Email Lookup: Free Email Checker & OSINT Trace
Email lookup: the email checker with technical context and risk scoring
An email lookup in seconds requires combining several sources: SMTP validation, domain infrastructure, authentication (SPF, DMARC, MTA-STS, TLS-RPT), presence of the alias on external platforms, and antifraud scoring with a professional summary. IntelMind brings this entire flow together to help you decide whether an email is legitimate before acting on it, and goes further: it detects the owner’s credentials in infostealer logs, corporate exposure of the domain, cross-confirmed presence on public platforms (Holehe + Maigret), and advanced technical posture (SSL Labs, security.txt RFC 9116, CAA, DNSSEC).
What you get from an IntelMind email lookup
user@domain.com · Ideal for triage, OSINT, fraud checks and initial technical reviewSee a full sample report Click to expand a real screenshot of an email analysis — the image is only a partial view of the report; below it you’ll find the full list of everything you get
The full email report includes more than 80 correlated data points grouped into 4 major layers. The image below is a partial view: for the full picture, see the list below.
🎯 Quick decision (top section)
- Weighted 4D scoring: Final risk + Deliverability (12%) + Domain posture (13%) + Identity (30%) + Operational (45%) with consistent levels LOW / MEDIUM / HIGH / CRITICAL
- Factors behind the score: pills for each concrete driver (catchall_detected, dmarc_none, breaches_recent_12m, stealer_logs_recent, role_based, etc.)
- Actionable executive summary in 3 lines: Suggested decision · Risk level · Immediate action
🧠 Two-part AI report (OpenAI gpt-5.4)
- PART 1 — for non-technical readers: intro paragraph + 4 pre-built bullets (IDENTITY · PUBLIC EXPOSURE · DIGITAL HABITS · RISKS) + human verdict + What to do if you work with this person
- PART 2 — technical: Mailbox validation, technical domain posture (full DNS table), HudsonRock stealer logs (detailed table), HIBP breaches (table with DataClasses), cross-references between sources, public digital presence, reasoned inferences, limitations of the analysis, final risk
- More than 20 control rules + PART 1 bullets that the AI copies verbatim from the backend (zero invention)
📧 Mailbox validation and domain posture
- Double cross-checked SMTP/MX validation: Hunter.io + MailboxLayer (format, MX, SMTP, disposable)
- Local database of 72,710 disposable domains + normalized Gmail dot/plus/googlemail detection
- Domain technical posture: SPF, DMARC (policy + reject/quarantine/none), DKIM, MTA-STS, TLS-RPT, BIMI, DNSSEC, CAA, security.txt RFC 9116
- SSL Labs grade (A/B/C/D/F) + RDAP domain age + Wayback Machine first observed date
- theHarvester: publicly discovered subdomains
🦠 HudsonRock — forensic stealer logs
- Owner’s infections: table with N stealer logs, exact dates, unique compromised machines, operating systems, real IPs of the infected machine, countries
- Literal list of IPs found in the stealer logs (useful for timeline correlation)
- HudsonRock volume when there are no stealers: context on database coverage
- Corporate domain exposure: if the email belongs to a business domain — total domain-wide credentials in stealer logs, breakdown by employees vs. external users, last documented compromise
🔓 HIBP — historical data breaches
- Total breaches + recency (12m, 24m) + number of breaches with passwords + number of stealer-log entries
- Breach table with DataClasses: passwords, emails, IPs, card numbers, dates, physical addresses, phone numbers
- 🚨💳📅 flags + associated country where applicable
- Stealer ↔ breach cross-confirmation: double confirmation if the same email appears in both sources
👤 Owner’s digital footprint
- Local-part pattern analysis: detected pattern (firstname_lastname, role_based, initials_digits, unique_generic_name, unique_username, random_bot) with strict homonymy gating
- Holehe: confirmed platforms via email search (Twitter, Spotify, Adobe, GitHub, Imgur…) — with a 14-site anti-false-positive blacklist (xvideos, xnxx, twitter, spotify, etc.)
- Maigret: top 15 candidates cross-confirmed with Holehe (only matches confirmed by both sources are published)
- Confirmed public profiles: GitHub, Keybase, DEV.to (only when the local-part pattern guarantees attribution to the owner)
- Gravatar / Libravatar: public avatars linked to the email’s MD5 hash
- Microsoft account: login.live.com detection (consumer Hotmail/Live/Outlook vs. organizational Microsoft 365) with throttling handling
🔬 Deterministic anomalies and recommendations (forensic, no AI)
- Cross-source anomalies detected: contradictions between sources (DMARC=none but a corporate domain, Microsoft throttled, Maigret with high homonymy, HIBP with 0% confidence but N historical reports, etc.)
