un-breach data, but you can break the chain by retiring old addresses that link your identities, not reusing passwords, and turning on two-factor authentication.

    Your own social media, and the metadata in your photos

    Public profiles give up more than their owners think. A gym check-in establishes a neighborhood, a photo out of a window establishes a view, a recurring Tuesday post establishes a routine, a school shirt establishes a school. Friends and family leak information about you even when your own account is locked, especially in tagged photos.

    Photo metadata is a related risk. Digital photographs can carry EXIF data including GPS coordinates, device and timestamp. Most large social platforms strip it on upload, so a post on a major network is usually safe from this exposure. Files shared in original form are not: images attached to emails, uploaded to a personal site or forum, or synced through a cloud link can retain everything the camera wrote.

    Public records: property, voter, court and business filings

    County assessor and recorder databases list property owners and parcel addresses through searchable portals. Voter registration files contain a voter’s name and residential address, with the rules on who may obtain the file, and what they may do with it, varying considerably by state. Court dockets carry names and sometimes addresses. Business registrations list registered agents and principal offices, so if you registered an LLC from your kitchen table, your kitchen table is on file.

    You usually cannot delete a public record. You can sometimes change what it points to: use a registered agent or commercial mail address for future filings, and check whether your state runs an address confidentiality program. Several do, typically for survivors of domestic violence, stalking or sexual assault, with eligibility rules that differ by state.

    Adjacent registries do the same job. A domain registered without privacy protection may have published your name, address, email and phone, and historical snapshots persist even after you enable privacy later. Licensing boards publish licensee names, nonprofit filings list officers, and old resumes on job boards fill in the rest.

    Reverse image search and visual geolocation

    A profile picture used across several accounts links them together, and reverse image search makes that connection trivial to find. Reusing one avatar on a professional network and an anonymous forum is among the most common ways pseudonymity collapses. People are also good at identifying places from background details: a street sign, a distinctive building, a ridge line, a bus route number.

    Social engineering, which is mostly just asking

    The least technical source is the most reliable one. Someone calls a receptionist to confirm a delivery address, or messages a mutual friend claiming to be organizing a surprise, or poses as a recruiter who needs a phone number to “send the calendar invite,” or calls a customer service line pretending to be you and recites the three details they already have to get a fourth. Pretexting works because people default to being helpful and each question sounds harmless alone.

    Related is SIM swapping, where an attacker persuades a carrier to move your number to their device. Most carriers now offer a port-out PIN or number lock. Turn it on.

    Why people dox: the common motives

    Motive matters because it predicts what comes next and how long it lasts.

    • Punishment for an opinion. Someone says something contentious and a hostile audience decides that finding them offline is a proportionate response. The most common pattern, and usually the fastest-moving.
    • Vigilante identification. A crowd tries to identify the person in a viral video. Crowd identification is frequently wrong, and the misidentified party receives the full campaign anyway, often with no realistic way to correct the record.
    • Personal grudges. Ex-partners, former business associates, disgruntled ex-employees, feuding neighbors. Quieter, more persistent, and often the hardest to get platforms to act on, because the poster frames it as a private dispute.
    • Online community conflict. Disputes inside gaming and streaming communities produce a high volume of doxxing, and this is where swatting most often follows.
    • Extortion. The information is not published immediately. It is shown to the target with a demand attached, which is closer to blackmail than to a campaign.
    • Accountability framing. Some doxxing is presented as public interest journalism or activism. Sometimes that is defensible, sometimes it is a costume. The test is whether the disclosed information relates to the alleged conduct or simply locates the person.
    • Fraud groundwork or status. A full profile is raw material for identity theft and targeted phishing, and in some corners of the internet producing a dossier is a display of skill where the target is incidental.

    What happens to someone after they are doxxed

    The experience tends to follow a recognizable arc, though intensity varies enormously.

    The first wave is volume. Calls from unknown numbers, a flooded inbox, messages on every platform the target uses, and a burst of unsolicited sign-ups as people submit the address and email to mailing lists and subscription forms. Some targets receive deliveries they never ordered. The effect is that a phone and an email address stop being tools and become channels for abuse.

