Doxxing is the act of researching and publishing someone’s private identifying information online without their consent, usually so that other people can find, contact, intimidate or harm them. The information can be a home address, a phone number, an employer, a real name behind a pseudonym, the names of family members, or a daily routine.
Almost none of that information is secret in the strict sense. Your county records your property. Your state records your voter registration. A people-search site scraped an old forum profile. Individually each fact is dull. The harm is assembly: someone collects the pieces, arranges them into one post, and hands the result to an audience that is already angry at you.
This guide covers what doxxing is, why the spelling keeps changing, where the information comes from, why people do it, what happens to a target afterward, and how to make yourself harder to find. One thing it deliberately does not do is explain how to dox anyone, and no section below teaches it.
Doxxing means gathering private or personally identifying information about a person and publishing it without their permission, typically to expose, humiliate, intimidate or endanger them. To dox someone is to do that to them. To be doxxed is to have it done to you.
It helps to break the behavior into three steps, because the law, the platform rules and the practical defenses attach to different ones.
That third step separates doxxing from ordinary research. A journalist checking a source, a landlord running a background check and a recruiter reading your LinkedIn all perform step one. Doxxing is defined by publication to an audience, and usually by the intent behind it.
All of them are in use and none is wrong enough to argue about. The confusion comes from the word’s origin.
Merriam-Webster records the headword as dox, lists doxx as a variant, and accepts both inflected forms: doxed or doxxed, doxing or doxxing. It traces the word to a respelling of “docs,” the plural of “doc,” from the earlier phrases “dropping docs” and “doc-dropping,” and gives 2009 as the first known use of the verb, although the practice circulated in hacker and bulletin board culture well before the word reached print. The original sense was literal: you had documents on someone, and you dropped them in public.
Here is how the variants line up.
|
Spelling |
Part of speech |
What it means and where you will see it |
|---|---|---|
|
dox |
Verb and noun |
The dictionary headword. As a noun it means the documents or the compiled information itself (“someone posted his dox”). As a verb, to publish that information. |
|
doxx |
Verb and noun |
Listed as a variant of the same word. The double-x spelling is common in online usage, probably because it looks less like the plural of “dock.” |
|
doxing |
Present participle or gerund |
The single-x form, preferred by many news style guides and academic writing. |
|
doxxing |
Present participle or gerund |
The double-x form. The most common spelling in general online usage and the one most people type into a search box. |
|
doxed / doxxed |
Past tense |
Both accepted. “I got doxxed” and “I got doxed” mean the same thing. The person doing it is a doxxer or doxer. |
A practical rule: for a general online audience use doxxing, because that is what most readers write themselves, and for a publication with a house style guide check it, because plenty of newsrooms standardize on doxing. If you are filing a complaint with a platform or a police department, spell it either way and describe the conduct in plain words, because “he published my home address and told his followers to visit” is far more useful to a moderator than any spelling of a slang verb. Search engines treat all four as the same concept, so you lose nothing by picking one.
The term gets stretched in arguments, so it is worth drawing lines. These are not legal rulings, just the distinctions platforms, employers and reasonable observers tend to make.
Most real disputes live here. Identifying an anonymous account that has been harassing people is accountability to one side and doxxing to the other. Tagging an employer in a complaint about public conduct sits between a consumer complaint and a pressure campaign. Two questions resolve the gray zone better than the label does. Is the information connected to the conduct being discussed, or is it just a way to locate the person? And what does the audience do with it? A post that ends with an address and no reason for including the address is functioning as a doxx regardless of what its author calls it.
Platforms also enforce their own rules here, and those rules are usually stricter than the law, so content can be removable even where nothing illegal happened.
This section describes the sources so you know which to close. It is a defensive map, not a method.
This is the single biggest source and the one most people underestimate. An industry buys, scrapes, merges and resells consumer records: names, current and former addresses, phone numbers, ages, relatives, neighbors and property ownership. Its consumer-facing end is the people-search site, where anyone can type a name and get a profile for free or a few dollars. The records come from public filings, marketing lists, loyalty programs, warranty registrations, credit header data and other brokers. Nobody asked your permission, and in most states nobody had to.
Because these sites rank well in search, one name query often surfaces a usable address on the first page. Almost all of them have an opt-out process, and almost all make it tedious on purpose. Our guide to opting out of Whitepages shows what that looks like, and the pattern repeats across the industry.