- Specific actionable recommendations: verify via an alternative channel, cross-check the alias on GitHub/Twitter/LinkedIn, require a named email if role-based, request additional physical documentation if recent stealer logs
- Forensically citable evidence — generated in code from correlated sources, with zero possibility of hallucination
📋 Traceability and deliverables
- Verifiable public sources: list of the 24+ sources consulted with a ✓ status and a link to reproduce the lookup manually
- Follow-up questions: up to 3 questions to the AI analyst about the report results (gpt-5.4-mini)
- RFC 3161-signed PDF: cover page with premium scoring + risk bar with factors · full AI report on a dedicated page · technical data · anomalies · FreeTSA timestamp · SHA-256 hash · public verification URL · corporate signature block + INCIBE Emprende seal
- Suitable as evidence: electronic evidence in court, documentary annex for M&A due diligence, support for an expert report, regulatory evidence for KYC/AML compliance, journalistic annex

What is this email lookup tool?
For an email lookup, IntelMind offers a complete OSINT email analysis for any address: it validates the email at a technical level, analyzes the infrastructure of the associated domain, and produces an antifraud risk score with an actionable professional summary.
Unlike a conventional email checker, this email lookup correlates multiple sources — Hunter, MailboxLayer, DNS, RDAP, Holehe, Maigret, HudsonRock — to detect signs of phishing, identity impersonation and disposable addresses. As a result, the output includes SPF/DMARC authentication, the email’s digital footprint and an executive verdict you can export as a PDF.
What you get with every lookup
- Email validation: format, MX, SMTP, deliverability signals and provider context.
- Associated domain analysis: WHOIS, RDAP, DNS, TXT records, MX, NS and a basic technical footprint. Go to the domain tool
- Email security: SPF, DMARC, MTA-STS, TLS-RPT and other authentication signals.
- Risk classification: score, informational flags and confidence level of the analysis.
- Explanatory professional summary: results interpreted without losing technical precision.
- Follow-up questions: dig deeper into specific findings from the report (up to 3 questions per lookup).
- PDF export: a report ready to share, document or archive your findings.
- Centralized workflow: less time jumping between tools, more focus on the analysis. Learn about the platform
Quick FAQ
Does this tell me with 100% certainty whether an email exists?
Not always. It provides strong validity and deliverability signals, but 100% confirmation depends on the specific case.
What sections does the exported PDF report include?
A two-part professional summary — a version for non-technical readers (What we found · Human verdict · What to do if you work with this person) and a technical forensic version (Mailbox validation · Domain posture · HudsonRock · HIBP · Cross-references · Digital presence · Reasoned inferences · Limitations · Final risk). It includes multidimensional 4D risk scoring (deliverability 12% + domain posture 13% + identity 30% + operational 45%) with consistent LOW / MEDIUM / HIGH / CRITICAL levels and an executive verdict, SMTP/MX validation (Hunter.io + MailboxLayer), the owner’s credentials in stealer logs (HudsonRock Cavalier), corporate domain exposure (HudsonRock domain), historical breaches (Have I Been Pwned with DataClasses), cross-confirmed presence on public platforms via Holehe + Maigret (including GitHub, Keybase and DEV.to), the domain’s real visible age (Wayback Machine + RDAP), a public subdomain inventory (theHarvester), advanced technical posture (SSL Labs, security.txt RFC 9116, CAA, DNSSEC), SPF/DMARC/MTA-STS/TLS-RPT/BIMI authentication, detection of a Microsoft account linked to the email (consumer Hotmail/Live/Outlook or organizational Microsoft 365), avatars (Gravatar + Libravatar) and disposable email detection (72,710+ domains). The PDF is signed with a digital chain of custody: SHA-256 hash, RFC 3161 timestamp issued by FreeTSA, and a public verification URL.
How is the risk score interpreted?
The 4D score weighs four risk dimensions on the same scale (0–100, high = high risk): deliverability (12%), domain posture (13%), identity (30%) and operational (45%). The levels are consistent across all four: LOW (0–19, standard process), MEDIUM (20–39, pay attention), HIGH (40–64, additional verification or a soft block) and CRITICAL (65–100, reject or escalate). Operational — breaches, stealers and flags — carries the most weight because it’s the most predictive antifraud signal.
Is this tool safe to use for fraud triage?
Yes. IntelMind correlates more than 20 public sources (Hunter.io, MailboxLayer, HudsonRock Cavalier, Have I Been Pwned, Maigret with Holehe cross-confirmation on public platforms, theHarvester, Wayback Machine, SSL Labs, security.txt, CAA/DNSSEC, GitHub, Keybase, DEV.to, Gravatar, Microsoft account detection) to give you antifraud context. It’s not a binary checker — it’s OSINT intelligence with an actionable executive verdict, multidimensional 4D risk scoring and a digitally signed PDF chain of custody.
