Email OSINT Checker — Account Finder & Reverse Lookup
Pricing
from $10.40 / 1,000 account founds
Email OSINT Checker — Account Finder & Reverse Lookup
Enter an email address and find out where it already has an account — 120+ platforms including LinkedIn, Twitter/X, Spotify, Pinterest, Adobe and Imgur. Nothing is sent to the address: no password-reset mail, no notification. Open-source holehe engine. Batch up to 500 addresses per run.
Pricing
from $10.40 / 1,000 account founds
Rating
5.0
(1)
Developer
daehwan kim
Maintained by CommunityActor stats
6
Bookmarked
1.8K
Total users
208
Monthly active users
7 days ago
Last modified
Share
Email OSINT Checker, Account Finder, Reverse Lookup, 120+ Sites
Give it 1 email address and get 1 row per site it is registered on, out of 120+ sites checked — without any password-reset email reaching the target. Find which accounts an email address has signed up for. This email lookup / email OSINT tool discovers which 120+ sites an email is registered on — LinkedIn, Twitter, Spotify, Pinterest, Imgur, Tumblr, and many more — without ever sending a password-reset notification to the target. A fast reverse email search powered by holehe (GPL-3.0, 5.6k+ stars), a widely used open-source email OSINT tool.
Free Apify plans get a sample, paid plans get the full result set. A run on a free plan returns up to 25 result rows from the first 3 addresses, then finishes successfully with a
Free tier limit reachedstatus message and afree-plan-caprecord — never an error. Any paid plan removes both limits (up to 500 addresses per run, every account found) and applies your plan's Store discount: Bronze 20%, Silver 35%, Gold and above 48% off. See Pricing.
What you get
| Capability | Detail |
|---|---|
| Sites checked | 120+ per email — LinkedIn, Twitter/X, Spotify, Pinterest, Imgur, Tumblr, Adobe, Atlassian, and more |
| Silent lookups | No password-reset emails sent to the target — passive account-existence signals only |
| Flat, table-ready rows | One row per account found, with platform, domain and detection method |
| Bulk mode | Up to 500 emails per run on any paid plan (free plans: first 3 addresses) |
| Extra identity hints | Masked recovery email and masked partial phone, when the platform exposes them |
| Ready to export | Download the dataset as JSON, HTML, CSV or Excel |
| No setup | No subscription, no scraping config — just an API call |
Sample result
One dataset item per registered account found — not one per email. An address registered on 17 sites produces 17 rows.
{"email": "test@gmail.com","platform": "codepen","exists": true,"domain": "codepen.io","method": "register","emailRecovery": null,"phoneNumber": null,"rateLimit": false,"charged": true,"sitesChecked": 121}
| platform | domain | exists | method | rateLimit | |
|---|---|---|---|---|---|
| test@gmail.com | codepen | codepen.io | true | register | false |
| test@gmail.com | anydo | any.do | true | login | true |
A live test of test@gmail.com returned 17 confirmed accounts across 121 sites checked.
Use Cases
- Security incident response — given a breached email, map exposure across SaaS
- Fraud investigation — confirm an email is a real online identity, not a throwaway
- Recruiter verification — confirm candidate email is registered on professional platforms
- KYC enhancement — supplement identity verification with online-account footprint
- OSINT pentesting — reconnaissance phase for authorized engagements
- Data-broker compliance — auditing your own organization's email exposure
Built for security researchers, fraud investigators, OSINT analysts, KYC teams, and recruiters who need to verify online presence of a given email address with zero footprint.
