How to Identify Anonymous Website Visitors: 5 Methods and What Each Actually Delivers
There are five real ways to identify anonymous website visitors, and they deliver wildly different things. This guide walks through each method — reverse-IP company lookup, third-party identity graphs, first-party server-side resolution, form fills with enrichment, and manual LinkedIn matching — with the realistic match rate, cost, and limits of each, so you can pick the one that fits your traffic instead of the one with the loudest pitch.

Last updated: September 3, 2026
To identify anonymous website visitors, you match the signals they leave — IP address, device, behavior, or a hashed email — against an identity graph or your own first-party data. Five practical methods do this, ranging from company-level IP lookup that names the organization to person-level resolution that names the individual, each at a different accuracy, cost, and legal risk.
Identification is five different methods, and most guides on the topic treat it as one.
A tool that identifies 60% of your traffic at the company level and a tool that identifies 18% at the person level are both telling the truth and selling completely different products. If you can't tell which method produced a vendor's number, you have no way to judge whether it's impressive or simply irrelevant to what you need, and I've sat through demos where that distinction never came up once.
So this is the no-black-box version: five methods, what each one actually produces, and the rate I'd expect from each on real US business traffic rather than on the vendor's own carefully-chosen sample. We use four of the five ourselves, and I'll flag which one we sell so you can discount me accordingly. It's the companion to the pillar guide, which covers the category end to end. If you run an ecommerce store rather than a B2B site, the methods weight differently — our ecommerce visitor identification guide covers that side.
KEY STATS
- Around 98% of website visitors are anonymous and never identify themselves (Twilio Segment, 2026)
- Only about 3% of B2B website visitors fill out a form (6sense, 2022)
- Reverse-IP company identification commonly resolves 30-65% of US business traffic, with published vendor claims reaching 80% (compiled July 2026)
- Person-level identification via third-party graphs realistically lands around 15-20% of US traffic, while published claims run as high as 55% (compiled July 2026)
- Independent testing across 12 platforms puts realistic person-level identification at 5-20% (MarketBetter, 2026)
- Form fills identify close to 100% of the visitor who submits, but only reach the ~3% who fill one out (6sense, 2022)
- Data sourced from vendor documentation, published match-rate disclosures, and platform benchmarks, compiled July 2026
What's in this guide:
- The five methods at a glance
- Method 1: Reverse-IP company identification
- Method 2: Third-party identity graphs
- Method 3: First-party server-side identification
- Method 4: Form fills with enrichment
- Method 5: LinkedIn and manual matching
- How to combine methods
- Frequently asked questions
The five methods at a glance
Here are the five methods in one table. The match rates are for US business traffic. They are the working numbers we use internally rather than the marketing headlines, which run higher across every row.
I'd rather hand you the numbers I plan against than the ones I'd put in an ad. Where our own row sits below a competitor's published claim, I've left it there.
| Method | What it identifies | Realistic match rate | Effort / cost | Best for |
|---|---|---|---|---|
| Reverse-IP lookup | Company | 30-65% of business traffic | Low | Knowing which accounts visit |
| Third-party identity graph | Person (name + email) | 15-20% person-level | Medium, per-resolution | Named-contact outbound |
| First-party server-side | Returning and known visitors | Varies; highest accuracy | High setup, low ongoing | Durable, privacy-safe ID |
| Form fills with enrichment | Person (self-identified) | ~3% of visitors, near-100% accurate | Low | High-intent opt-in leads |
| LinkedIn / manual matching | Person | Low volume, high effort | High, manual | Low-traffic, high-value accounts |
The takeaway: Reverse-IP lookup reaches the most traffic, 30-65% of business visitors, but returns only a company name. Third-party identity graphs name an actual person for 15-20% of visitors. Form fills identify roughly 3% at near-perfect accuracy. Coverage and certainty pull against each other across all five methods, which is why most teams end up running two of them together.
Method 1: Reverse-IP company identification
How it works. Every visitor arrives carrying an IP address, and reverse-IP identification maps that address to the organization that owns or leases it, so you learn that someone at a specific company visited your site even though you never learn which person it was. This is the oldest form of visitor identification we have, and it's still the engine behind tools like Leadfeeder and Lead Forensics.
What it delivers. The company name, plus firmographics like industry, size and location, attached to the specific pages that company viewed. You get no individual and no email address, which is the whole reason the other four methods exist.
Realistic match rate. 30-65% of US business traffic, depending on your mix. Published vendor claims go higher — Happierleads advertises 80%+, Demandbase reports 77% on its own site, and Bullseye claims up to 70% — but those are all the vendors' own figures measured on their own traffic.
