Skip to main content

The Advanced Guide to Email OSINT: Verifying Addresses Beyond the Inbox

An email address connects domains, accounts and organisations. Learn how to check mail setup, headers, account presence and domain history to verify who operates an address before you act on it.

· By UserSearch Team · 9 min read

Disclaimer: This article is for education and for lawful, authorised professional research. Use these methods only where you have a legitimate purpose and a lawful basis, and follow the laws and platform terms that apply to you, including data protection law such as the UK GDPR and EU GDPR. See our Terms of Service.

TL;DR

  • The Problem: Email addresses are often treated as simple contact points, but they are persistent identifiers that connect accounts, domains and organisations.
  • The Approach: By combining technical analysis (MX, SPF, DMARC, headers) with account presence checks and domain research, analysts can verify whether an email address really belongs to the organisation it claims to represent.
  • The Workflow: We cover manual techniques (search operators, DNS checks, Gravatar hashing) and show how to scale them with the UserSearch Email Intelligence and Domain Intelligence Search types, including ProtonMail key analysis.
  • The Outcome: You will learn to tell established business addresses from newly created ones, date an address from its public key, and build defensible findings for payment verification and due diligence.

2.1 The Anchor Identifier: Why Email Matters in OSINT

Among online identifiers, the email address sits near the top, arguably above the phone number. Why? Because it is the key for almost every online interaction. Organisations need one to register a domain, open a supplier account, sign up to a payment platform or publish an app.

For Open Source Intelligence (OSINT) analysts, that makes the email address an excellent pivot point. It is the thread that connects an organisation's domains, its public accounts, its supplier relationships and its history. Unlike a username, which can be changed on a whim (moving from @SignalsDesk99 to @CryptoKing), an email address tends to stick. Changing a primary business address means changing dozens of accounts, invoices and contacts. As a result, organisations often keep the same addresses for years.

However, simply having an email address is not enough. The internet is full of throwaway addresses, spam traps and abandoned accounts. The challenge for the analyst is attribution: showing that [email protected] is actually operated by the supplier it claims to be, and what its history says about how far you can rely on it. This guide goes beyond basic lookup tools to the practical tradecraft of email research.

2.2 Defining Email Intelligence

Email Intelligence is the process of taking an email address and working outwards to establish which organisation operates it, how long it has existed, where it is registered and what risk it carries. Unlike forward searching (looking up a company to find its contact address), this approach relies on the public signals that an email address and its domain leave across the internet.

The discipline generally falls into three technical buckets:

  1. Technical Validation: Checking the domain's mail setup (MX records, SPF, DKIM and DMARC) to see whether the address can exist and how the domain handles mail. SMTP itself is defined by standards such as RFC 5321.
  2. Account Presence: Checking whether the address is linked to public accounts and services such as Gravatar, GitHub, app store developer pages or business directories.
  3. Domain and History Correlation: Researching the domain behind the address (registration date, WHOIS history, hosting and past versions of the website) to build a timeline of the organisation's online activity.

It is important to keep this work passive. Sending test emails or contacting the address can change the situation you are trying to understand. Good OSINT observes the signals that are already public.

2.3 The Strategic Value of Email Attribution

Why does careful email attribution matter? In security and fraud work, the email address is often the only lead you have.

Consider BEC (business email fraud), where a message that appears to come from a supplier or executive asks for a payment. The FBI's Internet Crime Complaint Center keeps warning organisations about it, most recently in a public service announcement on BEC. If a supplier suddenly emails you from a new address asking to change bank details, a quick email research check can show whether that address and its domain were created last week (a serious red flag) or have been active on professional platforms and business registers for ten years.

The same checks help with due diligence and brand protection. A domain registered a few days ago that copies your supplier's name, with no mail security records and no history, tells you a lot before a single invoice is paid. For legal and finance teams, this is one of the cheapest controls available. See how teams in insurance and fraud prevention use these checks.

2.4 The Manual Research Workflow (The Hard Way)

Before relying on platforms, every analyst should know the manual techniques. Checking an email address by hand teaches you to interpret the false positives and nuances that tools might miss.

