Email Osint
Email Osint
OSINT
Introduction
Open-source intelligence (OSINT) investigations for email addresses and phone numbers
involve gathering publicly available information to learn more about the owner of these details.
Below is a general guide for conducting such investigations ethically and legally
1) Search Engines
A) Use Google, Bing, or DuckDuckGo to search the email address in quotes (e.g.,
"[email protected]").
2) Social Media
Test the email on popular social media platforms (Facebook, Twitter, LinkedIn, Instagram).
Use tools like Have I Been Pwned to check if the email address has appeared in data
breaches.
Tools
https://intelx.io/
https://dehashed.com/
https://weleakinfo.io/
Steps: Enter the email to uncover past breaches, passwords, or connected accounts.
Goal: Look for other connected data points like associated usernames, domains, or linked
accounts.
Services like Hunter.io, VerifyEmail, or EmailRep can provide information about the domain,
reputation, and creation details of an email.
If you find an associated profile picture, use reverse image search tools like Google
Images or TinEy
If an email account has a public profile picture, perform a reverse image search on
Google Images or TinEye to find similar profiles.e to find other accounts linked to the
image.
6) OSINT Platforms
Tools like Maltego, Recon-ng, and Spadefoot can automate email investigations and
uncover connected entities.
in-depth mapping of the email's connections to domains, IP addresses, and social
media.
Steps -:
Steps:-
Check platforms like GitHub, GitLab, or Bitbucket for code contributions linked to the email.
"[email protected]" site:example.com
*@example.com
1. Search on Twitter:
"[email protected]" site:twitter.com
2. Search on Facebook:
"[email protected]" site:facebook.com
3. Search on Reddit:
"[email protected]" site:reddit.com
4. Search on LinkedIn:
"[email protected]" site:linkedin.com
"[email protected]" intitle:"profile"
"[email protected]" site:pastebin.com
"[email protected]" site:ghostbin.com
"[email protected]" filetype:txt
intext:"@example.com"
"@example.com" filetype:pdf
"@example.com" filetype:xls
"@example.com" filetype:doc
E) Admin and Registration Information
"[email protected]" inurl:admin
"[email protected]" inurl:register
"[email protected]" site:blogspot.com
"[email protected]" site:disqus.com
G) Associated Data
"[email protected]" "phone"
"[email protected]" "address"
"[email protected]" "username"
H) Advanced Operators
"[email protected]" -site:linkedin.com
cache:example.com [email protected]
Tips for Using Dorks E ectively
Experiment with Variations: If the exact email doesn’t return results, try variations (e.g.,
"name at example dot com").
Example:
"[email protected]" -site:linkedin.com