Ad tech stocks
TEAD0.60▲ +16.69%CDLX2.68▼ -8.84%186013.51▲ +7.48%PSKY9.59▼ -7.21%U43.38▲ +5.99%APPS11.69▲ +5.32%APP278.40▼ -4.14%STGW8.47▲ +4.06%RDDT147.50▲ +3.55%ZETA32.61▲ +3.29%TRU63.03▲ +3.12%OMC75.56▲ +2.61%SFOR44.85▼ -2.50%IHRT2.15▲ +2.38%INUV0.58▲ +2.38%MNTN10.41▲ +2.36%CCO2.40▲ +2.34%LFTO15.45▼ -2.22%IBTA40.16▲ +1.92%NFLX68.30▼ -1.84%WPP382.90▲ +1.81%CART43.89▲ +1.79%PUBM19.05▲ +1.68%DSP12.51▲ +1.58%ILLM0.66▲ +1.54%SAX35.96▲ +1.41%GOOGL339.26▼ -1.40%SCOR4.75▲ +1.39%SPOT493.77▲ +1.31%SNAP5.47▲ +1.30%035420191200.00▼ -1.29%BIDU85.75▼ -1.29%4755681.70▼ -1.26%AAPL328.95▼ -1.22%AZRN0.82▼ -1.20%ROKU150.53▼ -1.15%SIRI25.60▼ -1.08%PUB95.34▲ +0.87%MGNI25.46▲ +0.79%SST2.64▲ +0.76%47511238.50▲ +0.57%HAVAS17.55▼ -0.57%CRTO15.28▲ +0.53%RAMP37.70▲ +0.47%META728.53▲ +0.46%NEXN9.04▲ +0.44%24331308.00▲ +0.38%CPNG13.83▼ -0.29%0700431.00▼ -0.23%DEC24.68▲ +0.16%TBLA3.35▼ -0.15%SNOW340.01▲ +0.13%PINS18.91▲ +0.08%BABA107.47▼ -0.07%WBD30.93▼ -0.06%TTD12.16▼ -0.04%43243564.00▲ +0.03%OUT27.75▼ -0.02%DV13.49▲ 0.00%PERI8.69▲ 0.00%VER12.08▲ 0.00%
Ticker byClearTrust

Data & identity · also called HEM, hashed email address

Hashed email

A hashed email is an email address transformed by a one-way cryptographic function, usually SHA-256, into a fixed string used to match users across systems without sharing the plain address.

The short answer, from the AdTech Sumo glossary

If two companies both know someone's email, they can each hash it and compare the results: the same email always produces the same hash, but the hash cannot simply be reversed into the address. That makes hashed emails the most common key for matching audiences between advertisers, publishers and platforms.

To match correctly, emails must be normalised first, for example lowercased and with spaces removed, then hashed with the agreed algorithm, typically SHA-256. Hashed emails underpin customer-list uploads to social platforms, conversions APIs, clean rooms and identifiers like Unified ID 2.0 and RampID.

The big misconception is that hashing makes data anonymous. It does not. Anyone holding a list of emails can hash them and match, so a hashed email is still pseudonymous data and personal data under GDPR; US regulators including the FTC have said hashing does not make data anonymous. Hashed emails are also persistent and portable, which is why ID bridging and cross-context tracking concerns attach to them.

Think of it like this

A hashed email is like a fingerprint of your email address: it cannot tell a stranger your address, but anyone who has your address can check if it matches.

An example

"[email protected] " is normalised to "[email protected]" and hashed to a 64-character SHA-256 string; a retailer and a publisher each hash their lists and find 1.1 million matching strings.

Related terms

Sources: Unified ID 2.0, GDPR Article 4: definitions