Technique 1: Advanced Google Dorking

Search engines index email addresses that appear in public text: PDF reports, forum signatures, supplier lists and company websites. Use exact-match operators to cut noise.

"[email protected]"
site:linkedin.com "supplier-example.com"
site:supplier-example.com "@supplier-example.com"
filetype:pdf "[email protected]"

The site: query on the company's own domain shows which addresses the organisation publishes itself. The filetype:pdf query often brings up invoices, tender documents or conference exhibitor lists that confirm the address is used in normal business.

Technique 2: Checking the Domain's Mail Setup

A legitimate business domain usually has a consistent mail configuration. A lookalike domain registered in a hurry often does not. You can check this in seconds with dig:

dig +short MX supplier-example.com
dig +short TXT supplier-example.com
dig +short TXT _dmarc.supplier-example.com

The first command lists the mail servers, the second shows TXT records including SPF (the list of servers allowed to send for the domain), and the third shows the DMARC policy. Missing SPF and DMARC records on a domain that claims to be an established supplier are worth noting. The NCSC's email security and anti-spoofing guidance explains what good configuration looks like. Compare the results with the real supplier's domain: different mail providers on two domains that claim to be the same company is a strong signal.

Technique 3: Avatar Hashing (Gravatar)

Many services, including WordPress and GitHub, use Gravatar to display user icons. Gravatar URLs are based on a hash of the email address. By generating this hash, you can check whether a public Gravatar account exists.

Step-by-step:

  1. Take the email: [email protected].
  2. Trim whitespace and lowercase it.
  3. Generate the MD5 hash (for example in a terminal: echo -n "[email protected]" | md5sum).
  4. Visit: https://en.gravatar.com/HASH_GOES_HERE.json.

If a public account exists, the JSON response returns its display name and any links the owner has chosen to publish, such as a company website. For a business address, a Gravatar that points to the company's real site is a useful piece of corroboration.

Technique 4: Reading the Message Headers

If you have received the email itself, the full headers are the best evidence you have. In most mail clients you can open them with "Show original" or "View source". Look at:

  • Authentication-Results: whether SPF, DKIM and DMARC passed for the sending domain.
  • Return-Path and Reply-To: whether replies go to a different domain from the one shown in the From line.
  • Received lines: which mail provider actually handled the message, read from the bottom up.

A message that shows your supplier's name in the From line, fails DMARC and sets a Reply-To on a free webmail address is the classic pattern behind payment change requests.

2.5 Structured Email Intelligence with UserSearch

Manual checks are precise but slow. When you are reviewing 50 supplier addresses, you cannot hash each one or read DNS records by hand. This is where UserSearch moves the workflow from manual to structured.

UserSearch gives you access to 100+ third-party data sources through one account, so you do not need separate accounts with each provider. Instead of opening ten tabs, you run a structured workflow:

Step 1: The Presence Check

Start with the Email Intelligence Search type. Its Modules check where an address is registered and which public accounts are connected to it, which gives you a quick picture of how established the address is. With bulk search, you can run up to five addresses through one Module in a batch.

Step 2: OneScan Enrichment

For deeper analysis, use Email OneScan. OneScan runs one address across several selected data sources and merges the results with source attribution. The Credit cost is the sum of the selected sources and is shown before you run it. This is the scaled equivalent of the manual checks above, across many more services.

Typical results include:

  • Registered accounts: business and developer platforms where the address is in use.
  • Public account details: display names, company names and linked websites.
  • First-seen dates: where a source provides them, an indication of how long the address has been active.

Step 3: Domain History

Pivot from the address to its domain in the Domain Intelligence Search type to see ownership, registration history and favicon matches. If the domain was registered last month and its favicon matches three other lookalike domains, you have a pattern. If it has been registered to the same company for a decade, that supports the address being genuine. For a full walkthrough of the domain side, see our domain OSINT guide.

2.6 Advanced Attribution Tradecraft

Now that we have the data, how do we turn it into an intelligence product? Here are three strategies used by experienced analysts, plus a worked example.

