GDE-005 |
Email OSINT | |||||||
Digital infrastructure | ||||||||
June 2026 | ||||||||
01
What it is
Email OSINT is the structured use of open-source methods to trace an email address to its owner, associated accounts, breach history, and infrastructure, using only publicly accessible tools and data without accessing the account itself.
A tip arrives via an encrypted channel. The sender claims to be a government official with documents showing procurement fraud. Before you engage further, before you ask a single question, you need to know whether the email address they used is real, how old it is, which platforms it has been registered on, and whether the domain it sits on was built last week or five years ago. That sequence takes about fifteen minutes using the tools in this guide. It has ended investigations before they started, and it has confirmed sources that went on to produce significant published findings.
Email OSINT operates in three phases. Verification confirms the address is real and active. Enumeration maps the platforms and accounts linked to it. Infrastructure analysis examines the domain and its DNS records to understand the address in its operational context. Each phase produces pivot points that open new investigative lines. The goal at every stage is a defensible chain of evidence. Volume of results is not the measure; reproducibility is.
|
When to use this guide
|
02
How to trace an email address with OSINT
A six-step workflow covering verification, breach checking, account enumeration, username pivoting, domain infrastructure analysis, and header analysis.
The following tools are used across the steps below. All are free unless noted.
Have I Been Pwned: Public breach notification service indexing over 17 billion records from known data breaches. Enter an email address to retrieve a list of breaches in which it appeared, including the platform name, breach date, and data types exposed. No account required. Free.
Holehe: Open-source command-line tool that checks whether an email address is registered on over 120 platforms by using password-reset flows rather than scraping or brute-force methods. Does not alert the account holder. Returns positive hits with partially masked recovery data where available. Free. Requires Python 3.
WhatsMyName: Cross-platform username search tool. Used after extracting the username portion of an email address to locate accounts on other platforms using the same handle. Free.
MXToolbox: DNS and email infrastructure diagnostic suite. Used to query MX records, SPF and DMARC configurations, and blacklist status for any email domain. Free for standard lookups; registration required for monitoring features.
MXToolbox Email Header Analyser: Paste raw email headers to reveal the full delivery path, hop-by-hop timestamps, SPF/DKIM/DMARC authentication results, and originating IP address. Free, no account required.
theHarvester: Open-source reconnaissance tool that passively enumerates subdomains, associated email addresses, and hosts tied to a target domain using search engines and certificate transparency logs. Useful for mapping the wider staff email pattern and infrastructure connected to a corporate domain. Free.
|
Before you begin Stop at the login. Every step in this guide is passive. Do not attempt to log in to, reset the password for, or trigger any authentication flow on accounts linked to the target address. Password-reset enumeration via Holehe works by analysing HTTP responses, not by completing the reset; do not take any action beyond initiating the check. Do not use breach credentials to attempt account access under any circumstances. Legal considerations. An email address constitutes personal data under GDPR and equivalent frameworks. Ensure you have a lawful basis for processing it before beginning. Accessing accounts without authorisation violates the Computer Misuse Act 1990 (UK), the Computer Fraud and Abuse Act (US), and equivalent laws in most jurisdictions. Breach data from HIBP reveals which platforms a subject used; using any passwords exposed in those breaches to access accounts is a criminal offence in virtually every jurisdiction. |
Run a Google dork: search the email address in quotation marks, then repeat without quotes. Note every page where the address appears publicly. Run a MXToolbox DNS lookup on the domain portion of the address to confirm mail exchange records exist and the domain is active. A domain with no MX records cannot receive email and the address is likely invalid or abandoned. Record the MX lookup result, the domain registrar, and any nameserver details visible. This is your baseline infrastructure record.
Enter the address at Have I Been Pwned. Record every breach result: the platform name, breach date, and data types exposed. The breach list is an indirect platform map. An address appearing in a 2015 LinkedIn breach confirms a LinkedIn account existed as of that year; an address in a gaming platform breach suggests the subject used that service. The earliest breach date gives a minimum age for the address. Do not use or seek the passwords associated with breach records. The platform list is the intelligence; the credentials are not.
Run Holehe against the target address. The tool checks over 120 platforms using password-reset response analysis and returns a list of positive registrations. Where a partial recovery email or phone number is returned by the platform, record it as a secondary identifier for further investigation. Compare Holehe results against the HIBP breach list: platforms appearing in both are confirmed with higher confidence than platforms appearing in only one source. Note that Holehe coverage varies by platform; a negative result does not confirm the address is unregistered on that platform.
