Open Source Email Intelligence

Email OSINT

Advanced email OSINT reconnaissance for cybersecurity professionals, fraud examiners, and privacy auditors. Examine public registration footprints and exposure vectors.

@
No account required. Searches are processed in memory and aren't stored.·Privacy details
In-memory execution: queries are never stored or logged in any database.Privacy Policy
Methodology

How This Scan Works

01

Domain & DNS Analysis

Parses email domain, MX host records, and disposable mail provider indicators.

02

Public Endpoint Probing

Queries non-invasive public APIs and account recovery signals across major networks.

03

Intelligence Synthesis

Correlates discovered usernames, avatar hashes, and breach records in real time.

What Can Be Found

  • Registered service footprints across developer, communication, and gaming platforms
  • Public Gravatar avatar images, bio data, and linked usernames
  • Mail exchange (MX) provider classification (Google Workspace, Microsoft 365, custom)
  • Known historical breach and compromise records

What Cannot Be Determined

  • Private email correspondence or attachments
  • Account passwords or password hashes
  • Confidential subscriber records or telephone billing data
  • Private accounts on closed corporate intranets
Coverage Examples

Sample Platform Signals

Avatar Hashes

Gravatar API

Inspects public MD5/SHA256 hashes for attached profile photos and usernames.

DNS Infrastructure

MX & SPF Records

Evaluates mail delivery servers, spoofing protection, and enterprise hosting.

Security Exposure

Public Breach Indexes

Cross-references public databases of previously leaked credential collections.

Limitations & Corroboration Notice

  • Services with blind password resets will not disclose account registration states.
  • A breach record reflects historical compromise, not current account status.
  • Ethical OSINT strictly limits collection to publicly available data points.
Questions & Answers

Frequently Asked Questions

What is email OSINT primarily used for?

Email OSINT is used for defensive security audits, investigating spear-phishing campaigns, verifying user authenticity in fraud prevention, and evaluating personal digital footprints.

Does OSINTScan alert the target email address?

No. All queries are passive HTTP requests directed at public platforms and open indices. No email is sent to the address.

Are search queries saved or logged?

No. In adherence to privacy-first engineering, all scans are processed strictly in volatile memory and purged upon completion.