Skip to content
32 min readByBob Thordarson

Anonymous Website Visitor Identification for B2B: The Complete 2026 Guide

Anonymous website visitor identification turns a fraction of your invisible B2B traffic into named buyers. This complete 2026 guide covers how it works, person-level vs company-level, the match rates vendors won't verify, how to route identified buyers into your CRM, and when it's actually legal to email them.

Isometric diagram of a B2B website funnel where anonymous visitors pass an identification layer and a small subset resolves into named profiles.

Key benchmarks at a glance

2026 B2B Website Visitor Identification Vendor Match Rate Claims · 2026

MetricFigures
Highest published person-level match rate claim55%Claims run from 15 percent (Clearbit/Breeze) to 55 percent (Happierleads). RB2B publishes 40-45 percent, Common Room up to 50 percent, Bullseye up to 40 percent.
Highest published company-level match rate claim80%Happierleads publishes 80 percent or more, Demandbase 77 percent measured on its own site, Bullseye up to 70 percent, Warmly about 65 percent for US traffic.
Vendors compared11Eleven B2B visitor identification vendors with a published or third-party-estimated match rate, including one, Lead Forensics, that declines to publish a number.

Last updated: September 2, 2026

Anonymous website visitor identification is the practice of matching an unknown business visitor to a real person or company using an identity graph, then enriching and routing that contact into a CRM. Also called website deanonymization, it resolves a fraction of otherwise-invisible traffic into named buyers with firmographic and contact data your sales team can act on.

The pitch behind the category is real, and it's also routinely oversold. Most of your website traffic never identifies itself. According to Twilio Segment, around 98% of website visitors are anonymous, and 6sense reports that only about 3% of B2B visitors ever fill out a form. That gap is the entire reason the category exists, and on the arithmetic alone it's a compelling one: if 98 out of every 100 visitors leave no trace and only three of them would ever have filled in a form, then almost everything you paid to attract is invisible to you.

What I didn't expect, when we started pulling vendor documentation for this series, was just how far apart the tools are on match rate. Published claims run from 15% to 80%. We found the same product advertised at four different rates depending on who was doing the advertising.

This guide covers how identification works, what "person-level" versus "company-level" really buys you, the match rates you can trust versus the ones you can't, how to move an identified visitor into your pipeline, and the part most vendors skip, which is when it's actually legal and safe to email the people you identify. Where a topic deserves its own deep dive, it links to the dedicated post. If your traffic is consumer ecommerce rather than B2B, the mechanics differ enough that they get their own treatment in our ecommerce visitor identification guide; this guide is the B2B version.

KEY STATS

  • Around 98% of website visitors are anonymous and never identify themselves (Twilio Segment, 2026)
  • Only about 3% of B2B website visitors fill out a form (6sense, 2022)
  • Person-level identification of US B2B traffic realistically lands at 15-20%; published vendor claims run as high as 55% (compiled from vendor documentation, July 2026)
  • Independent testing across 12 platforms puts realistic person-level identification at 5-20% (MarketBetter, 2026)
  • Company-level identification commonly resolves 30-65% of US business traffic, with published claims reaching 80% (compiled from vendor documentation, July 2026)
  • One product, RB2B, is currently published at four different person-level rates — 8-15%, 10-20%, ~30% and 40-45% — depending on who is doing the publishing
  • The CCPA/CPRA business-to-business data exemption expired January 1, 2023 — a California resident's work email is now regulated personal information (IAPP, 2023)
  • Consumer mailbox providers require senders to keep spam-complaint rates under 0.3% or risk blocking (Google, Yahoo, Microsoft bulk-sender rules, 2024-2026)
  • Data sourced from vendor documentation, published match-rate disclosures, and primary regulatory guidance, compiled July 2026

What's in this guide:


What is anonymous website visitor identification?

Anonymous website visitor identification connects a website session with no login, no form fill, and no known cookie to an actual identity — either the company the visitor works for or the individual person. It sits between two things marketers already understand: Google Analytics, which counts anonymous sessions, and Salesforce or HubSpot, which hold known contacts. Identification tries to move a session from the first bucket into the second.