Breached databases circulate indefinitely and get combined into searchable collections. An old email address is a pivot point: it links a throwaway handle to a real name, a real name to a phone number, a phone number to a delivery address. Password reuse compounds it, because a credential from a dead service can open a live account that holds shipping addresses and receipts. You cannot un-breach data, but you can break the chain by retiring old addresses that link your identities, not reusing passwords, and turning on two-factor authentication.
Public profiles give up more than their owners think. A gym check-in establishes a neighborhood, a photo out of a window establishes a view, a recurring Tuesday post establishes a routine, a school shirt establishes a school. Friends and family leak information about you even when your own account is locked, especially in tagged photos.
Photo metadata is a related risk. Digital photographs can carry EXIF data including GPS coordinates, device and timestamp. Most large social platforms strip it on upload, so a post on a major network is usually safe from this exposure. Files shared in original form are not: images attached to emails, uploaded to a personal site or forum, or synced through a cloud link can retain everything the camera wrote.
County assessor and recorder databases list property owners and parcel addresses through searchable portals. Voter registration files contain a voter’s name and residential address, with the rules on who may obtain the file, and what they may do with it, varying considerably by state. Court dockets carry names and sometimes addresses. Business registrations list registered agents and principal offices, so if you registered an LLC from your kitchen table, your kitchen table is on file.
You usually cannot delete a public record. You can sometimes change what it points to: use a registered agent or commercial mail address for future filings, and check whether your state runs an address confidentiality program. Several do, typically for survivors of domestic violence, stalking or sexual assault, with eligibility rules that differ by state.
Adjacent registries do the same job. A domain registered without privacy protection may have published your name, address, email and phone, and historical snapshots persist even after you enable privacy later. Licensing boards publish licensee names, nonprofit filings list officers, and old resumes on job boards fill in the rest.
A profile picture used across several accounts links them together, and reverse image search makes that connection trivial to find. Reusing one avatar on a professional network and an anonymous forum is among the most common ways pseudonymity collapses. People are also good at identifying places from background details: a street sign, a distinctive building, a ridge line, a bus route number.
The least technical source is the most reliable one. Someone calls a receptionist to confirm a delivery address, or messages a mutual friend claiming to be organizing a surprise, or poses as a recruiter who needs a phone number to “send the calendar invite,” or calls a customer service line pretending to be you and recites the three details they already have to get a fourth. Pretexting works because people default to being helpful and each question sounds harmless alone.
Related is SIM swapping, where an attacker persuades a carrier to move your number to their device. Most carriers now offer a port-out PIN or number lock. Turn it on.
Motive matters because it predicts what comes next and how long it lasts.
The experience tends to follow a recognizable arc, though intensity varies enormously.
The first wave is volume. Calls from unknown numbers, a flooded inbox, messages on every platform the target uses, and a burst of unsolicited sign-ups as people submit the address and email to mailing lists and subscription forms. Some targets receive deliveries they never ordered. The effect is that a phone and an email address stop being tools and become channels for abuse.
The second wave is escalation to the physical world. Unwanted visitors, notes, vandalism, and in the worst cases swatting, where someone files a false emergency report designed to send an armed police response to the target’s home. Swatting is dangerous to everyone involved, including responding officers, and the FBI has established a national database for tracking swatting incidents so local agencies can connect cases across jurisdictions. Not every doxx escalates this far. Enough do that the risk cannot be waved away.
The third wave hits work. Employers get emails. Clients get tagged. Review profiles get hit. Licensing boards receive complaints. Even when the accusations are baseless, the volume is a burden an employer may resent, and some targets lose income for reasons unrelated to whether the claim was true.
Then comes persistence. The original post is deleted and reappears elsewhere. Screenshots outlive the source. Archives keep copies. Search results for the target’s name reorganize around the incident, so anyone who looks them up sees the campaign rather than their work. This is the phase that turns an acute incident into a long-running online reputation management problem, because removal at the source does not clean the mirrors, the aggregators or the search results that picked it up.
Underneath all of it sits security risk. Exposed details feed identity theft, credential stuffing and targeted phishing, and password reset flows built on personal knowledge questions become weak points once the answers are public. Targets frequently change numbers, rebuild account security, and in severe cases move.
Then there is the part that shows up in no log: the anxiety of not knowing who has your address, the hypervigilance about the front door, the effect on partners and children who did not sign up for any of it. People working through the practical checklist routinely underestimate how much of the damage is this.
It depends on the conduct, the state and who was targeted. No single federal statute in the United States makes doxxing a crime by that name. Federal charges generally rest on statutes written about interstate stalking, threats and harassment, so the facts have to fit those statutes. A number of states have passed laws addressing publication of personal information with intent to intimidate, and several protect specific groups such as judges, law enforcement officers and health workers. Civil claims may also exist depending on what was published and what followed. Separately, virtually every major platform bans doxxing in its terms of service.