Input
| Field | Type | Required | Description |
|---|---|---|---|
emails | array of string | ✅ | Up to 500 email addresses to investigate |
email | string | — | Legacy single-email input (use emails for batch) |
timeout | integer | — | Per-site timeout in seconds (default 30) |
maxEmails | integer | — | How many emails this run processes; hard cap 500 |
{"emails": ["alice@example.com", "bob@example.org"],"timeout": 30,"maxEmails": 10}
Output
| Field | Type | Description |
|---|---|---|
email | string | The address checked |
platform | string | Platform short name, e.g. codepen |
domain | string | Platform domain, e.g. codepen.io |
exists | boolean | true when an account was detected on that platform |
method | string | How existence was detected: register, login or other |
rateLimit | boolean | true when holehe flags this site as one that throttles frequent lookups (a static property of the site, not a failure of this lookup) — the account is still confirmed, so the row is charged; the flag simply tells you the site is worth re-verifying |
charged | boolean | true when this row was billed as an account-found event |
emailRecovery | string | Masked recovery-email hint, when the platform exposes one (else null) |
phoneNumber | string | Masked partial phone, when the platform exposes one (else null) |
sitesChecked | integer | Total platforms probed for this email |
rowType | string | result, notice, or error |
checkCompleted | boolean | true only when the email investigation finished |
matchStatus | string | found, no-match, incomplete, not-started, or withheld |
accountDetailsDelivered | boolean | On a completed-check summary, whether separately billed account detail rows were delivered |
emailCheckedBillingStatus | string | Whether the separately registered completed-check event was inactive, charged, platform-unbilled, or stopped by a charge limit |
disclaimer | string | Legal-use notice, repeated on every row |
A confirmed account on a site holehe flags as frequently rate-limiting — still billed, with rateLimit: true telling you the site is worth re-verifying:
{"email": "test@gmail.com","platform": "anydo","exists": true,"domain": "any.do","method": "login","emailRecovery": null,"phoneNumber": null,"rateLimit": true,"charged": true,"sitesChecked": 121}
When an address is registered nowhere, you get a completed-check summary row instead
(platform: null, exists: false, checkCompleted: true, matchStatus: no-match,
foundCount: 0). A real engine or system failure is different: it returns an error row
with checkCompleted: false, applies no completed-check or account-found fee, and leaves
the run failed rather than presenting incomplete work as a successful investigation.
You can download the dataset as JSON, HTML, CSV or Excel.
Pricing
Current active billing:
- $0.005 once per valid run (event:
run-started), after input validation and before investigation work begins. - $0.02 per registered account delivered (event:
account-found).
Completed-email fee pending activation: the Actor declares $0.01 per completed
email investigation (event: email-checked), including a completed no-match. The code
checks the run's effective price table and charges this event only after the platform
activates it. Until then, no email-checked charge is attempted. Invalid input and an
engine or system failure that prevents completion never incur this fee.
Free plans and paid plans
| Free Apify plan | Any paid plan | |
|---|---|---|
| Addresses checked per run | first 3 | up to 500 |
| Result rows returned | up to 25 (sample) | every account found |
| When the limit is reached | run finishes SUCCEEDED with a Free tier limit reached status message and a free-plan-cap record | no such limit |
| Event price per account found | $0.02 | $0.016 Bronze · $0.013 Silver · $0.0104 Gold and above |
| Event price per run started | $0.005 | $0.004 Bronze · $0.00325 Silver · $0.0026 Gold and above |
The sample limits are policy, not a failure: nothing is retried, nothing errors, and the rows already delivered are kept. Your run log names the plan and the discount tier it was priced at before the first lookup starts. Platform credits, maximum-cost settings, the 500-email hard cap and the run-time budget apply on every plan.
| What you run | Accounts found | Cost |
|---|---|---|
| 1 typical personal address, current billing | 10–30 | $0.205 – $0.605 |
| 1 typical personal address, after completed-check activation | 10–30 | $0.215 – $0.615 |
| 1 completed no-match, current billing | 0 | $0.005 |
| 1 completed no-match, after activation | 0 | $0.015 |
A live test of test@gmail.com returned 17 confirmed accounts. At current active
billing that is $0.345 ($0.005 run + 17 × $0.02). After the completed-check event is
activated, the same run would be $0.355 including one $0.01 completed-email fee.
The legacy charged field continues to describe only the account-found event. A
no-match is never relabeled as an account finding. The separate
emailCheckedBillingStatus field reports the once-per-email completed-check event when
it is active. Notices are not product findings and do not create extra product fees.
The examples above show Actor event fees only. Apify platform usage is charged separately
under the customer's current Apify plan and the platform's applicable rates. Set the
run's maximum cost in Run options before a large batch.