Three terms get used interchangeably: tracking, identification, and identity resolution. Website visitor tracking records what an anonymous visitor does: pages viewed, time on site, return visits. Visitor identification, sometimes called website deanonymization, resolves who that visitor is. Identity resolution is the broader data-science discipline of stitching fragmented records into one profile, and it powers identification under the hood.

Most identification tools do all three. They track behavior, resolve identity, and hand you a contact. Accuracy and legal footing then differ sharply depending on how far up that chain a tool actually reaches.

For B2B specifically, the useful output is a named person at a target company, ideally with a verified work email and enough firmographic context to know whether they're worth a sales touch.

An identification is worth something to me only if it's accurate, the contact is reachable, and contacting them is legal.

Miss any one of those three and you've added a row to a database, not a lead to a pipeline.

What is website deanonymization?

Website deanonymization is another name for visitor identification: the process of resolving an anonymous website session to a known company or person. It combines a tracking pixel, an identity graph, and enrichment to attach a name, company, or work email to a visitor who never identified themselves. The term is used interchangeably with anonymous visitor identification.


How anonymous website visitor identification works

Every identification tool runs the same basic loop. Capture a signal from the visitor, match that signal against a graph of known identities, and return whatever the match yields. The differences between vendors come down almost entirely to which signals they're able to capture in the first place and, more importantly for buyers, how precisely they're willing to describe what the resulting match actually produces.

The identity graph

The engine behind identification is an identity graph, a large database that links identifiers belonging to the same person or company. Cookies, device fingerprints, IP addresses, hashed emails, and login events all become nodes, and the graph draws edges between the ones it believes belong together. When an anonymous visitor lands on your site, the tool grabs whatever identifiers it can reach in the browser, hands them to the graph, and asks the only question that matters: who does this belong to?

Two properties determine whether a graph is worth querying. How fresh it is, and where it came from. Both decay, constantly.

People change jobs, so a work email that mapped to one company last quarter maps to a different one now. Estimates of how fast that happens vary. HubSpot's decay model, built on MarketingSherpa research, puts B2B contact data at 2.1% lost per month, or 22.5% a year, while ZoomInfo's own analysis says 25-30%.

They disagree by roughly a third, but both imply that about a quarter of what any graph knows about your market goes wrong within a year. We assume that decay rather than argue with it, and we re-verify rather than trust the age of a record.

Cookies get cleared and blocked. Fingerprints drift. A graph assembled from a broad publisher co-op will usually reach a good deal more people than one built from a narrow set of first-party sources, and it will carry correspondingly more stale records, more mismatched records, and more people who left the company the graph still believes they work for.

That trade-off is why we don't buy third-party data for Signal, and it's the thing I'd push hardest on in a vendor call. When you evaluate a tool, the age and sourcing of its graph tells you considerably more than the raw size they advertise. Post 3 breaks the identity graph down node by node.

Node-and-edge diagram of an identity graph linking one person to a work email, hashed email, device fingerprint, IP address, cookie and LinkedIn.

Deterministic vs probabilistic matching

Matching happens two ways, and the difference explains almost every match-rate dispute in the category.

Deterministic matching links records on exact, verified identifiers. A hashed email appearing in both your data and the graph is a deterministic match, meaning two records that provably belong to the same person. It's accurate because it rests on known facts rather than inference, and it's the backbone of any identification you can actually trust for outreach, which is why I'd rather quote you a small deterministic number than a large blended one.

Probabilistic matching infers a link from statistical signals like IP address, device type, location, and behavior, then decides that two anonymous touchpoints are probably the same person. It reaches far more traffic, because it never needs a shared verified identifier. It's also wrong far more often. A probabilistic match can return the right household but the wrong person, or the right company but the wrong employee, or a name so plausible that nobody on your sales team will think to question it right up until the moment they use it in a first line and get corrected.

Neither method is misleading on its own, and we use both. Probabilistic signals are genuinely useful for prioritization. A probabilistic signal can move a visitor up our priority list; it never becomes a name we put in front of your reps.

That rule costs us a higher advertised match rate. A vendor that counts probabilistic guesses as identifications can advertise reach we can't match, and on the same traffic ours will read lower than theirs.

