A practical directory of email OSINT tools used in the Email OSINT Guide 101. Every row is here because it answers a specific investigative question. A 200-link graveyard is not a toolkit.
Tools die. If a row is stale, open an issue.
Rules that apply to every tool in this list
| If you need… | Start with |
|---|---|
| A face or a name in 30 seconds | Epieos, Gravatar |
| A live list of registered sites | Holehe, user-scanner |
| Breach timeline | Have I Been Pwned |
| Infostealer exposure | Hudson Rock free tools |
| Corporate pattern + more addresses | Hunter.io, Phonebook.cz, theHarvester |
| Google-account depth | GHunt |
| Username reuse | WhatsMyName, Maigret |
| Header authenticity | MXToolbox + your own reading |
| Graph of relationships | Maltego CE, or paper |
| One paid pane of glass | OSINT Industries or your desk’s licensed platform |
| Tool | Type | Cost | What it is actually for |
|---|---|---|---|
| Hunter.io Verifier | Web / API | Free tier | Deliverability + catch-all + disposable flags. Treat catch-all as unknown |
| Email Hippo | Web | Freemium | Syntax, MX, mailbox-level verdict without you touching SMTP |
| EmailRep | API | Free / key | Reputation sketch: reputation, suspicious, references. Can be stale; confirm |
| MXToolbox | Web | Free | MX, blacklist, SPF/DKIM/DMARC, header analyzer |
| disposable-email-domains | List | Free | Daily-updated throwaway domain list |
dig / nslookup |
Local | Free | Ground truth for MX, TXT, NS, A |
| Tool | Type | Cost | What it is actually for |
|---|---|---|---|
| Google / Bing / Yandex / DuckDuckGo | Web | Free | Still the best email OSINT tool. See dorks |
| Phonebook.cz | Web | Free | Fast @domain harvest of indexed emails, URLs, subdomains |
| Hunter.io Domain Search | Web / API | Free tier | Corporate pattern (first.last) and sourced staff addresses |
| theHarvester | CLI | Free | Passive emails, names, subdomains from search engines, CT, APIs |
| Intelligence X | Web | Freemium | Pastes, documents, historical indexes beyond Google |
| RocketReach / Snov.io | Web | Paid | Sales-intel style people → email. Use only with a lawful basis |
| Whoxy / ViewDNS Reverse WHOIS | Web | Freemium | Domains registered with this email |
| crt.sh | Web | Free | Certificate Transparency; occasional embedded emails |
| Wayback Machine | Web | Free | Pages that used to list the address |
| archive.today | Web | Free | Independent archive when Wayback misses |
| Tool | Type | Cost | What it is actually for |
|---|---|---|---|
| Have I Been Pwned | Web / API | Free | Confirmed breaches + pastes; data classes; minimum age |
| Hudson Rock free tools | Web | Free | Whether email/domain appears in infostealer telemetry |
| DeHashed, LeakCheck, Snusbase | Web | Paid | Deeper corpora for licensed teams. Record names and classes, not passwords to try |
| h8mail | CLI | Free + paid backends | Local/orchestrated breach search for authorized assessments |
| Mosint | CLI | Free | All-in-one email recon (breaches, socials, related addresses) if you want a single binary |
HIBP’s Pwned Passwords API uses k-anonymity so you can check your own password hashes without sending the secret. That is a defensive feature. It is not a reason to test a stranger’s recovered password against a login form.
| Tool | Type | Cost | What it is actually for |
|---|---|---|---|
| Epieos | Web | Free limits | Google / Microsoft name + avatar; selected linked services. Third-party logs your query |
| Holehe | CLI | Free | Live “is this email registered?” across 100+ sites |
| user-scanner | CLI | Free | Email + username scanning; bulk-friendly |
| GHunt | CLI | Free | Public Google account OSINT (Maps reviews, calendar, photos). Uses your Google login |
| ProtOSINT | CLI | Free | Proton Mail existence / custom-domain MX notes. Prefer DNS MX for custom domains |
| osgint | CLI | Free | GitHub username ↔ email via public commits and GPG |
| Gravatar | API | Free | SHA-256(email) → avatar + public profile JSON |
| OSINT Industries | Web | Paid | Aggregated accounts + breaches in one report |
| MailAccess | CLI | Free | Self-hosted fan-out across many modules; heavier setup |
Epieos vs Holehe is not a contest. Epieos asks “who?” Holehe asks “where?” Run both, or run neither and do it by hand.
| Tool | Type | Cost | What it is actually for |
|---|---|---|---|
| WhatsMyName | Web | Free | Fast username presence check you can screenshot |
| Maigret | CLI | Free | Deep username search, HTML report |
| Sherlock | CLI | Free | Classic username hunter; more false positives |
| Namechk | Web | Free | Quick visual scan, not authoritative |
| Google Lens / Yandex / TinEye | Web | Free | Reverse image on avatars |
Username hits are leads. See confidence rules in the main guide.
| Tool | Type | Cost | What it is actually for |
|---|---|---|---|
| MXToolbox Header Analyzer | Web | Free | Hop list + auth summary. Still read the raw headers yourself |
| Google Admin Toolbox Messageheader | Web | Free | Clean Received-chain visualization |
| DNSDumpster | Web | Free | Visual DNS for a corporate domain |
| SecurityTrails | Web | Freemium | Historical DNS / WHOIS |
| keys.openpgp.org | Web | Free | PGP UIDs: names, extra emails, key age |
Header methodology: Email header analysis.
| Tool | Type | Cost | What it is actually for |
|---|---|---|---|
| Maltego CE | Desktop | Free / paid | Link analysis; Epieos and other transforms exist on the hub |
| SpiderFoot | Local | Free | Automated OSINT fan-out. Review every finding; it will over-collect |
| Hunchly | Browser | Paid | Automatic evidence capture with hashes |
| SingleFile / Firefox / Chrome | Extension | Free | Save the page you are about to lose |
| Obsidian / any notes app | Local | Free | Claim log + source URLs. Use the checklist |
These are the commands investigators actually type. They touch public data only.
# DNS ground truth
dig MX acme.com +short
dig TXT acme.com +short
dig TXT _dmarc.acme.com +short
# Holehe
pipx install holehe
holehe subject@acme.com
# theHarvester — passive sources
theHarvester -d acme.com -b duckduckgo,crtsh -l 200
# Gravatar (SHA-256 of lowercase trimmed email)
email="subject@acme.com"
hash=$(printf '%s' "$email" | tr '[:upper:]' '[:lower:]' | sha256sum | awk '{print $1}')
curl -sI "https://www.gravatar.com/avatar/${hash}?d=404"
# Windows PowerShell — SHA-256 for Gravatar
$email = "subject@acme.com".ToLower().Trim()
$bytes = [System.Text.Encoding]::UTF8.GetBytes($email)
$sha = [System.BitConverter]::ToString([System.Security.Cryptography.SHA256]::Create().ComputeHash($bytes)).Replace("-","").ToLower()
"https://www.gravatar.com/avatar/${sha}?d=404"
VRFY / RCPT TO probe scriptsIf a product’s main demo is “we show you the password,” close the tab.