Large batches and the run charge limit
Every Apify run has a maximum cost, which you set per run (or per schedule) in the Actor's Run options. This Actor accepts up to 500 email addresses in a single run, and a big batch can easily find more accounts than the default limit covers.
When a run reaches its charge limit, this Actor stops checking and finishes successfully with everything it found up to that point, plus a final Charging limit reached record explaining what happened. You are never charged past your limit, and the run is not reported as a failure.
To get the full batch, do one of the following:
- Raise the run's maximum cost in Run options before starting, or
- Split the email addresses across several runs — for example 25 emails per run instead of 500.
Quick Start
curl
curl -X POST "https://api.apify.com/v2/acts/ntriqpro~email-osint-search/runs?token=YOUR_TOKEN" \-H "Content-Type: application/json" \-d '{"emails": ["alice@example.com"]}'
Python (Apify Client)
from apify_client import ApifyClientclient = ApifyClient("YOUR_TOKEN")run = client.actor("ntriqpro/email-osint-search").call(run_input={"emails": ["alice@example.com", "bob@example.org"]})items = list(client.dataset(run["defaultDatasetId"]).iterate_items())for item in items:if not item.get("exists"):continueflag = " (site frequently rate-limits — re-verify)" if item.get("rateLimit") else ""print(f"{item['email']} -> {item['platform']} ({item['domain']}){flag}")
Technology
- holehe (GPL-3.0) — Email-based account existence checker, 5.6k+ stars
- Apify SDK for Python (Apache 2.0) — Actor runtime
- httpx (BSD) — Async HTTP client
Limitations
| Limitation | Detail |
|---|---|
| Sites that frequently rate-limit | holehe flags ~10-15% of sites as ones that throttle frequent lookups. Confirmed accounts on those sites are flagged rateLimit: true so you can re-verify |
| False positives | Existence signals can be ambiguous; treat as leads, not proof |
| New site discovery | holehe upstream adds sites quarterly; we update with library releases |
| Rate limiting | Recommended: batch <10 emails per run to avoid IP-based throttling |
| Billing retries | An ambiguous charging failure is not retried within the same run because the remote charge may already have succeeded. Exact-once billing across a separate restarted run is not claimed; inspect the failed run before restarting it. |
Disclaimer
Legal Disclaimer: This Actor is an unofficial integration of holehe (megadose) and is not affiliated with or endorsed by the original project. Use only on email addresses you own or have explicit authorization to investigate. Comply with PIPA (KR), GDPR (EU), CCPA (US), and applicable privacy laws.
This Actor is an unofficial open-source wrapper around megadose/holehe. It is not affiliated with, sponsored by, or endorsed by the holehe project, its maintainers, or any of the platforms being probed. OSINT results are based on publicly observable account-existence signals and may produce false positives.
You are solely responsible for ensuring you have legal authorization to investigate any email address. Misuse may violate privacy laws (PIPA, GDPR, CCPA, etc.) and the terms of service of target platforms. This tool is intended for security research, fraud prevention, and authorized investigation use only.
Privacy & data responsibility
You are the data controller for every search you run with this Actor; ntriqpro is a data processor acting solely on your instructions. You are responsible for having a lawful basis and a legitimate, purpose-limited reason for each lookup, and for complying with GDPR, PIPA, CCPA, and other applicable privacy laws. We do not store your results — output is written only to your own run's dataset and is never retained on our side. Use this Actor only for lawful purposes and only on email addresses you own or are authorized to investigate.
🔗 Related Actors by ntriqpro
Running several of these by hand? OSINT Recon Suite takes one target — email, username, domain or phone — runs Maigret, Sherlock, holehe, theHarvester, WHOIS and dnstwist against it, then correlates everything into a single risk-scored report. One input, one report, instead of six separate runs to stitch together yourself.
Build your full OSINT stack:
- maigret-actor — Username OSINT across 3000+ sites (5.0★ rated)
- phoneinfoga-osint — Phone number OSINT — carrier, country & footprint
- dnstwist-osint — Typosquatting & phishing domain detector
- subfinder-osint — Subdomain finder for attack-surface mapping
- gitleaks-secret-scanner — Find leaked secrets in public repos
⭐ Rate this Actor
If this saves you investigation time, please leave a review — it helps other security researchers discover it.