Print this or copy it into your case file. One checklist per address. If a second email appears, start a new sheet and cross-link the IDs.
Back to the Email OSINT Guide 101.
Case / ticket: ________________________________
Analyst: _____________________________________
Lawful basis / authorization: _________________
Date opened (UTC): ____________________________
Primary address (exactly as received): _________
Normalized forms:
- lowercase: ________________________________
- plus-stripped: ____________________________
- Gmail-dotless (if consumer Gmail): _________
Classification: [ ] consumer [ ] corporate [ ] role
[ ] disposable [ ] catch-all [ ] alias
[ ] spoofed [ ] unknown
Name hypothesis (label as hypothesis): _________
Do-not-do list: no login, no reset, no credentials, no contact
dig MX, dig A)Provider / MX notes:
MX:
SPF:
DMARC:
Notes:
For each engine, search the quoted original and normalized forms.
filetype:pdf / xlsx / csv / docsite:github.com / gitlab.com / linkedin.com / reddit.comintext:"@domain" -site:domain (corporate only)| URL | What it shows | Date seen | Archive link | Confidence |
|---|---|---|---|---|
| Source | Date | Data classes | Pivot produced | Still live? |
|---|---|---|---|---|
Earliest public / breach date (minimum age): _______
?d=404) + profile JSON| Platform | Evidence | URL | Photo / name | Confirmed live | Confidence |
|---|---|---|---|---|---|
New identifiers (email / phone / username / URL):
1.
2.
3.
Domain (skip consumer webmail)
If a message was received
.eml saved.eml: __________From vs Return-Path vs Reply-To vs DKIM d=Received chain read bottom-upAuthentication-ResultsMessage-ID, X-Mailer, X-Originating-IP (if any)Header verdict: [ ] authentic [ ] spoofed [ ] forwarded [ ] inconclusive
| Claim | Sources | Confidence | Caveat |
|---|---|---|---|
| High / Med / Low |
.eml + hashRetain according to your organization’s policy. Delete what you have no lawful basis to keep.