It works well for visitors on corporate networks with dedicated IP ranges, and badly for remote workers, VPNs and mobile traffic, all of which have grown as a share of business browsing. Remote work has quietly eroded IP-to-company accuracy over the last few years, which is why I treat any 90%+ claim as a prompt to ask what's being measured rather than as a number. Dealfront advertises "over 90%," for instance, but for building advertising audiences rather than for naming the companies on your site.
I only caught that distinction because I clicked through to the page the claim sits on. A comparison table would have handed me the 90% with no asterisk on it, and that is the failure mode worth guarding against.
Best for. Account-based marketing, where knowing a target account is active is enough on its own to trigger a play, and for prioritizing the accounts already sitting in your pipeline. It's also the lowest-risk method legally, because company-level data isn't personal data under most frameworks, and I'd start here if compliance review is the thing slowing you down.
The limit. A company name is a starting point, not a lead. Knowing that "someone at Acme" viewed your pricing page never tells you whether that was the VP who signs the contract or an intern doing coursework, and those two visits deserve very different responses from your sales team. That gap is exactly what person-level methods try to close.
Method 2: Third-party identity graphs
How it works. A third-party identity graph is a large external database that links identifiers — cookies, hashed emails, device IDs — to real people, assembled from publisher networks, data partnerships, and co-ops. A pixel on your site captures whatever identifiers it can from a visitor and asks the graph to return a matching person. This is the method behind most person-level tools, including RB2B, Warmly, Vector, Bullseye, Happierleads, Common Room and Instantly's TrafficID.
What it delivers. A named individual, often with a work email and a LinkedIn profile, matched to the pages they viewed. When it lands correctly this is the most useful output in the category, and when it lands incorrectly your rep opens with the wrong person's name.
Realistic match rate. 15-20% of US traffic at the person level is the defensible range, and independent testing across 12 platforms puts it at 5-20%. Marketed numbers run much higher: RB2B publishes 40-45%, Bullseye up to 40%, Common Room up to 50%, and Happierleads 30-55%. The match-rate teardown in Post 4 explains exactly how that gap gets manufactured, usually by blending in company-level matches or leaning on probabilistic guesses.
The quickest way to see that these numbers aren't measurements is to look up the same product twice. RB2B carries four published person-level rates in the same year, from 8-15% to 40-45%, which tells you the category has no shared definition of a match. Post 4 lays the four sources side by side.
Best for. Outbound and warm follow-up where you need an actual contact rather than just an account. This is the method we sell, so weigh what follows accordingly: it's the highest-value option when the match is right, because a name attached to a verified work email is something a rep can act on the same afternoon.
The limit. Two of them, and we run into both. Graph quality decays constantly, and Safari and Firefox blocking third-party cookies by default takes a share of your traffic out of reach entirely; this is also the method carrying the most legal exposure, because you're resolving and storing data about identifiable individuals. In our experience third-party graphs are also where accuracy quietly slips: a returned "match" can be a stale record, or a household member, rather than the person actually on your site.
There's a third limit, and I have an obvious interest in how you weigh it. I went looking for a vendor in this method willing to state the ceiling out loud, and the clearest version came from the founder of the best-known tool in it, correcting his own earlier position on what person-level identification is good for:
"And by the way, I got this wrong. As a lead gen strategy, it's not great because B2B traffic is kind of low and then people don't realize that the concentration of their traffic that is actually their ideal customer profile […] is actually, it's very low. It's like five to 10% of the people that visit your site you actually wanna talk to." — Adam Robinson, Founder & CEO, Retention.com and RB2B (Pony Studio interview)
Run that against a 15-20% person-level match rate and the arithmetic gets sobering fast. Identify a fifth of your traffic, of which a tenth is someone you actually wanted, and the method is returning a very small number of usable names. I still think that is worth paying for. It isn't what the category's marketing implies you're buying.
Method 3: First-party server-side identification
How it works. Instead of relying on a third-party graph, first-party identification resolves visitors using data you own — your own cookies set from your own domain, your CRM records, past purchases, prior sessions — and does the matching server-side rather than in the browser. When a known contact returns without logging in, you recognize them because you already have their record. Post 8 is the technical playbook for this approach.
What it delivers. High-confidence identification of returning and previously-known visitors, plus a durable first-party signal for the new ones. Reach is capped by how much data you already hold, which means it starts slow and compounds, but it's far more accurate for every visitor it does catch.
Realistic match rate. This one resists a single number, because it depends entirely on how much first-party data you already hold and what share of your traffic is returning rather than new. For a site with a large customer base and heavy repeat visits, it can be the most reliable method you own outright. For a brand-new site with no history, it will identify almost nobody in month one and then compound quietly from there.
