Email-OSINT-Guide-101

Email OSINT Investigation Checklist

Print this or copy it into your case file. One checklist per address. If a second email appears, start a new sheet and cross-link the IDs.

Back to the Email OSINT Guide 101.


Case header

Case / ticket: ________________________________
Analyst: _____________________________________
Lawful basis / authorization: _________________
Date opened (UTC): ____________________________
Primary address (exactly as received): _________
Normalized forms:
  - lowercase: ________________________________
  - plus-stripped: ____________________________
  - Gmail-dotless (if consumer Gmail): _________
Classification:  [ ] consumer  [ ] corporate  [ ] role
                 [ ] disposable  [ ] catch-all  [ ] alias
                 [ ] spoofed  [ ] unknown
Name hypothesis (label as hypothesis): _________
Do-not-do list: no login, no reset, no credentials, no contact

Phase 1 — Normalize and classify


Phase 2 — Validate

Provider / MX notes:

MX:
SPF:
DMARC:
Notes:

Phase 3 — Search and archives

For each engine, search the quoted original and normalized forms.

URL What it shows Date seen Archive link Confidence
         
         

Phase 4 — Exposure

Source Date Data classes Pivot produced Still live?
         

Earliest public / breach date (minimum age): _______


Phase 5 — Accounts

Platform Evidence URL Photo / name Confirmed live Confidence
           

Phase 6 — Pivots

New identifiers (email / phone / username / URL):

1.
2.
3.

Phase 7 — Infrastructure and headers

Domain (skip consumer webmail)

If a message was received

Header verdict: [ ] authentic [ ] spoofed [ ] forwarded [ ] inconclusive


Phase 8 — Report

Claim log

Claim Sources Confidence Caveat
    High / Med / Low  

Analyst conclusion (plain language)






Evidence pack

Retain according to your organization’s policy. Delete what you have no lawful basis to keep.