Skip to main content

Email Research OSINT: Verifying Business Contacts and Sender Domains

How professional teams verify a business email address and the domain behind it: DNS and sender policy checks, published presence, open-source tools, and structured research in UserSearch with source attribution.

· By UserSearch Team · 8 min read

Disclaimer: This article is for education and for lawful, authorised professional research. Use these methods only where you have a legitimate purpose and a lawful basis, and follow the laws and platform terms that apply to you, including data protection law such as the UK GDPR and EU GDPR. See our Terms of Service.

TL;DR

  • We show why structured email research beats a quick web search when you need to verify a business contact or an organisation's sender address.
  • You'll learn the manual workflow (DNS records, search operators, open-source CLI tools) and where it slows down.
  • We then show how UserSearch runs several third-party data sources on one address, with source attribution, SargeBot summaries and a Case history for your audit trail.
  • Two worked scenarios: (1) a newsroom verifying the organisation behind a press contact; (2) a finance team reviewing the sender domain on a supplier payment request.
  • We finish with legal and ethical guardrails and a practical next step.

2.1 Why Email Research Matters for Verification

An email address is often the first and only thing you receive from an organisation you do not yet know: a new supplier, a press office, a partner asking to change bank details. A simple Google search usually hits a dead end. To decide whether the address belongs to the organisation it claims to represent, you need to look at the structure around it: the domain behind it, how that domain is configured, where the address is published, and whether third-party data sources have already recorded it in an abuse context.

2.2 What Email Research Covers

Email research, as one strand of OSINT (open source intelligence), means checking an address against public and licensed data sets to establish:

  • Domain facts: who registered the domain, when, and whether it has mail records and sender policies in place.
  • Public presence: whether the address is published on the organisation's own website, in filings, press releases or code repositories.
  • Service registrations: whether a business address is used on public platforms such as GitHub or a Gravatar account, which helps confirm it is live and in real use.
  • Risk indicators: links to reported scam campaigns or to domains with a history of abuse.

For a technical primer, see OSINT on Wikipedia. For a longer look at working with historical data sets in email research, see our email research guide.

2.3 Stakes: Verification and Risk Triage

Why does this matter? Because email is still the main channel for supplier payment requests, invoices and partnership approaches, and lookalike domains remain a common route for payment diversion. The UK's National Cyber Security Centre publishes guidance on email security and anti-spoofing because organisations need to know whether a message really came from the domain it shows.

Journalists use email research to confirm that a press contact really speaks for an organisation. Compliance and fraud teams use it to check that a new supplier's address sits on the supplier's registered domain. Security teams use it to spot lookalike domains aimed at their own brand. Knowing how an address and its domain are set up is the difference between guesswork and a decision you can defend. Our insurance and fraud teams page sets out how this fits into wider verification work.

Each of these teams needs speed, coverage and an audit trail. Each also needs proportionality: you research the address and the organisation behind it for a stated business purpose, and you keep only what that purpose requires.

2.4 Manual Email Research Workflow (The Hard Way)

  1. Domain and DNS checks
    Start with the domain, not the mailbox. Registration date, registrar and mail configuration tell you a lot about whether an organisation has operated from this domain for years or set it up last week.
  2. Manual notes and audit trail
    Spreadsheets or note apps to record hits, URLs and timestamps. Pain point: no central case history, hard to repeat or share, easy to miss sources.

Mail records and sender policy
Check whether the domain receives mail and publishes SPF and DMARC records:

dig +short MX example.com
dig +short TXT example.com
dig +short TXT _dmarc.example.com

The first line lists mail servers, the second shows TXT records including any SPF policy, and the third shows the DMARC policy. An established business domain with no mail records, or a domain registered days before a payment request, deserves a closer look. The DMARC overview explains what each policy value means.

Gravatar pivots
MD5 the address (lowercased, trimmed) to see whether a Gravatar account exists:

echo -n "[email protected]" | md5sum

Then request https://www.gravatar.com/avatar/<hash>?d=404 to check for an image. A company logo on a business address is a useful sign that the address is in real use. Caveat: it only works where the account holder set one up. Background is on the Gravatar Wikipedia page and in the Gravatar support docs.

CLI tooling
Holehe checks whether an address is registered on a set of major sites (pip install holehe, no API key needed):

holehe [email protected]

Maigret checks a handle across many sites, which is useful when a business address uses a brand name as its local part (pip install maigret):

maigret examplebrand -a

Caveats: coverage shifts, CAPTCHAs, rate limits and false positives without context. Treat every hit as a lead to corroborate.

Search operators for published addresses
Search engines help you establish whether an address is published where you would expect it, such as the organisation's own site or its public code:

site:example.com "@example.com"
"[email protected]" -site:example.com
site:github.com "@example.com"

The first query finds addresses the organisation publishes on its own domain, the second shows where else the exact address appears, and the third shows commits or documentation mentioning the domain. If a "finance" address appears nowhere on the organisation's site, ask why before you act on it.

Where it hurts: inconsistent coverage, slow checks across several sources, no enrichment context, no summaries and poor auditability. You spend most of your time fixing tools and too little analysing the organisation under review.

2.5 How UserSearch Speeds Up Email Research

Instead of hand-stitching tools, UserSearch runs structured email research in one web platform:

  • Email Intelligence and Domain Intelligence Search types for the address and the domain behind it, including domain ownership and history.
  • OneScan runs one address across several selected third-party data sources and merges the results with source attribution. The Credit cost is the sum of the selected sources and is shown before you run it.
  • Access to 100+ third-party data sources through one UserSearch account, so you do not need separate accounts with each provider.
  • SargeBot, the AI research assistant, where you choose the model (Claude, GPT or Grok), set a lawful objective and generate a PDF report. You verify its output before relying on it.
  • Cases: Forensic Mode stores search history and bookmarks for audit; Private mode does not store history.

