Form, domain, mail policies and known breaches. Three groups of findings with three different weights, kept apart.
It consumes no slots and has no usage limits: it is included in C.E.R.T.O. Desktop and available to anyone with an account.
The result is sealed in a bundle with an Ed25519 signature and an RFC 3161 timestamp, with a report in text and PDF.
Findings about an e-mail address do not all carry the same weight, and this check does not add them up into a score. Form and DNS can be repeated by anyone. SPF and DMARC are public records, with written rules that can be challenged step by step. The mail server's answer, instead, depends on who asks and when: it is not repeatable.
A “4 out of 5” like the one paid services give would hide exactly the distinction that matters. Here the three groups stay separate, and the report states how much each one weighs.
Only what the program actually does: every item matches a finding that exists in the code.
Syntactic correctness of the address, existence of the domain, declared mail servers and their preference order.
The chain is actually walked, counting the DNS lookups the record imposes. Measured on a real domain: 8 lookups out of 10, 72 mechanisms, 5 domains in the chain — two steps from the limit beyond which the record stops protecting. A shallow check would have passed it.
The declared policy and what it actually entails: whether non-conforming messages are rejected, quarantined or merely observed.
Whether the address appears in publicly disclosed data breaches, with the date and source of each.
A stated limit is worth more than a claim of completeness — and it goes into the report too, not just onto this page.
🔴 It does not say whether the mailbox exists, and nobody can say so reliably. The technique one would use — asking the mail server whether it accepts that address — proves nothing, and this was measured: asked about a real mailbox and a non-existent one, a server answered 250 Ok to both. A service telling you “this e-mail exists” is selling you that answer.
The dangerous case is not the absence of an answer: it is an answer that is plausible and wrong. So when the server behaves in a way that makes the answer worthless, the report says so rather than reporting an outcome.
It does not say who the address belongs to. Mail policies concern the domain, not the person.
The questions we are asked most often about this check.
All inside C.E.R.T.O. Desktop's OSINT section, all with their own sealed bundle.
Register and download C.E.R.T.O. Desktop for Windows and macOS from your client area.