The misrepresentation happens when a vendor blends the two, counts every probabilistic guess as an identification, and quotes the combined figure as though it were all deterministic.

That blend is the mechanism behind most inflated match rates, and it's also why the reach number a vendor leads with so rarely survives contact with your actual traffic. Ask any vendor, us included, to split the figure into its deterministic and probabilistic halves before you put two of them side by side.

The pixel

Identification starts with a snippet of JavaScript, a pixel, that you install on your site — usually through Google Tag Manager, which is exactly where most teams lose track of what is firing and on which pages. The pixel collects identifiers and sends them to the vendor's graph.

This is also where the legal footing begins, and it's the detail I most often find teams have skipped entirely.

It's also where I'd start a compliance review, and where we started ours. I can't tell you what your obligations are. But "what does our pixel do when Global Privacy Control is switched on?" has a specific answer, and every team I've put that question to went away and looked it up.

The pixel is the moment of data collection, and consent obligations attach at collection rather than at the moment you decide to email someone.


Person-level vs company-level identification

The single most important question to ask any vendor is whether they identify the company or the person. Those two things aren't close substitutes, and the marketing blurs them constantly, which means a demo can leave you believing you bought named buyers when what you actually bought was a list of logos with a guess attached to each one.

Company-level identification maps a visitor's IP address to the organization they work for. You learn that someone at Acme Corp visited your pricing page. You never learn who.

This is the older, more established, and more defensible form — it's what Leadfeeder and Lead Forensics have done for years — and its match rates run higher, because mapping an IP to a company is a much more tractable problem than naming an individual.

Person-level identification returns the individual: a name, often a work email, sometimes a LinkedIn profile. It's far more valuable when it's right, considerably riskier legally, and much harder to do at volume. All three of those are true at once, which is what makes the category hard to buy in.

Much of what gets sold as "person-level" is company-level data with a probabilistic guess bolted on, or a blend that quietly averages the two together to inflate the headline. Post 6 covers exactly how to tell the difference in a sales demo.

My rule of thumb, and I apply it to us too: if a vendor quotes one match rate without separating company from person, assume the person-level portion is much smaller than the number they led with.

There's a real reach-versus-identity trade-off here that no tool escapes, including ours. The more of your traffic a method covers, the less it tends to know about each visitor. Company-level identification is wide and shallow, person-level is narrow and deep, and a voluntary form fill is the narrowest and deepest of all. Working out where a tool sits on that curve will usually tell you more than any single percentage.

Trade-off chart plotting reach against depth for four visitor identification methods, from high-reach reverse-IP lookup to high-depth form fills.


Match rates: what's real vs what's marketed

Match rate is the percentage of your anonymous traffic a tool can identify. It's the most important number in the category and easily the least reliable, because almost no two vendors define it the same way, the definition is rarely published anywhere near the number, and none of them will let you verify the figure against your own traffic before you've already signed something.

We pulled everything in the table below from vendor documentation, vendor comparison pages, and third-party testing in July 2026, quoted exactly as published.

Eleven rows here, not the fifteen vendors Post 4 compares. I kept the ones publishing a person-level figure with a source I could point at, because a short table I can defend line by line beats a long one padded out with vendors whose numbers I inferred.

VendorPublished person-level claimPublished company-level claimIndependently verifiable?
Happierleads30-55% of B2B sessions80%+Vendor-stated
Common Room (with Vector)Up to 50%, US trafficVendor-stated
RB2B40-45%, Pro plan, unique US traffic30-35%Vendor-stated
BullseyeUp to 40%Up to 70%Vendor-stated
Vector35% on a partner page, 15-30% in its own materialsLabels verified vs inferred
Instantly (TrafficID)~30% of total visitorsCites one 14-day test
ZoomInfo WebSights15-30%50-60%Third-party estimate
Warmly15-25%, averaging ~15%~65% USSelf-reported
Clearbit / Breeze15-20%40-65%Third-party estimate
DemandbaseUnder 30% per third parties77% on its own siteWarns rivals inflate
Lead ForensicsNo number publishedCompany-level onlyOffers a trial on your own traffic

The takeaway: Published person-level claims across these eleven vendors span 15% to 55%, while the same vendors' company-level claims run from 30% to more than 80%. Only Lead Forensics declines to publish a figure, offering a trial on your own traffic instead. Every other number here is vendor-stated or a third-party estimate, and none of them can be checked before you sign.