Best for. Durability and privacy. Third-party cookies never actually went away — Google kept them in Chrome in April 2025 — but Safari and Firefox block them by default, so a third-party graph silently misses roughly a fifth of your traffic and can't tell you which fifth. First-party identification holds up precisely because it never depends on borrowed data. It also carries the cleanest consent story, since you collected the data directly on your own domain. This is the layer we anchor Signal on, and I'll say plainly that it costs us reach.
What that trade looks like from the customer's side: very little identified in month one, more each month after. I've watched that land badly on a first call and fine on a third.
The limit. It won't cold-identify a first-time anonymous visitor the way a third-party graph attempts to. In practice, the strongest setups pair a first-party foundation with a third-party graph for reach — which is the combination the last section covers.
Method 4: Form fills with enrichment
How it works. The oldest trick in the book, and still the most accurate one available. A visitor voluntarily submits an email or a form, and you enrich that single data point into a full profile — name, title, company, firmographics — using an enrichment API. The visitor identified themselves. You just filled in the rest, and nobody had to guess at anything.
What it delivers. A complete, self-identified, opted-in contact. This is the highest-quality lead you can get, because the person chose to raise their hand.
Realistic match rate. Near 100% accuracy on the person who submits, because there's no guessing involved. The catch, as always for us, is coverage: only about 3% of B2B visitors fill out a form, according to 6sense. You get a perfect answer about a tiny slice of your traffic.
Best for. Every site we work with, always. Form fills should be the foundation of your identification strategy rather than an afterthought, precisely because they're both accurate and consented. Everything else on this list exists only to reach the 97% who never fill one out.
This is the method I recommend first and we don't sell, which I mention because it's the cheapest way to tell whether a vendor is describing your problem or their product. We've talked customers into fixing a form before buying anything from us. It's a worse quarter for us and a better first month for them.
The limit. Volume, and there's no way around it. You can't form-fill your way to identifying most of your traffic, no matter how good the offer or how light the form, which is the entire reason the other four methods exist at all.
Method 5: LinkedIn and manual matching
How it works. For company-level visits with no person attached, some teams work backward by hand: they take the company and the pages viewed, then use LinkedIn to find the likely individuals in the right roles and reach out to them directly. A few tools semi-automate the suggestion, but mostly this is human effort and I budget it as such.
What it delivers. A short list of plausible individuals at an account that showed interest, assembled by hand.
Realistic match rate. There isn't a clean percentage here, because this is a manual process rather than a resolution technology, and the output depends entirely on how much time a rep spends and how cleanly the roles at that company map onto your actual buyer.
Best for. Low-traffic, high-value scenarios — boutique consultancies, enterprise sales, deals where a single account is worth enough to justify the manual research. If you get a handful of qualified company visits a week, working them by hand on LinkedIn will beat paying for a graph you would barely touch. I tell people that even though it costs us a sale.
The limit. It doesn't scale, and it guesses at the individual rather than resolving them, which means you're paying a rep to do probabilistic matching by hand. For any high-traffic site that is a poor use of the most expensive person in the process.
How to combine methods
No single method both names the person and covers most of your traffic, so the practical answer is to layer them rather than pick one. Here is the stack we recommend for most B2B sites, including to people who end up buying nothing from us.
It's also the stack we run on our own site, in this order. We got the order wrong at first and led with the graph layer, because that is the one that demos well.
Start with form fills and enrichment as the accurate, consented core of the whole thing. Add first-party server-side identification so that returning contacts get recognized without having to re-submit anything.
Layer a third-party identity graph on top for person-level reach into new anonymous traffic, and go in expecting the 15-20% it will resolve rather than the 40% you were quoted. Use reverse-IP to catch the account-level activity your graph misses, and reserve manual LinkedIn matching for the handful of accounts valuable enough to justify a rep's afternoon.
One caveat on that third layer, and it decides whether the method is available to you at all. Person-level resolution through a third-party graph is a US-traffic technique. The founder of RB2B states the constraint without hedging it:
"Right now we're just doing that one thing, right? It's just this person level of identity and that is not GDPR compliant. So it's US only […]" — Adam Robinson, Founder & CEO, Retention.com and RB2B (Pony Studio interview)
If a meaningful share of your traffic is European, that layer doesn't apply to it, and reverse-IP plus consented form fills is the whole of what you can legally run. Any vendor quoting you a person-level rate on EU traffic is describing something you should ask a lawyer about before you buy it.

The mistake to avoid is buying a single tool on the strength of one headline number without knowing which method produced it. A 60% match rate from reverse-IP and an 18% match rate from a graph aren't competing claims at all. They answer completely different questions, and I'd rather you understood that before you talked to any of us. Post 7 compares the 2026 tools on exactly this basis.
