> For the complete documentation index, see [llms.txt](https://csbygb.gitbook.io/pentips/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://csbygb.gitbook.io/pentips/osint/email.md).

# OSINT Email

## Lookup using websites

* [Hunter](https://hunter.io/) 50 free searches/month We can use this tool to look for email address with a company name for instance. It is also useful to identify patterns on how the email address are built.
* [Phonebook](https://phonebook.cz/)
* [Voilà Norbert](https://www.voilanorbert.com/)
* [Clearbit connect](https://chrome.google.com/webstore/detail/clearbit-connect-supercha/pmnhcgfcafcnkbengdcanjablaabjplo?hl=en) need to be added on google chrome, but very powerful. Lots of filters, returns lots of info as well,..

## Methodology

* Look on google "who is in this role at this company" for example
* Then we can use phonebook or hunter and try to find the email pattern
* Then we can take the email and verify it with [emailhippo](https://tools.emailhippo.com/) or [emailchecker](https://email-checker.net/)

## Other tips

* We can use password recovery or account recovery to get more info about the user