Extract the local part of the email address, the text before the @ symbol, and run it through WhatsMyName. Many people reuse their email handle as a username on platforms that do not require email-based registration or where the email is never publicly visible. Any positive hit from WhatsMyName that matches or closely resembles the email handle is a candidate for corroboration. Do not attribute accounts based on username alone; a matching username on an unrelated platform requires at least one additional corroborating signal before inclusion in an investigation file.
Free provider domains (gmail.com, proton.me, outlook.com) require no further infrastructure analysis. For custom domains, run a full MXToolbox check: WHOIS for registrant data and registration date, A records for hosting provider, SPF and DMARC records to assess how actively the domain is administered. A custom domain with a recent registration date, generic WHOIS privacy, and minimal DNS configuration may indicate a purpose-built identity rather than an established organisation. Cross-reference the domain against the DIG-001 WHOIS card workflow for a structured registrant trace.
If you have received an email from the target address, open the raw headers in your email client and paste them into MXToolbox Email Header Analyser. The tool returns the full delivery path, hop timestamps, SPF/DKIM/DMARC pass or fail status, and the originating IP address where the sending server has not stripped it. A failed SPF or DMARC result indicates the email may have been spoofed from a domain it is not authorised to send from. The originating IP can be run through a geolocation lookup and cross-referenced with the claimed sender identity as a corroborating or contradicting signal.
|
03
What can go wrong when tracing email addresses
Attribution errors, false signals, and evidentiary traps specific to email OSINT investigations.
Shared or role-based addresses: Email addresses beginning with info@, admin@, contact@, or support@ are typically shared among multiple staff members or handled by automated systems. Any investigative finding derived solely from a role-based address cannot be attributed to a specific individual without additional corroborating evidence. Verifying check: Identify the address structure before drawing any personal attribution conclusions. If the domain has a staff page, press contact, or company registry entry, cross-reference to determine who controls or uses the address.
Holehe false negatives: A negative result from Holehe does not confirm the address is unregistered on that platform. Many platforms change their password-reset response behaviour over time, breaking Holehe modules. Rate limiting can also suppress results during a run. Verifying check: For platforms where registration matters to the investigation, manually attempt the password-reset flow directly on the platform and observe the response. A message confirming or denying that the email is registered constitutes independent corroboration.
Breach data as platform confirmation: An email address appearing in a breach database confirms the address was registered on that platform at the time of the breach. It does not confirm the account still exists, nor that it belongs to the current holder of the address if the address has since changed hands. Verifying check: For any breach-derived platform hit that is material to the investigation, manually confirm current account existence on the platform rather than relying on breach records alone.
Username coincidence: A matching username on WhatsMyName does not confirm the same person controls both accounts. Common words, numbers, and name combinations are reused across millions of accounts by unrelated users. Verifying check: Require at least two independent corroborating signals before attributing a WhatsMyName hit to the subject: profile photo match, consistent biographical detail, cross-platform reference, or direct mention linking the accounts.
Chain of custody: Email account status is volatile. Accounts are deleted, platforms shut down, and WHOIS data is updated without notice. Evidence that exists today may be gone tomorrow.
Screenshot every positive result from HIBP, Holehe, and WhatsMyName at the time of discovery with the timestamp visible.
Export or screenshot MXToolbox DNS results and note the query date and time.
Archive all Google dork result pages using the Wayback Machine and record the capture URL.
If email headers are part of the evidence, save the raw header text as a plain text file and record the SHA-256 hash.
Log every tool used, the exact query or input submitted, and the timestamp of each result in your case file.
04
Go deeper
Each reference card used in this guide is available individually in the archive. Every card covers the full workflow, key queries, OPSEC controls, false positives, and chain of custody requirements for the technique.
DIG-001
WHOIS investigation: domain name to attribution chain.
ViewDNS, SecurityTrails, and crt.sh. Registrant email pivots that extend and corroborate the domain infrastructure step of this workflow.
SOC-001
Social media account verification for investigators.
Botometer, Social Blade, and Wayback Machine. The corroboration layer for any username pivot from this guide.
AIV-001
Using AI tools in the verification workflow.
Claude, Whisper, NotebookLM, and OpenRefine. Where AI-assisted tools can and cannot be used in verification workflows, with chain of custody requirements.
GDE-004
How to verify a source: OSINT identity checks.
Digital depth assessment, employer verification, cross-platform mapping, and information corroboration. The identity layer that sits alongside this workflow.
Evidentiary standard
Signal & Shadow operates to the LST-001 evidentiary standard. All claims are graded against the LST-001 v1.0.3 confidence tiers (Confirmed, Corroborated, Reported, Alleged) per the canonical voice and structural specification.
About Signal & Shadow
Signal & Shadow is an independent forensic investigation and methodology practice publishing tutorials, reference cards, and forensic dossiers for working practitioners. Founded by Derek Bowler.





