Certification & Online Trace Collection · service active
WACZ · ISO 28500/ eIDAS timestamping/ Client area
C.E.R.T.O.
Sign in Register for free
IT EN
C.E.R.T.O. / OSINT / E-mail address check
OSINT · E-MAIL

E-mail address check

Form, domain, mail policies and known breaches. Three groups of findings with three different weights, kept apart.

Free

It consumes no slots and has no usage limits: it is included in C.E.R.T.O. Desktop and available to anyone with an account.

The result is sealed in a bundle with an Ed25519 signature and an RFC 3161 timestamp, with a report in text and PDF.

Findings about an e-mail address do not all carry the same weight, and this check does not add them up into a score. Form and DNS can be repeated by anyone. SPF and DMARC are public records, with written rules that can be challenged step by step. The mail server's answer, instead, depends on who asks and when: it is not repeatable.

A “4 out of 5” like the one paid services give would hide exactly the distinction that matters. Here the three groups stay separate, and the report states how much each one weighs.

What goes into the bundle

What it establishes

Only what the program actually does: every item matches a finding that exists in the code.

Form and domain

Syntactic correctness of the address, existence of the domain, declared mail servers and their preference order.

SPF in full, not just “it exists”

The chain is actually walked, counting the DNS lookups the record imposes. Measured on a real domain: 8 lookups out of 10, 72 mechanisms, 5 domains in the chain — two steps from the limit beyond which the record stops protecting. A shallow check would have passed it.

DMARC and MTA-STS

The declared policy and what it actually entails: whether non-conforming messages are rejected, quarantined or merely observed.

Known breaches

Whether the address appears in publicly disclosed data breaches, with the date and source of each.

Honesty first

What this check does NOT tell you

A stated limit is worth more than a claim of completeness — and it goes into the report too, not just onto this page.

🔴 It does not say whether the mailbox exists, and nobody can say so reliably. The technique one would use — asking the mail server whether it accepts that address — proves nothing, and this was measured: asked about a real mailbox and a non-existent one, a server answered 250 Ok to both. A service telling you “this e-mail exists” is selling you that answer.

The dangerous case is not the absence of an answer: it is an answer that is plausible and wrong. So when the server behaves in a way that makes the answer worthless, the report says so rather than reporting an outcome.

It does not say who the address belongs to. Mail policies concern the domain, not the person.

FAQ

Frequently asked questions

The questions we are asked most often about this check.

Can I find out whether an e-mail address really exists?
No, and be wary of anyone claiming otherwise. The check one would use was tested on a real mailbox and an invented one at the same domain: the server answered “fine” to both. Many servers answer that way on purpose, so as not to reveal which mailboxes they hold. A result built on that answer would be plausible and false — which, in a bundle, is the worst thing.
What is it for, then?
To answer a different and more useful question in court: could that domain be impersonated? If it has neither SPF nor DMARC, anyone could send messages in its name, and nothing would have flagged it to the recipient. That is often the decisive point when a disputed e-mail is discussed.
How much does it cost?
Nothing. It is one of the four free OSINT services.
Same section

The other OSINT checks

All inside C.E.R.T.O. Desktop's OSINT section, all with their own sealed bundle.

E-mail address check, free.

Register and download C.E.R.T.O. Desktop for Windows and macOS from your client area.