Skip to main content

Email OSINT: A Practical Guide to Researching Business Email Addresses

A practical guide to email research for due diligence, security and trust and safety teams: search operators, header reading, DNS and domain checks, and how to verify the organisation behind an address with UserSearch.

· By UserSearch Team · 11 min read

Disclaimer: This article is for education and for lawful, authorised professional research. Use these methods only where you have a legitimate purpose and a lawful basis, and follow the laws and platform terms that apply to you, including data protection law such as the UK GDPR and EU GDPR. See our Terms of Service.

TL;DR

  • The Problem: Business email addresses turn up in supplier onboarding, invoice requests, seller vetting and suspicious messages, but checking them by hand across many sources is slow and patchy.
  • The Approach: Structured email research combines technical checks (headers, DNS, domain registration) with public-source research to establish which organisation operates an address and whether its claims hold up.
  • Key Techniques: We cover precise search operators, header reading, MX, SPF and DMARC records, domain age, public avatar checks and username pivots.
  • The Outcome: You will learn how to turn a single email address into a verified, sourced finding about the business behind it, using manual methods and UserSearch Email Intelligence.

An email address is rarely just a way to send messages. For a business, it is often the first thing a new supplier, customer or partner gives you, and the thing a bad actor changes when they want a payment to go somewhere else. For analysts in due diligence, security and trust and safety teams, email research is the difference between a vague feeling and a documented decision.

Every organisation that sends email leaves public, technical evidence behind it: a domain with a registration date, mail servers with names, sender policies published in DNS, and a history of where the address appears on the open web. These are not noise. They are the signal. Understanding how to read headers, DNS records and public registrations lets you judge whether a sender really is the company it claims to be.

We have seen plenty of reviews stall because an analyst stopped at a single Google search. They missed the domain registered nine days earlier, the mail server that did not match the company's real one, or the same contact address reused across several unrelated seller accounts. This guide is your blueprint for going further, in a way you can defend later.

In this walkthrough we will break down how to research an email address from scratch. We will cover the manual techniques experienced analysts use, the command-line checks behind them, and how to scale your workflow with UserSearch 2.0 so scattered results become a clear, sourced finding.


What Is Email Research in OSINT?

Email research is the process of using an email address as a starting point to establish publicly available facts about the organisation or account that uses it. Open-source intelligence relies on information that has been published, registered or indexed in public, never on access you are not entitled to.

At its core, this technique answers three questions:

  1. Operator: Which business or organisation runs this address and its domain? (Registrant details where published, company registers, websites.)
  2. Presence: Where does this address appear in public? (Company websites, code repositories, marketplaces, public forums.)
  3. Consistency: Does the technical setup match the claims? (Domain age, mail servers, sender policies, public reports of misuse.)

The answers are leads to corroborate, not verdicts. An email address can be shared by a team, reassigned when staff leave, or set up by a third party on a company's behalf, so every finding needs a second source before it drives a decision.


Why It Matters: The Cost of an Unchecked Sender

Why do we pay so much attention to email addresses? Because they are sticky. Businesses change phone numbers and social usernames, but a company domain and its main contact addresses often stay in place for years. When a sender suddenly writes from a lookalike domain or a free webmail account, that change is itself worth checking.

The scale of the problem is well documented. The FBI's Internet Crime Complaint Center 2024 report again lists BEC, where a business is persuaded to pay a message that appears to come from a trusted contact, among the costliest categories of complaint. Many of those losses start with a payment request from an address that nobody checked. Security teams in our cyber security audience see the same pattern in suspicious messages reported by staff. For a wider view of how email addresses appear across historical data sets, see our related email research guide.

Whether you are onboarding a supplier, reviewing a suspicious invoice or verifying a marketplace seller, the ability to move from an email address to a verified organisation is a core skill. Missing these connections can lead to paid invoices that should have been queried or approved sellers who should have been reviewed. The UK's NCSC guidance on suspicious messages sets out why checking the sender is one of the most useful habits an organisation can build.


The Manual Method: Researching the Long Way

Before using automated tools, it is worth understanding the mechanics of a manual review. If you had no budget and only a web browser and a terminal, how would you research an email address? Here is the manual workflow we recommend learning.

1. Advanced Search Operators

Search engines index more than web pages. They index PDF brochures, public spreadsheets, supplier lists and forum signatures. Use exact-match operators to make the engine look for the address itself.

The basic query:

"[email protected]"

The document query:
Find the address inside published documents, which often include supplier lists, price sheets or public staff directories.

