Unmask Website Visitors: What Happens After the Match
Identification is the cheap half. Everyone buys it. Far fewer finish the job.
To unmask website visitors means resolving anonymous sessions into identified people you can actually contact, using an identity graph rather than guessing from IP addresses. You install a script, it resolves the identifiers a session carries against a provider's person-level records, and the sessions it can resolve come back as profiles with contact details. The part that decides whether any of it earns money happens after the match: what you know about that person, where the record lands, and how fast somebody acts on it. Identification is the cheap half. Everyone buys it. Far fewer finish the job.
Last updated: September 2026
Everyone knows the pitch, few know the failure mode
The pitch is easy to repeat. Most of your traffic leaves without converting, those people were real, and if you knew who they were you could follow up. All true.
What most people don't realize is that the failed deployments in this category have almost nothing to do with match quality. Teams buy identification, switch it on, watch names start appearing, and then the project quietly dies. Not because the matching was wrong, but because a list of identified strangers is not a pipeline. It is homework.
Three things separate the deployments that work:
- The matched record arrives with enough attached detail to decide what to do with it.
- It lands somewhere a human or a workflow will see it the same day.
- Somebody owns the follow-up and has agreed in advance what it says.
Miss any one of those and you have bought a very expensive report. The website visitor identification entry covers the category terminology, but the terminology is not the hard part.
Identification and enrichment are two purchases
A match returns an identity. That is less useful on its own than it sounds.
Suppose your pixel resolves a session to a real person with an email address. What do you do next? You do not know their household profile, their financial attributes, what else they have been shopping for, or whether they look anything like your existing buyers. You have a name and no basis for a decision.
Enrichment is the step that closes that gap: appending demographic, behavioral, financial, and contact fields to the matched record so it arrives ready to route. The difference in practice is between a lead your team has to go research and one your segmentation rules can act on automatically. If you are mapping how those two layers stack, visitor id plus enrichment is the direct treatment.
Exact Match's product record describes both sides sharing the same identity graph: Site ID for unmasking anonymous traffic and returning full contact and demographic profiles, sitting on a graph the record puts at 250M+ verified U.S. consumer profiles and 80,000+ targeting clusters across 9 data domains, with matching described as deterministic rather than probabilistic and verified against multiple identity anchors including name, email, phone, and address. The record states that graph "refreshes daily". Whichever vendor you use, ask whether identification and enrichment come from one graph or two stitched together, because the seam is where records go stale and contradict each other.
Be honest about the ceiling
You will not unmask everyone, and planning as though you will is how these projects get killed in their second quarter.
Exact Match's record puts Site ID at 25-40% of verified human visitors, bots excluded. Worth internalizing because the denominator is the claim: a percentage without its noun is not a number you can plan against.
Even at a healthy match rate, run the arithmetic before you build a forecast on it. Ten thousand monthly sessions at the top of that range is a few thousand identified people, and a meaningful share of those will be existing customers, current job applicants, competitors, and your own staff. The genuinely new, genuinely commercial subset is smaller than the headline, and it is the only part that matters.
That is not an argument against doing it. It is an argument for sizing it correctly, because a channel that gets sold as ten thousand leads and delivers four hundred good ones gets cancelled, while the same four hundred sold honestly gets renewed.
Suppress before you spend
The single highest-value step in this workflow is the one nobody demos: subtracting people you should not contact. Where they charge on matched volume, suppression makes the headline number smaller, so it tends not to feature in the pitch.
Before a matched record reaches anybody, filter out current customers, open opportunities already in sequence, recent unsubscribes and opt-outs, and anyone your team spoke to in the last 30 days. Emailing an existing customer a cold "I noticed you visiting our site" message is worse than not running the program at all, and it is the fastest way to lose internal support for it.
This is ordinary list hygiene and it is where an existing identity layer pays off, since deduplicating a matched record against your CRM is the same matching problem you already solved when you cleaned your database. Do it once, as a gate in the pipeline, not as something the sales rep is expected to remember.
Decide what happens in the first hour
Speed matters more here than in almost any other list you work, because the entire value of the signal is that it is fresh. Somebody looked at your pricing page today. In a week, that is trivia.
Three routes are worth setting up before you turn anything on:
High-intent, low-volume. Pricing page, demo page, comparison pages. These go to a human, same day, with a specific reference to what brought them in. Small enough volume to be handled properly.
Mid-intent, higher volume. Product and solution pages. These go into a nurture sequence keyed to the topic of the page, not a generic newsletter.
Everything else. Suppressed or held for audience building. A person who read one blog post is an audience member, not a lead, and treating them as a lead is how you burn the domain.
The one thing not to do is send it all to one inbox with a rule that sorts it into a folder. That is the default configuration and it requires no decisions, and that's why so many of these end up unused.
What to measure, and what to ignore
Ignore match rate after the first month. It tells you about your traffic mix, not about your program, and once it stabilizes it will not move much.
Track instead: how many matched records survived suppression, how many got contacted inside 24 hours, reply rate against your normal cold baseline, and pipeline sourced from matched sessions. That last one is the only number that will be asked about at renewal.
Set the baseline before launch. You cannot prove an increase against a number you never recorded, and "it feels like it's working" does not survive a budget review. For the vocabulary around the pre-match side of all this, the anonymous visitor identification entry is a useful reference, and the mechanics of the tag itself are covered in visitor identification pixel.
Frequently Asked Questions
Is unmasking website visitors legal in the United States?
It is a regulated activity rather than a prohibited one, and the answer depends on your state coverage, your disclosures, and your consent mechanics. State consumer privacy laws govern how personal information is collected, sold, shared, and deleted, and they carry access and opt-out obligations you inherit. Ask your provider what legal basis they rely on and exactly what they expect you to disclose, then have your own counsel confirm it before launch rather than after the first complaint.
What percentage of visitors can actually be unmasked?
It varies by provider and much more by your traffic mix. Exact Match's product record puts Site ID at 25-40% of verified human visitors with bots excluded. Treat any published range as a starting estimate, not a commitment: email-driven and returning traffic resolves at a far higher rate than cold paid social, because those visitors arrive carrying identifiers. Measure your own rate over a full month before building a forecast on someone else's average.
Should I email someone just because they visited my website?
Not without suppression, relevance, and a real reason to reach out. Cold outreach that opens by announcing you watched them browse reads as surveillance and performs accordingly. The version that works references the problem the page was about rather than the visit itself, and it never goes to an existing customer, an active opportunity, or anyone who has opted out. Build those filters before you send anything.
Can I unmask visitors without a pixel on my site?
Not in any way you should rely on. Some approaches attempt identification from server logs or IP ranges alone, which in practice resolves to a company or an internet service provider rather than a person. Person-level identification needs identifiers observed in the session and resolved against a graph, and that means a script on the page. A vendor claiming person-level results with no tag deserves a very specific question about how.
How is this different from retargeting?
Retargeting shows ads to an anonymous audience you never identify. The person stays a cookie or a device identifier, and your only available action is buying more impressions. Unmasking produces a named record with contact details, so you can also email, call, add to a nurture sequence, or suppress them from spend entirely. Different mechanism, different cost structure, different privacy obligations, and they are often run alongside each other rather than as alternatives.
Get Started: Unlimited
One plan, everything included: every product, every feature, and unlimited credits. $999/mo, or $6,999/yr on annual billing.