Strategy 1: The "Dormant Address" Analysis

In fraud research, you often meet "aged" addresses. Fraud groups buy old webmail accounts or let expired domains lapse and re-register them, because an older address looks more trustworthy. Your job is to show whether the address has been in steady use by the same organisation.

The Workflow:

  1. Run the address through Email OneScan and note any first-seen dates.
  2. Check the domain history. You see a registration in 2013, a website until 2015, then nothing.
  3. In 2024, the domain is re-registered and used to open a new supplier account.
  4. Conclusion: The gap (2015 to 2024) suggests the original business stopped using the domain and someone else picked it up. A genuine supplier rarely goes quiet for nine years and then returns asking for a payment change.

Strategy 2: ProtonMail Key Analysis and PGP

Privacy-focused services such as ProtonMail are often treated as dead ends. However, because ProtonMail uses PGP encryption, it publishes public keys for its users, and those keys contain metadata.

The Workflow:

  1. Use the ProtonMail Analyse Module in UserSearch on the address under review (for example [email protected]).
  2. The Module retrieves the PGP public key.
  3. Analysis: The key contains a creation timestamp. You can now check whether the address was created specifically for this request. If a "long-standing supplier" sent its first invoice at 10:00 and the key was created at 09:55 the same day, the claim does not hold. If the key was created three years ago, the address is a longer-term asset and may connect to earlier activity.

Strategy 3: The Shared Infrastructure Pivot

Sometimes the address itself leads nowhere, but its domain leads everywhere. Operators who register lookalike domains often reuse the same registrar, name servers, hosting and website template.

The Workflow:

  1. Take the domain from the address and run it through Domain Intelligence.
  2. Note the name servers, hosting IP and favicon.
  3. Pivot on each: other domains on the same IP, other domains with the same favicon, and archived versions of the site.
  4. Outcome: You might find that supplier-example-payments.com shares a hosting IP and favicon with four other domains copying different suppliers' names. You have now linked a single email address to a wider campaign.

Worked Example: A Payment Change Request

Context: The finance team at a fictional wholesaler, Tollgate Provisions, receives an email from [email protected] asking to change bank details. Their real supplier uses brightmoor-example.com.

The Workflow:

  1. The analyst reads the headers: DMARC fails and Reply-To points to a free webmail address.
  2. dig shows no SPF or DMARC records on the new domain.
  3. Domain Intelligence shows the domain was registered six days earlier; Email OneScan finds no registered accounts for the address.
  4. Outcome: The team rejects the change, confirms bank details with the supplier by phone using the number on file, and reports the domain to the registrar and to the authorities.

Email research must stay firmly within the law. It sits close to personal data, so the rules matter.

  • Observe, Do Not Access: Limit your work to identifying accounts and domains from public information. Signing in to an account you discover is outside OSINT and can be an offence under the Computer Misuse Act in the UK and the Computer Fraud and Abuse Act (CFAA) in the US.
  • GDPR and Personal Data: In the UK and EU, an email address that relates to a person is personal data. You need a lawful basis (such as legitimate interests for fraud prevention) to process it, and you should keep only what your purpose needs.
  • Terms of Service: Many platforms prohibit automated collection. UserSearch queries third-party data sources on your behalf, but you should still avoid running high-volume collection tools against platforms from your own IP address.

2.8 From One Address to Defensible Findings

The email address is one of the most useful keys in OSINT. It connects domains, accounts and organisations, links present activity to past activity, and shows risks that a quick glance at an inbox will miss. Whether you are checking a supplier, verifying a payment request or researching a campaign that copies your brand, the ability to move from an email address to a verified organisation is an essential skill.

The window for purely manual work is closing. As platforms tighten their privacy settings and API limits, the hard way is getting harder. With UserSearch you get one account, many sources, OneScan to combine them and Cases to keep your research organised for the report.

Stop guessing. Start researching with UserSearch at https://www.usersearch.com.

About the author

UserSearch Team
Updated on Sep 26, 2026