2.6 Advanced Tactics and Use Cases

Experienced analysts do not just run a search; they build an evidence trail. Here is how we approach email research on organisations inside UserSearch.

Choosing Sources and Filters

Start broad, then narrow. Run OneScan with several sources selected first, then deselect sources if cost or noise is high. Different providers return different metadata, such as display names, platform categories or registration signals, and comparing them side by side is faster than running each one on its own.

Pair the address with its domain. An address result means little on its own. Run Domain Intelligence on the same domain to see ownership and history, then decide whether the address fits the organisation's age and presence on the web.

Add a report-context check. Third-party data sources that record reported scams help you see whether an address or domain has already been reported in a payment or crypto scheme. Absence of a report is not proof of good standing, but a report is a strong reason to pause.

Worked Scenario 1: A Newsroom Verifies a Press Contact

Context: A reporter receives a statement from [email protected] claiming to speak for Brightwater Grid Ltd, a fictional energy company, and needs to confirm the address before quoting it.

Hard way steps:

  • DNS checks on the domain; WHOIS lookup for registration date.
  • Search operators to see whether the address appears on the company's own site.
  • Holehe to see whether the address is in use on major platforms.

Pain: fragmented results, uncertain matches, no single record of what was checked.

With UserSearch:

  • Email Intelligence on the address; Domain Intelligence on the domain for ownership and history.
  • OneScan across several selected sources, with the Credit cost shown before running.
  • SargeBot with the objective "confirm whether this address is an official contact for Brightwater Grid Ltd" to summarise the findings.

Outcome: The domain was registered three weeks earlier and does not match the company's long-standing website domain, and the address appears nowhere on the official site. The reporter contacts the press office through the number on the company's own website instead, and the Forensic Mode Case records every check for the editor.

Worked Scenario 2: A Finance Team Reviews a Supplier Payment Request

Context: The finance team at Halden Office Supplies, a fictional distributor, receives a request from [email protected] to change a supplier's bank details. The supplier normally writes from example.com.

Hard way steps:

  • Manual WHOIS and DNS checks on both domains.
  • Scattered web searches for the new address.

With UserSearch:

  • Domain Intelligence on both domains to compare registration dates and ownership history.
  • Email Intelligence on the new address, with OneScan across selected sources.
  • Bulk search to run up to five related addresses from the email thread through one Module.
  • SargeBot to draft a short risk note for the payments approver.

Outcome: A defensible risk note: the new domain is recent, has no history of use by the supplier, and one source records it in a reported payment scheme. The team holds the payment and confirms the bank details by phone using contact details already on file.

Operational Playbook Inside UserSearch

  1. Case setup: Create or select a Case. Pick Private mode if you do not want history stored, or Forensic Mode for a full audit trail. Record the business purpose for the Case before you start.
  2. First pass: Run Email Intelligence on the address and Domain Intelligence on its domain. Bookmark the useful results.
  3. OneScan sweep: Select several sources. If you need to conserve Credits, deselect one and add it back only when results are thin.
  4. Context check: Look for report context and for where the address is published. Note source names and dates.
  5. Synthesis: Ask SargeBot for a summary against your stated objective, then check each point against the underlying results.
  6. Reporting: Generate a PDF report or copy bookmarked URLs and verified summaries. Keep personal data out of reports unless the purpose requires it.
  7. Follow-up: If a decision is still open, re-run the checks on demand before the payment or publication date, and record the date of each run in the Case.

Practitioner Notes

  • Operators to keep handy: combine intext: with domain scoping and time bounds (before:/after: where supported) to find recent mentions of an address.
  • Logo reuse: a business Gravatar logo that matches the organisation's website and GitHub organisation page is a useful consistency check. Record the image hash for comparison.
  • Category filters: narrow OneScan sources to the categories that fit your question, such as business platforms for supplier checks.
  • Cost awareness: the Credit cost is shown before each OneScan, so you can control spend during broad triage.
  • Prompts that work: ask SargeBot "Summarise which organisation this address and domain most likely belong to, with sources" and then verify each claim.
  • Legal hygiene: only sign in to accounts you are authorised to use; keep Private mode on where history is not needed; cite sources if publishing.
  • Stick to publicly available or properly licensed sources, and to authorised access only.
  • Respect platform terms and data protection law, such as the UK GDPR and EU GDPR. Our OSINT fundamentals page covers the basics of lawful, proportionate research.
  • Keep only the data your purpose needs; use Private mode when you do not want history saved.
  • Cite sources and avoid overstating certainty. AI output is guidance to verify, not proof.

2.8 From One Address to a Defensible Decision

Email research turns a single address into a clear picture of the domain, the organisation and the context around it, if you run it in a structured way. Manual pivots are slow and lossy; structured research with source attribution gives you answers you can defend. By combining domain facts, published presence and report context, analysts can move from "who sent this?" to "this address does or does not belong to the organisation it claims, and here is the evidence" in minutes. If you are new to the platform, our beginner's guide to UserSearch is a good place to start.

Stop guessing. Start researching with UserSearch at usersearch.com. One account, 100+ third-party data sources, OneScan, Cases and SargeBot reports.

References

About the author

UserSearch Team
Updated on Sep 26, 2026