📧
DataShell

What An Email Reveals

by useosint

What An Email Reveals is a Data skill for Claude Code, published by useosint in osint-skills.

12 stars1 forkson useosint/osint-skillsAdded 2026/08/12+200% in starsRepository updated 2026/08/03
agent-skillsai-agentsclaudeclaude-skillscursorcursor-skillscybersecuritydigital-forensicsdue-diligencegeointinformation-gatheringinfosecinvestigationopen-source-intelligenceosintosint-toolspentestingreconnaissancesocmintthreat-intelligence
Install in seconds
Install What An Email Reveals
Copy What An Email Reveals into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/useosint/osint-skills/tree/main/skills/what-an-email-reveals ~/.claude/skills/what-an-email-reveals

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/useosint/osint-skills.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/what-an-email-reveals/SKILL.md in useosint/osint-skills
Installs to
~/.claude/skills/what-an-email-reveals
Collection
One of 25 skills cataloged from this repository
Category
Data668 skills

What What An Email Reveals does

What An Email Reveals investigates an email address with MX and syntax checks, Gravatar lookup, corporate format inference, breach exposure, and mail-header analysis. Use it for email OSINT, phishing triage, vendor verification, and tracing suspicious messages.

What An Email Reveals is cataloged under Data on DirSkills. What An Email Reveals comes from a repository tagged agent-skills, ai-agents, claude, claude-skills and cursor.

Documentation

README

What an email reveals

An email address is usually the highest-value selector in an investigation: it carries a name, a domain, an account history, and a breach footprint. The beginner error is trying to prove the address exists. Existence is the least interesting thing about it, it is the hardest thing to establish passively, and the techniques that establish it are the ones that expose you. Work the structure and the footprint first; treat validation as a bonus.

Never send mail to the subject as a research technique.

Step 1 — Authorized scope

This is the opening of the README. Read the full README on GitHub.

Frequently asked about What An Email Reveals

  • What else does useosint publish alongside What An Email Reveals?

    What An Email Reveals is one of 25 skills that DirSkills catalogs from useosint/osint-skills, the repository it ships in. Its siblings there include Dig Through Data Brokers, Find Anyone and Find Exposed Servers. Each one is a separate skill with its own page in this directory, installs the same way What An Email Reveals does, and is maintained by useosint in that same repository. The rest of the collection is listed on the useosint/osint-skills page.

  • How does What An Email Reveals compare to other Data skills?

    What An Email Reveals ranks #668 by stars among the 668 Data skills in this catalog. The most-starred ones next to it are Benchmark Methodology, Jupyter Notebook and Solana. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of What An Email Reveals against them. Open each page to compare what they document and how they install.

More from useosint/osint-skills

What An Email Reveals is one of 25 skills cataloged on DirSkills from useosint/osint-skills.

See all 25 skills
🕵️
3w ago

Dig Through Data Brokers

Dig Through Data Brokers uses people-search sites and public records to turn a name into candidate addresses, phones, relatives, and background details, then confirm them against primary sources. Use it for skip tracing, reverse address lookups, self-audits, and broker data removal.
Automation
121
🕵️
3w ago

Find Anyone

Find Anyone builds a sourced profile of one specific person from public records, professional profiles, court filings, and other open sources. It is used to identify, verify, or background-check someone while avoiding name-mixups.
AI Engineering
121
🔎
3w ago

Find Exposed Servers

Find Exposed Servers uses Shodan, Censys, and similar scan data to identify internet-facing hosts, ports, services, and devices without touching the target. Use it for exposure checks, origin-IP pivots, and Shodan query syntax.
Automation
121
🔎
3w ago

Find Hidden Subdomains

Find Hidden Subdomains enumerates an organization’s subdomains and sibling domains from Certificate Transparency logs and passive DNS without sending traffic to the target. Use it to map hostnames, find staging or admin systems, and spot newly issued certificates.
Automation
121
🕵️
3w ago

Find Leaks In The Wild

Find Leaks In The Wild helps check whether a name, email, domain, or credential is circulating in pastes, forums, and Telegram, and whether a claimed leak is genuine or a recycled combolist. Use it for breach triage, threat intelligence, and leak monitoring.
Automation
121
🖼️
3w ago

Find The Original Image

Find The Original Image uses multiple reverse image search engines to trace an image to its earliest known publication and read the source page. Use it to identify photos, logos, places, profile pictures, reposts, or video keyframes.
Automation
121