Because the law is uneven, we cover it in depth in a companion guide on whether doxxing is illegal and what US law actually says. That piece is general information, not legal advice, and anyone with a live situation should speak to a lawyer licensed in their state.
You cannot make yourself unfindable, but you can make yourself expensive to find, which deflects most attempts, because most doxxing is opportunistic rather than determined.
This is the highest-yield work. Search your name, your name plus your city, your name plus a former city, and your phone number, then list every people-search result showing real information about you and work through each opt-out. Expect a few hours, expect email confirmations, and expect to repeat the check in six months, because records get re-ingested from upstream sources.
Our guide to removing your address from the internet walks through this in order and links to the opt-out processes for the major sites.
California residents have an extra route. Under the state’s Delete Act, the California Privacy Protection Agency runs the Delete Request and Opt-Out Platform, known as DROP, which lets a verified resident file one deletion request that registered data brokers must honor. Consumers have been able to submit requests since January 1, 2026, and registered brokers became obligated to process them from August 1, 2026. It does not cover every company holding data about you, but it replaces a great deal of manual opt-out work with a single request.
Google offers a “Results about you” feature that finds search results containing your personal contact information, lets you request removal, and can notify you when new ones appear. Its published policy covers your address, phone number and email, government identification numbers, bank or card numbers, images of your signature or identity documents, private records such as medical records, and confidential credentials. It also covers doxxing content specifically: results pairing your personal information with explicit or implicit threats or calls to harass you, or aggregating a significant amount of personal information without a legitimate purpose. Removal from search is not deletion at the source, and Google weighs whether content is newsworthy, so requests are not automatic. It is still one of the highest-leverage buttons available, because most people find you through search.
|
Check |
What you are looking for |
How often |
|---|---|---|
|
Your full name, and name plus city |
People-search listings, old profiles, anything with an address |
Quarterly |
|
Your phone number and personal email |
Leaked contact details, forum posts, marketplace listings |
Quarterly |
|
Reverse image search of profile photos |
Accounts you thought were unlinked |
Twice a year |
|
Domain WHOIS and business filings |
A home address sitting in a public register |
Annually |
Prevention advice is cold comfort once your address is on a message board. The priorities change: capture evidence before the poster deletes it, secure accounts before anyone tests the exposed details, report to every platform involved, decide whether to contact law enforcement, get ahead of the conversation at work or school, then start the slower removal and suppression work.
We set that out step by step in what to do if you get doxxed, organized around the first forty-eight hours and the weeks after. Work through it in order, and do not delete your own accounts before screenshotting what you need, because that destroys your evidence along with the abuse.
Being doxxed means your private identifying information, typically your real name, home address, phone number or workplace, has been published online without your consent, usually so others can find, contact or harass you. “Doxed” is an equally accepted spelling.
To dox someone is to research their personal details and publish them to an audience without permission. The defining elements are aggregation into a profile and publication to people who can act on it. Looking someone up privately is research. Posting what you found is doxxing.
Frequently, yes, if the username has been reused. A handle carried across a gaming account, a forum, a marketplace listing and an old blog builds a chain that ends at a real name.
Not by itself. It does nothing about broker records, public filings, cached pages or screenshots already in circulation, and it can destroy evidence you may need. Lock accounts down first, preserve what documents the abuse, and delete only deliberately.
It varies by channel. Platform takedowns of clearly violating content can move in days. Broker opt-outs take weeks, with a real chance of records returning. Search removals depend on policy fit, and suppressing what still ranks takes months. Anyone promising total erasure on a fixed timetable is overselling.
No. This guide describes where exposure comes from so you can close it, and nothing here is a method for targeting anyone.
Doxxing works because modern life scatters small pieces of you across brokers, registries, platforms and old accounts, and because assembling those pieces takes less effort than protecting them. The word is unsettled, spelled dox, doxx, doxing or doxxing depending on who is writing, but the conduct is consistent: collect, aggregate, publish, and let an audience do the rest.
Exposure is a maintenance problem more than a technical one. Opting out of people-search sites, keeping identities separate, hardening account recovery, using the removal tools that exist and watching what you and your circle publish will not make you invisible, but they close the easy paths, and the easy paths are the ones almost everyone uses.
If your information is already out there, sequence matters more than speed: preserve evidence, secure accounts, report, then remove and suppress. And if search results for your name have reorganized around an incident rather than your work, that is a reputation problem as much as a security one, and it responds to sustained effort rather than a single takedown.