What HubSpot matches on
HubSpot's documentation says it automatically de-duplicates contacts using email addresses and companies using domain names. When a form is submitted with an email that already exists, the new information is added to that contact rather than creating another. If the submission uses a contact's secondary email address, the page says that address overwrites the contact's existing email address, which surprises people. Custom unique-value properties, which can be used to match on other fields in imports, are not supported in forms, so form matching stays with the default properties.
Four routes into HubSpot, four behaviours
The route a lead takes decides which rules apply. A HubSpot form with an email field follows the matching above. A HubSpot form with no email field has no email to match on, so HubSpot uses the browser cookie to identify the visitor, and its page on visitor tracking says that cannot be changed. A form on your own website that HubSpot collects through its tracking code depends on that code loading and on the form being a plain static form, not in an iframe; HubSpot suggests using its Forms API when those conditions are not met. An integration or script that creates records through the API follows the API's rules, and the documentation says companies created through the API are not de-duplicated by the domain name property. That last route is a common source of many company records sharing one domain.
- HubSpot form with an email field: matched by email.
- Form with no email field: matched by cookie.
- Collected external form: matched by email, with cookie effects, if the tracking code loads.
- API or integration: follows the API's rules; companies are not de-duplicated by domain.
Cookie matching can overwrite or combine people
The create-and-edit forms page describes a setting named Automatically create new contacts from unknown email addresses. With it on, each unique email address gets its own contact, and an existing email updates that record. With it off, HubSpot tries the email first and, if there is no match, falls back to the browser's cookies to decide which contact to update, and the page warns this may result in contacts being overwritten when the same form is submitted repeatedly from one device. The page on non-HubSpot forms adds that all submissions associated with the same cookie are added to the same contact record, so different email addresses entered on one browser can end up on one contact.
A shared office computer or a family laptop can therefore combine different people, or overwrite one with another; HubSpot's visitor-tracking page says the cookie can update or overwrite the cookied contact's properties, including email, on a shared computer, and suggests a private window or a different browser each time when testing. The remedy depends on the route, so confirm which route your duplicate or overwrite came through.
Do not merge as a test
Merging contacts looks like the obvious clean-up, but the page on merging says merged contacts cannot be unmerged, and the workaround it gives is to remove the extra email from the merged contact and create a new contact. A merge also combines timelines and property history, keeps the primary record's values where both have them, and can fail when records have combined more than a documented number of merges. Decide which record wins and test on synthetic records before any real merge, and do not merge in order to find out how a form behaves.
- Never merge real contacts to experiment.
- Choose the winning record rule before merging anything.
- Export or record what you are about to merge if you might need the values back.
A safe diagnosis
Open three duplicate contacts and note, for each, the original source and the form or integration that created it. If they share a path, that path is the suspect. Then check the form: is there an email field, and what does the create-contacts setting say? Then, on a test route and with synthetic addresses, submit the same email twice, two different emails from one domain, and two different people from one browser, and count the contacts and companies after each. Make sure that no workflow will email or notify real people when a test contact appears.
What this guide does not cover
This guide does not clean up existing duplicates, give consent or data-protection advice, or cover duplicates that come from the Salesforce sync, which follow different rules. The paid outcome changes one form path so that it creates one contact and one company, proven with six synthetic submissions. It does not merge anything. If several paths and tools need attention at once, the project outcome tests each path from form to owner.
Sources and limits
- HubSpot: deduplicate records Checked 2026-10-11.
- HubSpot automatically de-duplicates contacts using email addresses and companies using domain names.
- A form submission with an existing email adds its data to that contact, and a submission with a secondary email overwrites the existing email address.
- Companies created through the API are not de-duplicated by the Company domain name property, and custom unique-value properties are not supported in forms.
- HubSpot: create and edit forms Checked 2026-10-11.
- With Automatically create new contacts from unknown email addresses on, each unique email gets a contact; with it off, HubSpot falls back to browser cookies, which may overwrite contacts.
- By default the Email field is required for form submissions to create contacts.
- HubSpot: use non-HubSpot forms Checked 2026-10-11.
- Submissions from collected external forms create or update a contact by email, and all submissions associated with the same cookie are added to the same contact record.
- Collection depends on conditions such as the tracking code loading, a static form and no iframe, and a developer can use the Forms API instead.
- HubSpot: how HubSpot tracks visitors Checked 2026-10-11.
- A form with no email field identifies submissions by browser cookie and this cannot be changed.
- On a shared computer the cookie can update or overwrite the cookied contact's properties, including email, and HubSpot suggests a private window or different browser each time when testing.
- HubSpot: merge records Checked 2026-10-11.
- Merged contacts cannot be unmerged.
- The primary record's property values are prioritised, timelines and property history are combined, and a merge fails if the records have a combined total of 250 or more merges.