
Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess
mailaccess.pro · Docs · PyPI · Changelog
Self-hostable OSINT platform for investigating email addresses. Fan out across breach databases, social networks, DNS records, and the open web, then get back a unified exposure score and structured findings you can export or pipe into Maltego.
Built for security researchers, OSINT analysts, and penetration testers operating under authorization. Read DISCLAIMER.md before use.
pip install mailaccess
mailaccess investigate [email protected]
The CLI auto-starts and stops the backend for each investigation. Use
mailaccess serve when you want a persistent server, install
mailaccess[ml] for optional spaCy-based name classification, or
mailaccess[browser] (then playwright install chromium) for the optional
headless-browser account-existence oracles.
Full install options (Docker, persistent server, self-hosting) in docs/self-hosting.md.
mailaccess investigate [email protected]
mailaccess investigate [email protected] -o report.pdf
mailaccess harvest-emails --domain company.com
mailaccess harvest-emails --domain company.com --export harvest.csv
mailaccess find-email --name "Jane Doe" --domain company.com
mailaccess keys set HIBP_API_KEY your-key
mailaccess pro
mailaccess upgrade
mailaccess serve
Pipeline, stdin, JSONL, and CI examples in docs/integrations.md.
/investigation/:id/graph or export with GET /api/report/{id}/graph.harvest-emails discovers organization addresses across Common Crawl, GitHub, CT logs, registries, keyservers, dorks, employee pages, and patterns. (Pro adds the decision-makers behind the domain.)find-email turns a name plus an employer domain into one honestly-graded likely address, offline from a bundled 384K-domain pattern index. Microsoft 365 mailboxes are verified where the provider allows.Your free harvest finds the addresses that are public. It does not find the people who make the decisions.
The names that matter, heads of security, procurement, and engineering, rarely show up in Common Crawl, CT logs, or a GitHub commit. MailAccess Pro closes that gap. Add a Pro key and any lead-gen harvest is enriched with real business contacts, each carrying name, role, company, email, and LinkedIn, aggregated from publicly-available and third-party commercial sources. One command turns a bare domain into a working outreach list:
$ mailaccess harvest-emails --domain acme.com
312 addresses found
$ mailaccess harvest-emails --domain acme.com --mode public-business-contact
312 found · 968 available with Pro
──────────────────────────────────────────────────────────────────
Dana Reed VP Security Acme [email protected] in/danareed
Sam Okoye Head of Procurement Acme [email protected] in/samokoye
Priya Nair Director, Platform Acme [email protected] in/priyanair
… 653 more business contacts (name, role, company, email, LinkedIn)
Why teams upgrade:
--company "Stripe" resolves it for you.mailaccess pro for live availability.Corpus contacts are live-only: they render in their own Pro surface and never touch your exports, local database, or history. If the service is unreachable, the harvest shows the full open result. Without a key, nothing changes.
Start with Pro → · how it works
MailAccess checks PyPI for a newer release (cached, best-effort, never blocking) and prints an upgrade hint after a command when you're behind. Update in place with:
mailaccess upgrade
Silence the check with MAILACCESS_NO_UPDATE_CHECK=1. Prefer email? Get release notes in your inbox.
75 modules over a 5,300+ platform corpus. Investigations probe a bounded, evidence-first wave of the highest-signal platforms (~700 vetted by default) rather than the whole corpus. Full module reference in docs/modules.md.
Most modules work with zero keys. Optional keys unlock more coverage. Full list in docs/api-keys.md.