Three patterns showed up once we knew to look for them.

The highest numbers are usually two numbers added together. RB2B's own documentation lists person-level at 40-45% and company-level at 30-35%, then describes overall identification as 70-80% — the sum of the two, on a page that also states they're independent processes. Roughly half of that headline is "a company visited," which isn't something you can email.

Vendors disagree about each other far more than they disagree about themselves. RB2B is currently published at 40-45% by its own docs, about 30% by Bullseye, 10-20% by MarketBetter's independent test, and 8-15% by Warmly. Same product, same year, a factor-of-five spread. I checked that one twice, because I was certain I had misread a decimal. Every published table happens to be lowest where the publisher has least to gain.

The most defensible answer we found was a refusal. Lead Forensics declines to publish a headline rate at all and offers a trial on your real traffic instead. That is an inconvenient position for a marketing team, and it's the only one on this list a buyer can actually test.

It helps to understand why the ceiling sits where it does.

To resolve a US B2B visitor to a named person, the graph needs a recent, verified link between something on that visitor's browser and a real contact record. Most anonymous sessions never carry one. The visitor browses in Safari, where Intelligent Tracking Prevention is on by default, or sits behind a locked-down corporate laptop, or works from home on a residential Comcast line that maps to no company at all, or has never touched the publisher network the graph was built from.

So a deterministic person-level rate in the teens isn't evidence of a weak product. A vendor claiming to deterministically name half of your anonymous traffic is either counting company matches as people or counting guesses as facts.

"The problem with most intent data is that it tells you something happened but not whether it matters. A company visited your website. Okay. Is that a warm lead or someone who clicked the wrong link?" — Jon Dick, SVP of Marketing, HubSpot (LinkedIn)

One more trap worth knowing about before you benchmark anything. Consumer ecommerce identification tools publish far higher figures — Opensend at up to 73%, Customers.ai at 65-85%, and LiveRamp at 99.5% on full PII with a complete address, independently measured by Comscore. Those are real numbers for a much easier problem, because consumer graphs are denser and built on identifiers that barely move. A B2B buyer who anchors on them will find every accurate B2B quote disappointing, ours included.

The right way to read a match-rate claim is to demand three things: the definition, the split between company and person, and a way to test it on your own site.

Post 4 is a full teardown of how match rate is calculated, compares the published claims of 15 B2B vendors side by side, and includes a five-step self-audit you can run on your own traffic in an afternoon. If a vendor resists all three of those requests, and that absolutely includes us, I'd treat the number as marketing.


Intent data vs visitor identification

Visitor identification is often sold alongside intent data, and the two get conflated even though they answer different questions. Identification answers "who's this visitor?" Intent data answers "which accounts are showing buying signals?" — usually by tracking content consumption somewhere other than your own site, whether that is Bombora's publisher co-op or review traffic on G2 and TrustRadius.

Third-party intent data has a credibility problem that people inside the industry are increasingly willing to name.

"I have spent 15+ years building B2B databases. Let me share an uncomfortable truth: much of B2B intent data is fundamentally flawed. Why? Because most of this data is built from B2C traffic and a consumer context." — Santosh Sharan, B2B data executive (LinkedIn)

I agree with him, and it's a large part of why we built Signal around first-party signals instead. What someone does on your site beats third-party intent inference for reliability, because you observed the behavior directly rather than buying a guess about it.

A first-party signal can't tell you an account is in-market before it ever visits you, which is precisely what Bombora and 6sense sell. We traded the early warning for a signal I can always trace back to a specific event on your own site. Identification turns that first-party signal into a contact you can act on. Post 5 covers intent data in depth, including where it really helps and where it's an expensive way to feel busy.


Identification after third-party cookies

The ground under identification did shift, though not in the direction the category spent five years predicting. Safari and Firefox block third-party cookies by default and have done for years. Chrome never did. Google promised removal from 2020 onward, then reversed on April 22, 2025 and kept third-party cookie choice exactly where it was.

