Email OSINT Search — 120+ Sites Account Discovery
Pricing
from $20.00 / 1,000 account founds
Email OSINT Search — 120+ Sites Account Discovery
Discover which 120+ sites an email address is registered on (LinkedIn, Twitter, Spotify, Pinterest, Imgur, and more) using the open-source holehe tool. No password-reset emails sent to target. For authorized OSINT and security research.
Pricing
from $20.00 / 1,000 account founds
Rating
0.0
(0)
Developer
daehwan kim
Maintained by CommunityActor stats
3
Bookmarked
851
Total users
145
Monthly active users
6 hours ago
Last modified
Categories
Share
Find which accounts an email address has signed up for. This email lookup / email OSINT tool discovers which 120+ sites an email is registered on — LinkedIn, Twitter, Spotify, Pinterest, Imgur, Tumblr, and many more — without ever sending a password-reset notification to the target. A fast reverse email search powered by holehe (GPL-3.0, 5.6k+ stars), the standard open-source email OSINT tool — ideal for fraud checks, KYC, and finding out where an email is used.
Built for security researchers, fraud investigators, OSINT analysts, KYC teams, and recruiters who need to verify online presence of a given email address with zero footprint.
Legal Disclaimer: This Actor is an unofficial integration of holehe (megadose) and is not affiliated with or endorsed by the original project. Use only on email addresses you own or have explicit authorization to investigate. Comply with PIPA (KR), GDPR (EU), CCPA (US), and applicable privacy laws.
Why this Actor
- 120+ sites checked in one call (LinkedIn, Twitter/X, Spotify, Pinterest, Imgur, Tumblr, Adobe, Atlassian, etc.)
- No password-reset emails sent to target — uses passive account-existence signals
- Structured JSON output — site name, domain, category per match
- Bulk mode — process up to 500 emails per run (hard cap)
- Pay only per account found — $0.02 per confirmed account
- No subscription, no setup, no scraping — just an API call
Use Cases
- Security incident response — given a breached email, map exposure across SaaS
- Fraud investigation — confirm an email is a real online identity, not a throwaway
- Recruiter verification — confirm candidate email is registered on professional platforms
- KYC enhancement — supplement identity verification with online-account footprint
- OSINT pentesting — reconnaissance phase for authorized engagements
- Data-broker compliance — auditing your own organization's email exposure
Input
| Field | Type | Required | Description |
|---|---|---|---|
emails | array of string | ✅ | Up to 500 email addresses to investigate |
email | string | — | Legacy single-email input (use emails for batch) |
timeout | integer | — | Per-site timeout in seconds (default 30) |
maxEmails | integer | — | How many emails this run processes; hard cap 500 |
{"emails": ["alice@example.com", "bob@example.org"],"timeout": 30,"maxEmails": 10}
Output
One dataset item per email:
| Field | Type | Description |
|---|---|---|
email | string | Email checked |
foundCount | integer | Number of registered accounts discovered |
found | array | List of {site, domain, category, rateLimit, fullName, phoneNumber} |
sitesChecked | integer | Total sites probed |
error | string | Populated only on per-email failure |
disclaimer | string | Legal-use notice |
{"email": "alice@example.com","foundCount": 7,"found": [{"site": "LinkedIn", "domain": "linkedin.com", "category": "social", "rateLimit": false},{"site": "Twitter", "domain": "twitter.com", "category": "social", "rateLimit": false},{"site": "Spotify", "domain": "spotify.com", "category": "music", "rateLimit": false}],"sitesChecked": 121}
Pricing
- $0.02 per registered account found (event:
account-found) - No charge for sites where the email is NOT registered
- No charge for failed/rate-limited sites
- Apify platform compute usage is included (no separate charge)
Cost example: Email registered on 10 sites = $0.20. Email registered on 50 sites = $1.00.
Large batches and the run charge limit
Every Apify run has a maximum cost, which you set per run (or per schedule) in the Actor's Run options. This Actor accepts up to 500 email addresses in a single run, and a big batch can easily find more accounts than the default limit covers.
When a run reaches its charge limit, this Actor stops checking and finishes successfully with everything it found up to that point, plus a final Charging limit reached record explaining what happened. You are never charged past your limit, and the run is not reported as a failure.
To get the full batch, do one of the following:
- Raise the run's maximum cost in Run options before starting, or
- Split the email addresses across several runs — for example 25 emails per run instead of 500.
Quick Start
curl
curl -X POST "https://api.apify.com/v2/acts/ntriqpro~email-osint-search/runs?token=YOUR_TOKEN" \-H "Content-Type: application/json" \-d '{"emails": ["alice@example.com"]}'
Python (Apify Client)
from apify_client import ApifyClientclient = ApifyClient("YOUR_TOKEN")run = client.actor("ntriqpro/email-osint-search").call(run_input={"emails": ["alice@example.com", "bob@example.org"]})items = list(client.dataset(run["defaultDatasetId"]).iterate_items())for item in items:print(f"{item['email']}: {item['foundCount']} accounts")for hit in item['found']:print(f" - {hit['site']} ({hit['category']})")
Limitations
| Limitation | Detail |
|---|---|
| Sites blocking holehe | Some platforms have added defenses; ~10-15% sites may return rate-limited |
| False positives | Existence signals can be ambiguous; treat as leads, not proof |
| New site discovery | holehe upstream adds sites quarterly; we update with library releases |
| Rate limiting | Recommended: batch <10 emails per run to avoid IP-based throttling |
Technology
- holehe (GPL-3.0) — Email-based account existence checker, 5.6k+ stars
- Apify SDK for Python (Apache 2.0) — Actor runtime
- httpx (BSD) — Async HTTP client
Disclaimer
This Actor is an unofficial open-source wrapper around megadose/holehe. It is not affiliated with, sponsored by, or endorsed by the holehe project, its maintainers, or any of the platforms being probed. OSINT results are based on publicly observable account-existence signals and may produce false positives.
You are solely responsible for ensuring you have legal authorization to investigate any email address. Misuse may violate privacy laws (PIPA, GDPR, CCPA, etc.) and the terms of service of target platforms. This tool is intended for security research, fraud prevention, and authorized investigation use only.
Privacy & data responsibility
You are the data controller for every search you run with this Actor; ntriqpro is a data processor acting solely on your instructions. You are responsible for having a lawful basis and a legitimate, purpose-limited reason for each lookup, and for complying with GDPR, PIPA, CCPA, and other applicable privacy laws. We do not store your results — output is written only to your own run's dataset and is never retained on our side. Use this Actor only for lawful purposes and only on email addresses you own or are authorized to investigate.
🔗 Related Actors by ntriqpro
Running several of these by hand? OSINT Recon Suite takes one target — email, username, domain or phone — runs Maigret, Sherlock, holehe, theHarvester, WHOIS and dnstwist against it, then correlates everything into a single risk-scored report. One input, one report, instead of six separate runs to stitch together yourself.
Build your full OSINT stack:
- maigret-actor — Username OSINT across 3000+ sites (5.0★ rated)
- phoneinfoga-osint — Phone number OSINT — carrier, country & footprint
- dnstwist-osint — Typosquatting & phishing domain detector
- subfinder-osint — Subdomain finder for attack-surface mapping
- gitleaks-secret-scanner — Find leaked secrets in public repos
⭐ Rate this Actor
If this saves you investigation time, please leave a review — it helps other security researchers discover it.