Website visitor identification: what it actually delivers
The short answer
Two mechanisms, usually combined: reverse IP lookup, which matches a visitor's IP against databases of company-owned ranges, and identity graphs that link browsing behaviour to known individuals through third-party data partnerships. The first is degrading due to remote work; the second carries significantly more privacy exposure.
Website visitor identification tells you which companies visited your site without filling in a form.
It is the highest-precision paid signal available to most B2B teams, and it is also the category where the gap between the demo and the deployment is widest. Both things are true, and the vendors will only tell you the first.
How it works, and why that limits it
Two mechanisms, and the difference determines everything about what you get.
Reverse IP lookup. A visitor's IP address is matched against a database of IP ranges owned by or assigned to companies. Corporate offices have identifiable ranges. This is the traditional approach and it is the one that has degraded.
Identity graphs and cookie pools. Third-party datasets link browsing activity to known individuals or companies through cookie syncing and data partnerships. Higher potential resolution, considerably more privacy exposure, and increasingly restricted by browser changes.
Most vendors combine both. The mechanism matters because it explains the failure modes, which are systematic rather than random.
What remote work did to this
The single most important thing to understand before buying: reverse IP resolution assumed people work in offices.
A buyer researching from home appears as a residential broadband IP belonging to a consumer ISP. There is nothing to resolve them to. They are invisible.
This is not a bug any vendor can fix. It is a change in the underlying signal. Depending on your market, somewhere between a third and two-thirds of your genuine buying activity may now be arriving from IPs that resolve to nothing useful.
Related degradations worth knowing:
- VPNs and corporate proxies resolve to the VPN provider, not the employer
- Cloud-routed traffic resolves to a hosting provider
- Mobile traffic resolves to a carrier
- Coworking spaces resolve to the building operator, meaning you are told a company visited that has never heard of you
That last one matters more than it sounds. It does not just lose signal, it manufactures false ones.
Reading match rates honestly
Vendors quote match rates between 30% and 70%. The number is nearly always measured generously.
Three questions that reveal what you are actually buying:
"Match rate of what denominator?" Some vendors quote against identifiable traffic rather than total traffic, which excludes the residential and mobile visitors that constitute the problem. That converts a 25% real rate into a 65% headline.
"What is the rate for my regions?" Coverage outside North America is frequently much weaker and almost never stated up front. Ask for the breakdown, not the average.
"Company-level or person-level?" Company resolution is reasonable. Person-level resolution is poor and getting worse, despite being the thing most heavily implied in demos. Assume you will learn that Acme visited, not that a named person at Acme visited.
Run a trial and measure it yourself against a set of companies you know visited. The gap between quoted and observed is the useful number.
What it is genuinely good for
Despite all of the above, this remains the paid signal worth buying first. What it does well:
Confirming an account is active. You are already working a target list. Knowing which of those accounts touched your site this week is high-value and difficult to obtain any other way.
Detecting page-level intent. A pricing page visit outranks a blog visit by a wide margin. Multiple people from one domain on pricing inside a fortnight is the strongest signal in B2B, as argued in B2B buying signals.
Catching post-outreach research. An account that visits three days after your email did not reply, but is not cold either. That is a follow-up trigger and it is invisible without this tooling.
Confirming committee spread. Several distinct sessions from one company across different pages suggests more than one person is looking, which is what actually predicts a process.
What it is not good for
Cold prospecting from unknown visitors. The temptation is to treat every identified company as a lead. Most are not. They are recruiters, competitors, vendors, students and people who landed on a blog post from search. Filter against your target list first, always.
Person-level outreach. Do not email a specific person because a tool suggested they visited. The resolution is not reliable enough, and being wrong here is memorable in the worst way.
Replacing first-party instrumentation. If you are not already tracking product usage, email engagement and form activity in one place, fix that first. It is free and more accurate.
The privacy position
This deserves more care than it usually gets, because the regulatory position is genuinely unsettled and varies by jurisdiction.
Company-level identification from IP data is generally defensible under GDPR, on the argument that a company is not a natural person. Even here, a privacy policy disclosure and a lawful basis are expected.