So the accurate 2026 summary is not that third-party cookies are disappearing. Chrome and Edge together run about 74% of browsers worldwide against Safari's 16% and Firefox's 3%, which means third-party cookies keep working on roughly four visitors in five and fail silently on the fifth. That is a considerably more awkward problem than deprecation would have been. A signal that dies on a published date can be engineered around; a signal that works on most of your traffic and quietly fails on the rest biases every number you build on top of it, and nothing in your dashboard tells you which visitors went missing.

First-party, server-side identification collects signals on your own domain and resolves them server-side rather than leaning on a browser cookie that may not survive. It's more durable and more private, and generally more accurate for the visitors it does catch, because it's anchored in data you already own.

That is the bet we made with Signal, and I'll admit it costs us reach: a first-party graph can't see traffic that never interacted with you in the first place, so every visitor arriving cold and leaving cold stays invisible to us in a way it wouldn't to a vendor renting a publisher co-op. We think that trade is worth it. Not everyone will agree.

Post 8 is the technical playbook for first-party and server-side identification. The strategic point for this overview is that a tool's long-term match rate depends heavily on whether its graph is built on borrowed third-party data or on first-party signals it can keep.


From identified visitor to pipeline

Identification only pays off once the contact reaches the person who can act on it, in the system they already work in, with enough context to move. Until then you own a list. Identification that stops at a CSV export changes nothing about your pipeline, which is why Post 9 treats routing as a build step rather than a follow-up.

Good routing does a few unglamorous things well. It deduplicates against contacts you already have, assigns the new contact to the right owner, scores it so reps chase the visitors worth chasing, and drops it into Salesforce, HubSpot or Bullhorn automatically.

Post 9 covers routing mechanics in detail, including a distinction most tools ignore, which is separating buyers from non-buyers before anything hits your pipeline. A staffing firm's website, for example, gets visited by both potential clients and job seekers, and dropping a candidate into the sales queue in Bullhorn rather than the candidate pipeline wastes the whole exercise.

We don't sell you the sending layer. Getting a contact into your system correctly is routing. Deciding whether and how to email that contact is a separate question with its own risks, and it's where I see most teams get into real trouble.


Should you email identified visitors?

This is the highest-stakes decision in the category, and it deserves its own dedicated cluster in this series (Post E1, E2, and E3 go deep). Many teams skip straight to sending and regret it.

Identifying a visitor touches your data stack and nothing else. Emailing the people you identify concentrates three separate risks that identification on its own never carries, and each one can outlast the campaign that caused it.

The first is sender reputation. Emailing people who never asked to hear from you generates spam complaints, and the founder of Retention.com has acknowledged complaint rates around 5% from identified contacts against a roughly 0.04% benchmark for opted-in ecommerce lists. Complaints at that level poison deliverability for the real, permission-based list you spent years building, and the damage doesn't stay neatly inside the campaign that caused it.

The second is your email service provider's own rules. Klaviyo, Mailchimp, and most ESPs prohibit emailing contacts who didn't opt in, and they suspend accounts that do it. "Just feed the contacts into your ESP" is advice that can get your account shut down.

The third is legal basis. Whether you're allowed to email an identified visitor depends on who they are and where they happen to live, not on whether their address is sitting in your dashboard. Possession isn't permission.

A defensible default falls out of those three risks. It's the one we recommend to our own customers even where it costs us usage, and it absolutely costs us usage every month.

Email only high-intent visitors, prefer named people at company domains over personal consumer addresses, and never route identified contacts through the ESP that carries your permission-based list. Post E3 covers how to send safely without torching your domain, including the difference between sending from your primary domain and an isolated one.


Legality splits into two questions that are easy to conflate and important to keep apart. Is it legal to identify a visitor, and is it legal to email the person you identified?

Identifying and tracking is governed primarily by privacy law at the point of collection. Under CCPA and CPRA, a California resident's data is regulated personal information, and since the business-to-business exemption expired on January 1, 2023, that now includes work email addresses collected in a B2B context. The obligations attach to your identification pixel rather than to your outbound sequence, which means notice at collection, honoring opt-outs, and respecting browser signals like Global Privacy Control are all your problem from the moment the script loads. Post 10 covers pixel and tracking consent in full.

