Email Intelligence
What This Is
Email intelligence covers the full workflow of finding, verifying, and extracting value from email addresses during an OSINT investigation. An email address is one of the most useful identifiers available: it can confirm a real name, link accounts across platforms, reveal infrastructure, expose breach history, and map an organisation's internal structure.
This phase sits at the intersection of identity research and infrastructure mapping. The techniques here apply equally to individual subject profiling and to corporate reconnaissance.
When to Use This
Use email intelligence when you have any of the following starting points:
A name and organisation you want to find contact details for
An email address you want to verify or attribute to a real identity
A domain you want to map the email structure of
A suspected email address from a breach or leaked dataset
An email header from a received message you want to trace
The Workflow
Email intelligence runs in four stages. Discovery finds candidate addresses. Verification confirms which addresses are live. Identity resolution attributes addresses to real people or accounts. Infrastructure analysis maps the domain's email setup to understand the organisation and identify further attack surface.
Each stage feeds the next. A verified email from discovery can be run through breach databases in the resolution stage. Infrastructure analysis often reveals additional email patterns that expand the discovery stage on the same domain.
Subpages
Email Address Discovery and Harvesting — find email addresses associated with a person or organisation
Email Verification and Validation — confirm whether a discovered address is live and deliverable
Email-to-Identity Resolution — attribute an email address to a real person using breach data and header analysis
Email Infrastructure Analysis — map MX, SPF, and DMARC records to profile an organisation's email setup
OpSec Note
Some verification techniques send a live request to the target mail server. This is visible in server logs and can alert a target organisation's security team. Use disposable infrastructure for any active verification steps and be aware that SMTP probing from the same IP across multiple domains is a detectable pattern.
Was this helpful?
Your feedback helps improve this page.