"[email protected]" filetype:pdf OR filetype:xlsx OR filetype:txt

The site-specific pivot:
Check whether the address appears on specific platforms such as GitHub or LinkedIn company pages.

site:github.com "[email protected]"
site:linkedin.com "[email protected]"

The quotation marks force an exact match, filetype: limits results to one document type, and site: restricts results to a single domain. Expect gaps: search engines do not index everything, and results vary by region.

2. Email Header Analysis

If your organisation has received a message from the address, you hold useful technical evidence: the header. Many large providers do not include the sender's own IP address, but corporate servers and self-hosted mail systems often do.

To view headers in Gmail, click the three dots next to the reply button and select "Show original". Look for lines like:

Received: from [192.0.2.10] (helo=mail.example.com)
X-Originating-IP: [203.0.113.45]
Reply-To: [email protected]

Plug the IP address into an IP lookup such as MaxMind GeoIP. It may show the network operator or hosting provider the message came from. This matters when a supplier that claims to run its own London office mail server is actually sending from a consumer broadband range abroad. Also compare the Reply-To line with the sender: a different domain in the reply address is one of the most common signs of a redirected payment request.

3. Mail Server and Sender Policy Checks

DNS tells you how a domain handles mail and whether the owner has published rules about who may send on its behalf. The UK's NCSC email security and anti-spoofing guidance explains SPF, DKIM and DMARC in detail. The dig tool is installed on most Linux and macOS systems.

# Which servers receive mail for the domain
dig MX example.com +short

# The sender policy (SPF) and other TXT records
dig TXT example.com +short

# The DMARC policy
dig TXT _dmarc.example.com +short

MX asks for mail exchange records, TXT returns text records such as SPF, and +short trims the output to the answers only. A long-established company with no SPF or DMARC record is unusual. A domain whose MX points at a free forwarding service while the sender claims to be a large manufacturer is a question to raise. If you prefer a browser, MXToolbox runs the same lookups.

4. Domain Registration and Age

Next, look at when the domain was registered and through which registrar. ICANN's registration data lookup returns the RDAP record for most generic domains.

# Command-line alternative on most systems
whois example.com | grep -iE "creation date|registrar:|name server"

grep -iE filters the output, ignoring case, to the creation date, registrar and name servers. Registrant names are usually redacted for privacy, so do not expect a name. What you get is timing: a domain created a week before the first invoice arrived deserves a closer look.

5. Public Avatar Checks

Some business addresses are tied to a public Gravatar image, often a company logo. Gravatar's developer documentation explains that images are requested using a SHA-256 hash of the trimmed, lower-case address.

# Create the identifier, then request the image (no image returns a 404)
HASH=$(printf '%s' "[email protected]" | tr '[:upper:]' '[:lower:]' | sha256sum | cut -d' ' -f1)
curl -s -o avatar.png -w "%{http_code}\n" "https://gravatar.com/avatar/$HASH?d=404"

tr lowers the case, sha256sum creates the hash, and d=404 asks the service to return an error rather than a default image. A logo that matches the company's website is a small point in favour. A stock image reused elsewhere is a point to check.


Scaling Your Research With UserSearch

The manual method works, but it is slow. Running queries, reading DNS output and checking several websites one by one can take 20 to 30 minutes per address. In a busy onboarding queue or a case with dozens of identifiers, you do not have that time.

This is where UserSearch changes the workflow. Instead of switching between tools, you use one account to reach 100+ third-party data sources. Email Intelligence Modules check where an address is registered and what public information is attached to it. OneScan runs one input across the sources you select and merges the results with source attribution, showing the Credit cost before you run it. Domain Intelligence covers ownership, history and favicon checks for the domain behind the address.

Scenario 1: The Supplier Bank Detail Change

The Context: The finance team at Fernbrook Joinery, a fictional manufacturer, receives a request to change the bank details for a regular timber supplier, Alder & Pike Timber. The request comes from [email protected]. The supplier's usual address uses alderpiketimber.example, without the hyphen.

The Manual Problem: A search for the new address returns nothing. The message looks genuine and quotes a real invoice number.

The UserSearch Workflow:

  1. Domain Intelligence: The analyst runs the hyphenated domain. The registration date is eleven days old, while the supplier's real domain has a history going back years.
  2. Email Intelligence via OneScan: The analyst runs both addresses through OneScan. The established address appears on the supplier's website, a trade directory and a company register filing. The new address appears nowhere.
  3. Header check: The header shows a Reply-To on a third domain and a sending IP in a hosting range unrelated to the supplier's mail provider.

The Outcome: Finance calls the supplier on the number held in its own records, not the one in the email. The supplier confirms it made no change. The findings are saved in a Case in Forensic Mode, and the payment goes to the correct account.

