Skip to main content
Tutorial — Email OSINT (public footprint only)
Skill: osint-identity-researcher
Time: ~20 minutes
Goal
Determine whether an email appears in public breaches or public directories — for security or corroboration, not doxxing.
Steps
- Confirm you have lawful authority to query (your org’s email, or public campaign contact).
- Use reputable breach-status tools that do not exfiltrate the address to untrusted parties (follow org policy).
- Record which breach and year only; do not reuse passwords.
- If address is historic, note that it may no longer be valid.
- Never publish full breach dumps or paste credentials.
- For private individuals, default to not searching.
Pitfalls
- Typo squat addresses.
- Shared inboxes at campaigns.
