What Is Identity Resolution?
A deep dive into how identity resolution works: from deterministic matching and identity graphs to real-time visitor identification at scale.
By Delivr.ai
Identity resolution
Keep reading
- GuideDeterministic vs. Probabilistic Match Rates: The Honest NumbersMatch rate is the most abused number in visitor identification. What it really measures, why reported rates are inflated, and how to verify any vendor’s claim on your own traffic.
- GuideWebsite Visitor Identification: The Complete Guide (2026)How website visitor identification works: company-level vs. person-level, deterministic vs. probabilistic, and why match rates vary. A buyer’s guide to de-anonymizing your traffic.
- ArticleHow Identity Resolution Impacts AttributionAttribution without identity is guesswork. Learn how person-level identity resolution transforms measurement from a reporting function into an operational revenue advantage.
- ResearchPsychological Reactions to Being Confronted About Anonymous Online BehaviorOriginal research on why people deny tracked behavior: defense mechanisms, psychological reactance, and what it means for identity resolution.
- GuideThe 2026 Identity Resolution Buyer’s GuideA 7-step framework for evaluating identity resolution vendors — matching methodology, data ownership, ID interoperability, real-time capability, and total cost of ownership.
- GuideRFI Questions for Identity Resolution VendorsThe essential checklist every buyer should use when evaluating identity resolution platforms: data onboarding, privacy, activation, and accuracy.
Identity resolution is the process of deciding which records belong to the same person. A visitor arrives with a browser cookie, later opens an email on a phone, and exists separately again in a CRM. Each of those is a different identifier for one human being. Identity resolution is the work of joining them, and of being able to say how confident that join is.
It sits underneath most other marketing capability. Attribution needs to know that the click and the purchase were the same person. Suppression needs to know that a prospect is already a customer. Personalisation needs to know who is reading. If the joins are wrong, every one of those is wrong downstream, and usually silently.
How Identity Resolution Works
Almost every implementation moves through the same three stages, whatever the vendor calls them.
- Collection. Identifiers arrive from somewhere: a first-party pixel setting a cookie, a mobile advertising ID, a form submission, a CRM export, an authenticated login.
- Matching. Each identifier is compared against a reference set to find the record it belongs to. This is where deterministic and probabilistic approaches part company, and where most of the accuracy difference lives.
- Consolidation. Matched identifiers are attached to one persistent record, so the same person recognised through a different identifier tomorrow resolves to the same record rather than a new one.
The reference set is usually called an identity graph: a store of identifiers and the links between them. Its coverage sets the ceiling on how much traffic can ever be resolved, and its link quality sets how often the answer is right.
Deterministic vs Probabilistic Matching
Deterministic matching joins records on a shared identifier that is the same value in both places. A hashed email is the common one: hash the address on both sides, and identical hashes mean the same address. The join either exists or it does not.
Probabilistic matching infers that two records are the same person from signals that correlate without being identical: IP address, device and browser characteristics, timing, location. It produces a likelihood rather than a fact.
The trade is coverage against certainty. Probabilistic methods reach records deterministic methods cannot, because they do not need a shared identifier. They also produce errors that are invisible at the point of use: a wrong match looks exactly like a right one, and it surfaces later as an email to the wrong person or revenue credited to the wrong campaign. Deterministic methods resolve less traffic, and what they establish is narrower but firmer: that two records carry the same identifier. That is not the same as proving the record behind it is current or correctly attributed, since an address can be shared, reassigned or wrong at the source. It removes the guess from the join, not from the underlying data.
The distinction matters most for anything irreversible. Suppression lists, sales outreach and consent handling all reward certainty over reach, because the cost of a wrong answer is not a wasted impression.
What Changed in the Browser
Identity resolution used to lean on third-party cookies. That has genuinely narrowed, though not in the way the industry spent several years predicting.
Safari has fully blocked third-party cookies by default since 2020, describing itself at the time as the first mainstream browser to do so. Firefox does the same through Total Cookie Protection, which confines cookies to the site that set them.
Chrome did not follow. In April 2025 Google said it would keep offering users third-party cookie choice and would not ship a standalone prompt to deprecate them, after earlier signalling a phase-out. Anyone still planning around a Chrome deprecation date is planning around something that was called off.
The accurate position is narrower and more awkward than a collapse: third-party cookies are unavailable by default on two major browsers and available on the largest one, so coverage varies by browser in a way that is invisible in aggregate reporting. That is an argument for identifiers that do not depend on third-party cookies at all, rather than an argument that cookies are ending.
How Resolution Is Measured
Two numbers get quoted and they are not the same thing.
- Match rate is the share of traffic that resolves to a record at all. It is easy to raise: loosen the matching threshold and it goes up immediately.
- Accuracy is the share of those matches that are correct. It is hard to measure, because verifying it needs a truth set the vendor does not usually have.
A match rate quoted without an accuracy figure, or without saying how it was measured, is close to meaningless. Ask what counts as a match, what the denominator is, and whether the number is for all traffic or only for the authenticated subset, which is a much easier population to resolve.
Ask for it by browser, too. A blended figure hides the fact that the same method can perform very differently on Safari than on Chrome.
What It Is Used For
- Attribution and measurement: connecting an outcome to the touchpoints that preceded it, when those touchpoints happened on different devices.
- Visitor identification: recognising who is on a site without requiring a form.
- Suppression and routing: keeping existing customers out of acquisition spend, and sending a lead to the right owner.
- Audience activation: sending an audience to an ad platform in a form it can match, without shipping raw personal data.
- Personalisation: adapting a page to a known reader.
The privacy obligations differ by use. Resolving a visitor to a person and acting on it is a materially different act from counting them, and it is governed differently depending on where the person is.
Questions Worth Asking a Vendor
- Is the matching deterministic, probabilistic, or a blend? If blended, can the probabilistic portion be turned off, and what is the match rate without it?
- Where does the reference data come from, and on what legal basis?
- What is the accuracy figure, and how was it established?
- What happens to the identifiers on your side if you leave? Portability varies widely.
- How is a deletion request propagated, and how long does it take?
- Does the method depend on third-party cookies anywhere, and how does coverage differ across browsers?
How Delivr.ai Approaches Identity Resolution
This section describes one vendor, Delivr.ai, and is not a neutral survey. Everything above applies whichever vendor you choose.
Delivr.ai resolves deterministically only. Hashed email is the hub identifier: a first-party pixel sets a cookie which resolves to a hashed email, and mobile advertising IDs resolve the same way. Matching runs only on verified identifier linkages, never on inference from device or browser characteristics, which is the deliberate trade described above: less reach in exchange for joins that hold up.
IP addresses are treated separately and deliberately do not touch the person chain. An IP resolves to a company or to a household, and household is the bridge to people, so a shared office connection never becomes a claim about an individual.
The graph is built on hashed email as the hub identifier, with mobile advertising IDs, hashed phone records, US person profiles, company records and households linked to it. Specific record counts are deliberately left to the product pages rather than stated here: this page cites its outside claims, and a number that cannot be cited does not belong alongside ones that can.
Two caveats worth stating plainly. That resolution figure is measured on US traffic and will not hold everywhere. And because the method is deterministic, traffic that carries no resolvable identifier stays anonymous rather than being guessed at.
See Delivr.ai in action
Start a free Proof of Value and see how Delivr.ai turns your anonymous traffic into actionable pipeline.