Person-level identification through identity graphs is a materially different proposition. It processes personal data, usually without the visitor's knowledge, and the consent chain frequently rests on data collected elsewhere under terms nobody read. Regulators have been increasingly active here.
Practical position for most teams: use company-level identification, disclose it, and treat person-level resolution as a risk rather than a feature. If your buyers are European, involve whoever owns compliance before you deploy rather than after. The commercial upside of person-level does not justify the exposure for most B2B SaaS companies.
Making it useful
Identification alone changes nothing. Most implementations produce a daily list nobody opens by week three.
What makes it work:
Filter to the target list before anything reaches a human. An unfiltered feed is noise and it trains your team to ignore the channel permanently.
Weight by page. Pricing, comparison and integration pages carry real signal. Blog and careers pages carry almost none. A single weighted alert beats a daily digest.
Apply recency decay. A visit from six weeks ago is not a weaker version of a fresh one. It usually means they looked, decided, and did not choose you. The weighting model is in signal-based lead scoring.
Route to a person with capacity. A signal that arrives faster than anyone can act on is a source of guilt, not an asset. This is an orchestration problem, and where it sits is covered in the GTM engineering stack.
Never reference the visit directly. "I saw you visited our pricing page three times" is accurate and lands badly. Let the signal choose the timing and the topic, never the opening line.
Frequently asked questions
How does website visitor identification work?
Two mechanisms, usually combined: reverse IP lookup, which matches a visitor's IP against databases of company-owned ranges, and identity graphs that link browsing behaviour to known individuals through third-party data partnerships. The first is degrading due to remote work; the second carries significantly more privacy exposure.
How accurate is website visitor identification?
Company-level resolution is reasonable for office-based traffic. Person-level resolution is poor and declining. Quoted match rates of 30 to 70% are usually measured against identifiable traffic rather than total traffic, so real rates are often substantially lower, particularly outside North America.
Why has visitor identification become less accurate?
It assumed people work in offices. Remote workers appear as residential ISP addresses that resolve to nothing, VPNs resolve to the VPN provider, mobile traffic resolves to a carrier, and coworking spaces resolve to the building operator, which generates false positives as well as losing signal.
Is website visitor identification GDPR compliant?
Company-level identification from IP data is generally defensible with disclosure and a lawful basis. Person-level identification via identity graphs processes personal data usually without the visitor's knowledge and carries materially higher regulatory risk. Involve compliance before deploying if your buyers are European.
Is website visitor identification worth buying?
For most B2B teams it is the paid signal worth buying first: cheapest tier, highest precision, and it extends first-party data you already own. Its value comes from confirming which known target accounts are active, not from prospecting into unknown visitors.
---
*NomiOS is RZLT's GTM and ABM engine. Point it at a target and get back finished, branded work built on a real read of that company.*
[See how NomiOS works →](https://nomios.rzlt.io)
Questions
Frequently asked
- How does website visitor identification work?
- Two mechanisms, usually combined: reverse IP lookup, which matches a visitor's IP against databases of company-owned ranges, and identity graphs that link browsing behaviour to known individuals through third-party data partnerships. The first is degrading due to remote work; the second carries significantly more privacy exposure.
- How accurate is website visitor identification?
- Company-level resolution is reasonable for office-based traffic. Person-level resolution is poor and declining. Quoted match rates of 30 to 70% are usually measured against identifiable traffic rather than total traffic, so real rates are often substantially lower, particularly outside North America.
- Why has visitor identification become less accurate?
- It assumed people work in offices. Remote workers appear as residential ISP addresses that resolve to nothing, VPNs resolve to the VPN provider, mobile traffic resolves to a carrier, and coworking spaces resolve to the building operator, which generates false positives as well as losing signal.
- Is website visitor identification GDPR compliant?
- Company-level identification from IP data is generally defensible with disclosure and a lawful basis. Person-level identification via identity graphs processes personal data usually without the visitor's knowledge and carries materially higher regulatory risk. Involve compliance before deploying if your buyers are European.
- Is website visitor identification worth buying?
- For most B2B teams it is the paid signal worth buying first: cheapest tier, highest precision, and it extends first-party data you already own. Its value comes from confirming which known target accounts are active, not from prospecting into unknown visitors.