Emailing is governed separately. In the US, CAN-SPAM permits commercial email on an opt-out basis, so you may send without prior consent provided your headers are accurate, you include a physical address, and you honor unsubscribes promptly. CAN-SPAM never distinguishes between a work email and a personal one.

Europe and the UK absolutely do. Under PECR and GDPR, a named employee at an incorporated company can often be emailed under legitimate interest, while individuals, sole traders, and consumer email addresses generally require consent. Post E2 covers email consent in depth, including the "shared terms" model where a site's cookie and terms-of-service acceptance is asserted as consent to be emailed. Some vendors promote that approach. I'd understand it very carefully before relying on it.

None of this is legal advice, and I'm certainly not a lawyer. The real answer to "is it legal?" is that it depends on the recipient, the jurisdiction, and your setup.

The teams I've watched stay out of trouble all treat identification and emailing as two separate consent decisions, and they run both past counsel before scaling.

We're doing the same thing with this series. The three email posts coming after this one carry the actual legal claims, and I'm holding them until a privacy lawyer has read them. If you're making this decision now, that is the one part I wouldn't take from a blog post — mine included.

What surprised me building Signal was how many tools will hand you a contact you have no legal right to email, and how rarely anyone mentions it. The match rate gets three paragraphs on the pricing page; the fact that a chunk of those contacts are personal Gmail addresses belonging to people in jurisdictions where you need consent gets a footnote, if that. So we made a specific choice: validate the email, route it into the tools you already run, and flag consumer-domain addresses separately instead of quietly counting them as B2B contacts. It makes our number smaller. It also means the number survives a customer checking it. — Bob Thordarson, Geysera CEO


Is there free visitor identification?

Yes, with limits worth understanding. Several tools offer a free tier, and the free versions are almost always company-level only. RB2B's free plan, for example, historically surfaced company-level data, with person-level identification reserved for paid tiers. Free reverse-IP tools will tell you which organizations visited at no cost, because IP-to-company lookup is cheap to run at scale.

What is rarely free is person-level identification with a validated email. That is the expensive part, because it requires an identity graph, enrichment, and email verification through a service like ZeroBounce or NeverBounce, all of which cost the vendor money per contact. We pay for all three, which is exactly why our own free tier stops where it does.

When a tool advertises free person-level identification, read the terms closely. Usually it's a capped trial, a small monthly allotment, or a plan that returns unverified emails you must then clean yourself. Free is a perfectly good way to see whether identification produces anything useful on your traffic before you pay. It's exactly how I'd use it, and how I tell prospects to use ours.


Who it's for, and how to choose a tool

Anonymous website visitor identification earns its keep for businesses that have both enough qualified traffic to produce a usable number of identifications each month and a real sales motion already staffed to act on them. It works best when a single identified buyer is worth a lot, which in practice means recruiting and staffing firms, M&A advisors, and professional services with long sales cycles. It also depends on already running an outbound or account-based motion that a steady stream of warm contacts can feed.

If nobody is going to work the leads, identifying them changes nothing at all, and I'd much rather tell you that before you buy anything from us.

When you evaluate tools, weigh them on five things the marketing tends to obscure.

Whether they identify the person or just the company. Whether they will let you verify the match rate on your own traffic. Whether the email addresses they return are validated for deliverability. How many of the contacts still hold the job the tool says they hold. And whether they route cleanly into the Salesforce, HubSpot or Bullhorn instance you already run without forcing you into their own sending suite.

That fourth one is the step almost nobody runs, and it's precisely the difference between a match rate and a usable match rate.

Sample 100 identified contacts during a trial, check that the email is deliverable and the person is still in that role, then multiply your headline rate by the fraction that survives. A 40% rate where half the contacts bounce or have moved on is a 20% tool at a 40% price.

I wrote twenty-five here for months and I was wrong about it. At that size a survival rate coming back at 60% carries a 95% confidence interval of roughly 41% to 77%, which is far too wide to separate one vendor from another — and separating them is the entire job you're doing. A hundred contacts narrows it to about plus or minus nine points. I'm correcting my own advice here so that you don't run the bad version of it on your trial.