When we built identification into Signal, the temptation was to lead with the biggest number we could defend and let people assume it was person-level. Plenty of tools do exactly that and it works fine until the second call. What we found is that the first question a technical buyer asks is which method produced the number, and if the answer takes more than a sentence, you have spent your credibility before you have shown them anything. So we break it out by method up front. Fewer people are impressed on the first call. More of them are still there on the third. — Bob Thordarson, Geysera CEO
Frequently asked questions
How do you identify anonymous website visitors?
You identify anonymous website visitors by matching the signals they leave — IP address, device, behavior, or a hashed email — against an identity graph or your own first-party data. There are five methods: reverse-IP company lookup, third-party identity graphs, first-party server-side resolution, form fills with enrichment, and manual LinkedIn matching. Each names either the company or the person at a different accuracy.
What is the best way to identify website visitors?
There is no single best method — each answers a different question. Form fills are the most accurate but reach only about 3% of visitors. Reverse-IP covers the most traffic but only names the company. Third-party graphs name individuals but realistically resolve just 15-20%. Most effective B2B setups layer several methods rather than relying on one.
Can you identify website visitors without a form?
Yes. Form fills identify only the roughly 3% of visitors who submit one, according to 6sense. The other four methods — reverse-IP company lookup, third-party identity graphs, first-party server-side resolution, and manual LinkedIn matching — identify visitors who never fill out anything, at varying accuracy and with different privacy obligations.
How accurate is IP-based visitor identification?
Reverse-IP identification resolves 30-65% of US business traffic to the company level, with published vendor claims reaching 80%. It does not identify individuals. Accuracy has declined as remote work, VPNs, and mobile traffic have grown, so claims of 90%+ IP match rates are no longer realistic for most sites, and where they appear they usually describe advertising audience building rather than site visitor identification.
What is the difference between reverse-IP and person-level identification?
Reverse-IP identification maps a visitor's IP address to the company they work for, so you learn the organization but not the individual. Person-level identification uses an identity graph to return the actual person — a name and often a work email. Reverse-IP covers more traffic; person-level is more valuable per match but resolves a smaller share.
Do you need cookies to identify website visitors?
Not necessarily. Third-party identity graphs lean on cookies, and while Google kept third-party cookies in Chrome in 2025, Safari and Firefox block them by default — so those graphs quietly miss part of your traffic. First-party server-side identification resolves visitors using data you own. Reverse-IP identification uses the IP address, not cookies, and form fills rely on voluntary submission rather than tracking.
Is visitor identification worth it for a low-traffic site?
It can be, if each identified buyer is worth a lot. For low-traffic, high-value businesses, manual LinkedIn matching on the handful of qualified company visits you get may beat paying for a third-party graph you'd barely use. Form fills and reverse-IP cost little and are worth running at almost any traffic level.
Continue the Series
This is Post 2 in Geysera's 13-part series on B2B anonymous visitor identification.
- Post 1 — Anonymous website visitor identification: the complete 2026 guide (pillar)
- Post 3 — What is an identity graph? How anonymous visitors get matched to real people
- Post 4 — Match rates decoded: why 40%+ person-level claims are usually fiction
- Post 8 — Third-party cookies didn't die. The deprecation did.
- Post 7 — The best website visitor identification tools (2026)
Sources
- Twilio Segment — Identity resolution: what it is and how it works
- 6sense — Only 3% of web visitors fill out forms
- Demandbase — The State of Account Identification
- Factors.ai — Website deanonymization: B2B visitor identification in 2026
- Leadfeeder — How Leadfeeder identifies companies
- RB2B — Contact-level identification
- MarketBetter — 12 best B2B website visitor identification tools 2026, with tested match rates
- Warmly — Website visitor identification match rates: what every vendor won't tell you
- Happierleads — Visitor identification feature page
- Common Room — Enhanced website visitor identification (with Vector)
- Google Privacy Sandbox — Next steps for Privacy Sandbox and tracking protections in Chrome (April 22, 2025)
- Statcounter Global Stats — Browser market share worldwide, July 2026
- Bullseye — Bullseye vs RB2B comparison
- Pony Studio — Interview with Adam Robinson, Founder & CEO of Retention.com and RB2B

Co-Founder and CEO
Bob Thordarson is CEO and Co-Founder of Geysera, a serial entrepreneur with 25+ years and five co-founded ventures, including Cequint (acquired by TNS in 2010 for $112.5M) and Consumerware (acquired by ParkerVision). A graduate of the University of Washington and MIT Entrepreneurial Masters Program, based in Seattle, he serves on the boards of DRY Soda Co. and the Entrepreneurs' Organization Seattle chapter. He is an expert in retention marketing email systems and methodology for ecommerce and B2B brands — measured by incremental revenue, not vanity metrics.