    The second wave is escalation to the physical world. Unwanted visitors, notes, vandalism, and in the worst cases swatting, where someone files a false emergency report designed to send an armed police response to the target’s home. Swatting is dangerous to everyone involved, including responding officers, and the FBI has established a national database for tracking swatting incidents so local agencies can connect cases across jurisdictions. Not every doxx escalates this far. Enough do that the risk cannot be waved away.

    The third wave hits work. Employers get emails. Clients get tagged. Review profiles get hit. Licensing boards receive complaints. Even when the accusations are baseless, the volume is a burden an employer may resent, and some targets lose income for reasons unrelated to whether the claim was true.

    Then comes persistence. The original post is deleted and reappears elsewhere. Screenshots outlive the source. Archives keep copies. Search results for the target’s name reorganize around the incident, so anyone who looks them up sees the campaign rather than their work. This is the phase that turns an acute incident into a long-running online reputation management problem, because removal at the source does not clean the mirrors, the aggregators or the search results that picked it up.

    Underneath all of it sits security risk. Exposed details feed identity theft, credential stuffing and targeted phishing, and password reset flows built on personal knowledge questions become weak points once the answers are public. Targets frequently change numbers, rebuild account security, and in severe cases move.

    Then there is the part that shows up in no log: the anxiety of not knowing who has your address, the hypervigilance about the front door, the effect on partners and children who did not sign up for any of it. People working through the practical checklist routinely underestimate how much of the damage is this.

    Is doxxing illegal?

    It depends on the conduct, the state and who was targeted. No single federal statute in the United States makes doxxing a crime by that name. Federal charges generally rest on statutes written about interstate stalking, threats and harassment, so the facts have to fit those statutes. A number of states have passed laws addressing publication of personal information with intent to intimidate, and several protect specific groups such as judges, law enforcement officers and health workers. Civil claims may also exist depending on what was published and what followed. Separately, virtually every major platform bans doxxing in its terms of service.

    Because the law is uneven, we cover it in depth in a companion guide on whether doxxing is illegal and what US law actually says. That piece is general information, not legal advice, and anyone with a live situation should speak to a lawyer licensed in their state.

    How to reduce your exposure before anything happens

    You cannot make yourself unfindable, but you can make yourself expensive to find, which deflects most attempts, because most doxxing is opportunistic rather than determined.

    Start with the people-search sites

    This is the highest-yield work. Search your name, your name plus your city, your name plus a former city, and your phone number, then list every people-search result showing real information about you and work through each opt-out. Expect a few hours, expect email confirmations, and expect to repeat the check in six months, because records get re-ingested from upstream sources.

    Our guide to removing your address from the internet walks through this in order and links to the opt-out processes for the major sites.

    California residents have an extra route. Under the state’s Delete Act, the California Privacy Protection Agency runs the Delete Request and Opt-Out Platform, known as DROP, which lets a verified resident file one deletion request that registered data brokers must honor. Consumers have been able to submit requests since January 1, 2026, and registered brokers became obligated to process them from August 1, 2026. It does not cover every company holding data about you, but it replaces a great deal of manual opt-out work with a single request.

    Harden the accounts that unlock everything else

    • Turn on two-factor authentication everywhere, and prefer an authenticator app or a hardware security key over SMS codes.
    • Ask your mobile carrier to set a port-out PIN or number lock to blunt SIM swapping.
    • Use a password manager and stop reusing passwords, so one old breach cannot cascade.
    • Audit account recovery settings. An abandoned recovery email or old phone number is a live back door, and security questions should be treated as passwords rather than facts, because the true answer may already be published.

    Separate the identities you want kept apart

    • Use distinct email addresses for professional, personal and throwaway sign-ups, and never reuse a username or a profile photograph across contexts you want unlinked.
    • Use a forwarding number for anything public-facing rather than your real mobile number.
    • Enable domain privacy on any domain you own, and use a registered agent, a commercial mail address or a mailbox service for filings and deliveries rather than your home.