We'd much rather lose a deal at that step than at renewal, which is why we always tell prospects to run it on us first. Post 4 walks through the full audit, and Post 7 compares the 2026 tools against these criteria. The best choice is rarely the one with the biggest headline number.

One practical warning about comparison lists, including the ones that currently outrank ours. Several widely-shared 2026 roundups still recommend Koala, which shut down on September 30, 2025 after Cursor acqui-hired its team. If a list is still recommending a product that has been dark for most of a year, its match-rate column deserves exactly the same scrutiny.


Frequently asked questions

What is anonymous website visitor identification?

Anonymous website visitor identification is the practice of matching an unknown website visitor — one who never logged in or filled out a form — to a real company or person using an identity graph, then enriching and routing that contact into a CRM. Also called website deanonymization, it turns a fraction of otherwise-invisible traffic into named leads with firmographic and contact data.

How accurate is website visitor identification?

Accuracy depends on whether you mean company or person level. Company-level identification commonly resolves 30-65% of US business traffic, with published claims reaching 80%. Person-level identification typically lands at 15-20%, despite marketing claims running as high as 55%, and independent testing across 12 platforms puts the figure at 5-20%. The higher numbers usually reflect probabilistic guesses, or company data relabeled as person-level, or the two figures simply added together.

What is the difference between person-level and company-level identification?

Company-level identification maps a visitor's IP address to the organization they work for, so you learn that someone at a company visited. Person-level identification returns the individual — a name and often a work email. Person-level is more valuable when accurate but harder to do, riskier legally, and often overstated by blending in company-level data.

Identifying visitors is generally legal but regulated at the point of data collection. Under CCPA and CPRA, visitor data including work emails is protected personal information, since the B2B exemption expired January 1, 2023. Compliance obligations attach to your tracking pixel: notice at collection, honoring opt-outs, and respecting Global Privacy Control signals.

Can I email visitors I identify anonymously?

Sometimes, and carefully. US CAN-SPAM permits opt-out commercial email, but ESPs like Klaviyo and Mailchimp prohibit emailing non-opted-in contacts and will suspend accounts. Europe and the UK often require consent for individuals and consumer addresses. A safe default is to email only high-intent, named people at company domains, never through your primary ESP.

What is a good match rate for visitor identification?

For company-level, 30-65% is typical depending on your traffic. For person-level, a defensible rate is 15-20% of US business traffic, and one category glossary puts even the best tools at 15-35%. Treat any single blended number above 40% with skepticism, and treat any person-level claim above 80% as a sign the tool is leaning on probabilistic guessing. Ask the vendor to define the metric, split company from person, and let you test it on your own traffic before buying.

Is there free website visitor identification software?

Yes, but free tiers are almost always company-level only. Free reverse-IP tools reveal which organizations visited, because IP-to-company lookup is cheap. Person-level identification with a validated email is rarely free, since it requires an identity graph, enrichment, and email verification that cost the vendor per contact. Free plans are best used to test whether identification produces anything useful on your traffic.

Does visitor identification still work without third-party cookies?

Yes. Third-party cookies did not disappear — Google reversed its Chrome deprecation plan in April 2025 — but Safari and Firefox have blocked them by default for years, so roughly a fifth of your traffic was never reachable that way. Tools leaning on third-party cookies and probabilistic graphs fail on that share silently. First-party, server-side identification resolves signals on your own domain, making it more durable, more private, and more accurate for the visitors it catches.


Continue the Series

This is the pillar guide for Geysera's 13-part series on B2B anonymous visitor identification. Explore the deep dives:


Sources

Bob Thordarson

Co-Founder and CEO

Bob Thordarson is CEO and Co-Founder of Geysera, a serial entrepreneur with 25+ years and five co-founded ventures, including Cequint (acquired by TNS in 2010 for $112.5M) and Consumerware (acquired by ParkerVision). A graduate of the University of Washington and MIT Entrepreneurial Masters Program, based in Seattle, he serves on the boards of DRY Soda Co. and the Entrepreneurs' Organization Seattle chapter. He is an expert in retention marketing email systems and methodology for ecommerce and B2B brands — measured by incremental revenue, not vanity metrics.