Email OSINT
Advanced email OSINT reconnaissance for cybersecurity professionals, fraud examiners, and privacy auditors. Examine public registration footprints and exposure vectors.
How This Scan Works
Domain & DNS Analysis
Parses email domain, MX host records, and disposable mail provider indicators.
Public Endpoint Probing
Queries non-invasive public APIs and account recovery signals across major networks.
Intelligence Synthesis
Correlates discovered usernames, avatar hashes, and breach records in real time.
What Can Be Found
- •Registered service footprints across developer, communication, and gaming platforms
- •Public Gravatar avatar images, bio data, and linked usernames
- •Mail exchange (MX) provider classification (Google Workspace, Microsoft 365, custom)
- •Known historical breach and compromise records
What Cannot Be Determined
- •Private email correspondence or attachments
- •Account passwords or password hashes
- •Confidential subscriber records or telephone billing data
- •Private accounts on closed corporate intranets
Sample Platform Signals
Gravatar API
Inspects public MD5/SHA256 hashes for attached profile photos and usernames.
MX & SPF Records
Evaluates mail delivery servers, spoofing protection, and enterprise hosting.
Public Breach Indexes
Cross-references public databases of previously leaked credential collections.
Limitations & Corroboration Notice
- •Services with blind password resets will not disclose account registration states.
- •A breach record reflects historical compromise, not current account status.
- •Ethical OSINT strictly limits collection to publicly available data points.
Frequently Asked Questions
What is email OSINT primarily used for?▼
Email OSINT is used for defensive security audits, investigating spear-phishing campaigns, verifying user authenticity in fraud prevention, and evaluating personal digital footprints.
Does OSINTScan alert the target email address?▼
No. All queries are passive HTTP requests directed at public platforms and open indices. No email is sent to the address.
Are search queries saved or logged?▼
No. In adherence to privacy-first engineering, all scans are processed strictly in volatile memory and purged upon completion.