    Audit what you and your circle publish

    • Review privacy settings on every social account, including who can see your friends list, tagged photos and old posts.
    • Delete or lock down accounts you no longer use. Dormant profiles are often the most revealing, because you set them up before you thought about any of this.
    • Avoid real-time location posting, and check what is visible behind you in photos taken at home.
    • Ask family members not to tag your location or post identifying details about your children.

    Use the removal tools that already exist

    Google offers a “Results about you” feature that finds search results containing your personal contact information, lets you request removal, and can notify you when new ones appear. Its published policy covers your address, phone number and email, government identification numbers, bank or card numbers, images of your signature or identity documents, private records such as medical records, and confidential credentials. It also covers doxxing content specifically: results pairing your personal information with explicit or implicit threats or calls to harass you, or aggregating a significant amount of personal information without a legitimate purpose. Removal from search is not deletion at the source, and Google weighs whether content is newsworthy, so requests are not automatic. It is still one of the highest-leverage buttons available, because most people find you through search.

    Put the audit on a calendar

    Check

    What you are looking for

    How often

    Your full name, and name plus city

    People-search listings, old profiles, anything with an address

    Quarterly

    Your phone number and personal email

    Leaked contact details, forum posts, marketplace listings

    Quarterly

    Reverse image search of profile photos

    Accounts you thought were unlinked

    Twice a year

    Domain WHOIS and business filings

    A home address sitting in a public register

    Annually

    If it has already happened to you

    Prevention advice is cold comfort once your address is on a message board. The priorities change: capture evidence before the poster deletes it, secure accounts before anyone tests the exposed details, report to every platform involved, decide whether to contact law enforcement, get ahead of the conversation at work or school, then start the slower removal and suppression work.

    We set that out step by step in what to do if you get doxxed, organized around the first forty-eight hours and the weeks after. Work through it in order, and do not delete your own accounts before screenshotting what you need, because that destroys your evidence along with the abuse.

    Doxxing FAQ

    What does doxxed mean?

    Being doxxed means your private identifying information, typically your real name, home address, phone number or workplace, has been published online without your consent, usually so others can find, contact or harass you. “Doxed” is an equally accepted spelling.

    What does it mean to dox someone?

    To dox someone is to research their personal details and publish them to an audience without permission. The defining elements are aggregation into a profile and publication to people who can act on it. Looking someone up privately is research. Posting what you found is doxxing.

    Can someone be identified from just a username?

    Frequently, yes, if the username has been reused. A handle carried across a gaming account, a forum, a marketplace listing and an old blog builds a chain that ends at a real name.

    Does deleting my social media fix it?

    Not by itself. It does nothing about broker records, public filings, cached pages or screenshots already in circulation, and it can destroy evidence you may need. Lock accounts down first, preserve what documents the abuse, and delete only deliberately.

    How long does removal take?

    It varies by channel. Platform takedowns of clearly violating content can move in days. Broker opt-outs take weeks, with a real chance of records returning. Search removals depend on policy fit, and suppressing what still ranks takes months. Anyone promising total erasure on a fixed timetable is overselling.

    Will you explain how to dox someone?

    No. This guide describes where exposure comes from so you can close it, and nothing here is a method for targeting anyone.

    Conclusion

    Doxxing works because modern life scatters small pieces of you across brokers, registries, platforms and old accounts, and because assembling those pieces takes less effort than protecting them. The word is unsettled, spelled dox, doxx, doxing or doxxing depending on who is writing, but the conduct is consistent: collect, aggregate, publish, and let an audience do the rest.

    Exposure is a maintenance problem more than a technical one. Opting out of people-search sites, keeping identities separate, hardening account recovery, using the removal tools that exist and watching what you and your circle publish will not make you invisible, but they close the easy paths, and the easy paths are the ones almost everyone uses.

    If your information is already out there, sequence matters more than speed: preserve evidence, secure accounts, report, then remove and suppress. And if search results for your name have reorganized around an incident rather than your work, that is a reputation problem as much as a security one, and it responds to sustained effort rather than a single takedown.

      Once a week you will get the latest articles delivered right to your inbox