Scenario 2: The Repeat Seller Contact Address

The Context: The trust and safety team at Quayside Collectibles, a fictional online marketplace, is reviewing a new seller account after buyer complaints. The contact address is [email protected].

The UserSearch Workflow:

  1. Email Intelligence: The analyst checks where the address is registered. It returns several marketplace and forum accounts.
  2. Public avatar: The linked avatar is a product photo. A Picture search (reverse image search) shows the same image on listings from two other seller accounts under different names.
  3. Public Forums: A Reddit thread in a collectors' community describes non-delivery by a seller using the same contact address.
  4. Username Intelligence: The local part, vintage.parts.1985, is also the handle on two of the other seller accounts.

The Outcome: The team has a documented link between three seller accounts through one contact address, one reused image and one handle, each with its source. It applies the platform's policy on linked accounts and records the reasoning. The review stays within the marketplace's own accounts, because the purpose did not need more.


Advanced Strategies: Going Beyond the Basics

Once you are comfortable with the basic checks, these strategies help with harder cases.

1. Reading Registration Dates Together

An address on its own tells you little about age. Put three dates side by side: when the domain was registered, when its mail records first appeared in the Domain Intelligence history, and when the address first shows up in public sources. A company claiming ten years of trading whose domain, mail records and first public mention all date from last month has some explaining to do.

2. Image Reuse Analysis

If your email research returns an avatar or a logo, do not stop there. Run it through a Picture search in UserSearch or a service such as TinEye. We often see stock photos and borrowed logos reused across unrelated businesses. Two addresses that share one uncommon image are worth linking in your notes, then corroborating from a second source before you draw any conclusion.

3. Cross-Referencing Usernames

Take the local part of the address (for example vintage.parts.1985) and run a separate Username Intelligence search on it. Sellers and businesses often keep the same handle on platforms where the email itself is not shown. This widens your review from a few dozen sites to thousands. Our advanced username OSINT guide covers how to confirm that matching handles really belong to the same operator.

4. Disposable and Short-Lived Domains

Sometimes your research reaches a dead end because the address uses a temporary inbox service or a freshly registered domain. Less experienced analysts stop here. Experienced analysts look at the DNS.

The DNS workflow:

  1. Check MX records: Use dig to see which server receives mail for the domain.
dig MX example.net +short

If the answer points to a known temporary inbox provider, treat the address as short-lived and move to other identifiers, such as the website, the IP address or the handle, rather than spending Credits on enrichment.

  1. Check the SOA record: The Start of Authority record includes a contact mailbox for the DNS zone, written with a dot in place of the @ sign.
dig SOA example.net +short

We have seen cases where several lookalike domains shared one unusual SOA contact, such as hostmaster.example-parent.com. That shared detail can connect a group of domains to one operator, which is exactly the kind of infrastructure link a security or brand team needs before it files takedown requests.

5. Weighing Public Reports Carefully

When an address appears in a public complaint, a forum thread or a warning list, context is everything. Check the date, the author and whether the report names the same address exactly or a close variant. One unverified post is a lead. Several independent reports that match your own technical findings are a stronger basis for a decision. Record each source in your Case so a colleague can follow your reasoning.


Email research uses personal data whenever an address belongs to a person, including many business addresses. Treat that seriously.

  • Public information only: Work with information that is published, registered or indexed in public. Stay out of accounts that are not yours, and use only the access you are entitled to.
  • Purpose and proportionality: Decide your purpose first, such as supplier due diligence, security research or marketplace policy, and collect only what that purpose needs. Stop when you have enough to decide.
  • Lawful basis: Under the UK GDPR and EU GDPR you need a lawful basis, such as legitimate interests, for processing personal data. The ICO's guide to lawful basis is the place to start.
  • Record your reasoning: Keep your searches and findings in a Case in Forensic Mode, or capture web pages as evidence with Forensic Capture, so your work can be reviewed.

For practical methodology from experienced open-source researchers, the Bellingcat how-to guides are a good next step.


The Email Intelligence Mindset

An email address is a starting point, not an answer. Followed carefully, it leads to the organisation behind a message, the infrastructure it uses and the public record of how it behaves. Done by hand, that work is slow and easy to get wrong. When a payment or a policy decision depends on it, speed and a clear record both matter.

By combining careful manual checks with the reach of one platform, you can turn a single address into a sourced, reviewable finding. With UserSearch you get Email Intelligence, Domain Intelligence and 100+ third-party data sources through one account, OneScan to merge results with attribution, Cases to keep your work together, and SargeBot to draft a PDF report that you verify before sharing.

Ready to run your next email check properly?
Stop guessing. Start researching with UserSearch.

About the author

UserSearch Team
Updated on Sep 26, 2026