An email address is a high-value artifact: it is often reused across services and tied directly to a real identity. This method checks exposure and pivots outward to the accounts and person behind the address.
What you'll need
- The target email address
- Breach-check and exposure tools from the Data Acquisition category
- Email-investigation tools from the Phone Numbers & Emails category
Steps
- Check for breach exposure. Run the address through breach-lookup services to see whether it appears in known data breaches. Exposure both confirms the address is real and hints at where the person has accounts.
- Discover registered services. Some email-investigation tools reveal which platforms an address has registered with, often surfacing accounts you would not otherwise find.
- Test the address on platforms directly. Many sites' password-reset or sign-up flows indicate whether an email is already registered — a careful way to confirm account existence without contacting the person.
- Pivot to linked accounts. Registered services and breach data expose usernames and profiles. Feed these into the username method above to map the full account set.
- Analyse the address itself. The format (firstname.lastname, a handle you have seen before, a company domain) can reveal a real name, an employer, or a reused alias worth searching.
- Corroborate identity. Tie the address to a person only when independent evidence — a profile, a public record, a consistent handle — supports it.
Common pitfalls
- Assuming breach data is current or complete. Absence from breach databases does not mean the address is unused; treat every source as one input.
- Contacting the subject. Never email or otherwise alert the person — it compromises the investigation and crosses ethical lines.
- Over-attributing. A shared or role address (info@, admin@) may not map to one individual.
Verify your result
You have investigated the address when you can state its breach exposure, the accounts credibly linked to it, and — where the evidence supports it — the identity behind it, each finding tied to a source. A clear "no exposure found" is itself a legitimate, documented result.