what-an-email-reveals

Solid

Investigate an email address — MX and syntactic validation, Gravatar lookup, corporate email-format inference, breach exposure, and full mail-header analysis covering the Received chain, Message-ID and SPF, DKIM and DMARC results. Use for email OSINT, verifying whether an address exists, finding accounts registered to it, guessing a company's email format, or tracing where a suspicious message actually came from. Applies to business email compromise and invoice-fraud investigation, phishing triage, vendor-payment verification, and pre-engagement research. Reference at useosint.com/skills/what-an-email-reveals.

AI & Automation 42 stars 4 forks Updated 1 months ago MIT

Install

View on GitHub

Quality Score: 82/100

Stars 20%
54
Recency 20%
75
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# What an email reveals An email address is usually the highest-value selector in an investigation: it carries a name, a domain, an account history, and a breach footprint. The beginner error is trying to prove the address exists. Existence is the least interesting thing about it, it is the hardest thing to establish passively, and the techniques that establish it are the ones that expose you. Work the structure and the footprint first; treat validation as a bonus. Never send mail to the subject as a research technique. ## Step 1 — Authorized scope Read [../../ETHICS.md](../../ETHICS.md). Write down subject, objective, in-bounds selectors, out-of-bounds actions, and the governing jurisdiction. Decide in advance whether *interactive* probing — SMTP conversations, password-reset flows, signup-form enumeration — is authorized. It usually is not. Everything below is passive unless marked otherwise. **Done when** scope is written and the interactive-probing decision is recorded. ## Step 2 — Parse and validate Three different things get called "email validation". They are not interchangeable. | Method | What it proves | Cost | |---|---|---| | Syntactic | The string could be an address | Free, passive, proves nothing about the mailbox | | Domain / MX | The domain exists and accepts mail | Free, passive, `dig MX example.com` | | SMTP `RCPT TO` probe | The server claims the mailbox exists | Interactive, often blocked or lied to, and logged | Do the first two. The third — open...

Details

Author
useosint
Repository
useosint/osint-skills
Created
1 months ago
Last Updated
1 months ago
Language
Shell
License
MIT

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Listed

email-validate-post-email

Validates a single email address and returns a full breakdown of syntax validity, MX record status, disposable domain check, normalized form, and any typo suggestion.

2 Updated 5 days ago
bobadilla-tech
Data & Documents Listed

phishing-analysis

Analyze a reported or suspicious email end to end: Received chain and SPF/DKIM/DMARC alignment, sender and Reply-To and display-name mismatches, lookalike domains, URL and redirector analysis, QR codes, HTML smuggling, attachment triage, lure classification (BEC/invoice, credential harvest, callback/TOAD, MFA push, package delivery, HR/payroll), verdict, blast radius, and response actions. Use it whenever someone pastes headers or an .eml, says "is this phishing", "a user reported this email", "check these headers", "is this sender legit", "who else got this", asks why DMARC failed, wants a phishing triage note, or forwards a suspicious invoice, voicemail, DocuSign, MFA, delivery, or payroll-change message, even if they never use the word phishing.

0 Updated 1 weeks ago
ftrout
AI & Automation Listed

email-verification

Verify email addresses before sending so bounces never damage a sending domain, and interpret each verification status correctly. Use whenever the user mentions email verification, email validation, bounce rate, hard bounces, invalid emails, catch-all domains, disposable addresses, MX records, list cleaning, or asks whether an address is real. Also use before launching any cold email campaign, and when a campaign has been paused for bounces.

0 Updated 2 weeks ago
manypicom