How many credits does an email lookup cost?
Each email lookup costs 5 credits. The monthly B2B plans (Analista €29, Profesional €79, Firma €199, Corporativo €499) let you scale volume at a lower cost per lookup than combining individual APIs (Hunter.io, MailboxLayer, HudsonRock Cavalier, Have I Been Pwned, Maigret, Holehe, theHarvester, SSL Labs, Wayback Machine, etc.), which would cost several times more billed separately.
How does IntelMind detect phishing or identity impersonation?
The analysis combines multidimensional risk scoring, domain infrastructure verification (SPF, DMARC, MTA-STS, TLS-RPT, BIMI, DNSSEC), domain age via RDAP, historical age via Wayback Machine, SSL Labs posture and disposable-domain detection. When several signals line up — a recently registered domain, no DMARC, a weak certificate — the executive verdict flags it as HIGH risk with a recommended blocking action.
What are SPF and DMARC checks used for on an email?
SPF confirms that the server sending the email is authorized by the domain; DMARC defines what to do if SPF fails (discard, flag or deliver) and lets the domain owner receive abuse reports. Together with MTA-STS and TLS-RPT, they form the backbone of modern mailbox authentication. Their absence, or an insecure configuration (an overly permissive SPF, DMARC at p=none), is a technical risk signal that IntelMind penalizes in the score.
How is an email lookup different from OSINT intelligence?
A lookup confirms that an email exists and can receive messages. OSINT intelligence goes further: it analyzes the domain’s reputation, the email’s presence on external platforms, the domain’s age, security configurations and possible data breaches, and produces a risk score with an executive verdict. IntelMind is not a simple checker — it’s a full OSINT analysis tool.
Advanced details of an OSINT email lookup
Is there a way to check whether an email is real without sending it a message?
IntelMind runs a passive SMTP check that talks to the recipient’s server without ever delivering a message. That check reveals whether an email is real and whether the domain is configured to receive it. Combined with SPF/DMARC analysis and the domain’s technical posture (MTA-STS, TLS-RPT, DNSSEC), it also helps confirm whether an email is safe before you trust its origin.
Can I find out if the owner’s credentials have leaked in infostealers?
IntelMind checks the email against the public HudsonRock Cavalier databases, which catalog credentials exfiltrated by infostealers (malware that steals passwords saved in the browser of an infected machine). If the email shows up, the report reveals how many incidents there are, the dates, the operating system of the affected machine and the first characters of the leaked passwords. It’s a layer no conventional SMTP checker offers, and it’s critical in antifraud triage for spotting reused credentials.
How does IntelMind combine Holehe and Maigret to detect the owner’s digital footprint?
Holehe queries the email directly against platforms that accept it as a login identifier (Twitter, Spotify, Adobe, Imgur…). Maigret searches for the email’s local-part as a username on public platforms that list profiles by username (GitHub, Keybase, DEV.to). IntelMind only publishes the platforms where both sources agree, removing the false positives typical of individual scraping. The result is a clean list of the owner’s verified presence: a cross-confirmation technique an OSINT analyst would otherwise do by hand in minutes, which IntelMind runs as a standard part of the flow on every email lookup.
How do I measure a domain’s corporate exposure for due diligence or KYB?
When the email belongs to a corporate domain (not Gmail, Outlook or Yahoo), IntelMind adds a domain-wide analysis with HudsonRock Cavalier: total domain credentials found in stealer logs, a breakdown between employees and external users, the date of the last documented compromise, and the overall scale of the exposure. Combined with the publicly visible subdomain inventory (theHarvester) and technical posture (SSL Labs, security.txt, CAA, DNSSEC), it delivers a full picture for M&A due diligence, pre-contract KYB, private banking risk assessment or corporate compliance.
How can I find out who owns an email address?
There’s no directory that returns the owner’s name for any given email, and IntelMind never invents identities. What it does is infer attribution from correlated public signals: the local-part pattern (firstname_lastname, initials, generic role), the email and its alias confirmed on platforms via cross-confirmed Holehe + Maigret (GitHub, Keybase, DEV.to), the linked public avatar (Gravatar/Libravatar), and the type of Microsoft account (personal Hotmail/Live/Outlook or corporate Microsoft 365). When these signals converge, the report attributes the email to a person or a role; when there isn’t enough evidence, it says so honestly and still delivers the technical and exposure footprint. It’s the rigorous way to find out who owns an email address without guessing a name without proof.
Can I check if my email has been in a data breach or hacked?
Yes. IntelMind checks the email against Have I Been Pwned (historical breaches, with the detail of what data was exposed: passwords, phone numbers, physical addresses, dates) and against HudsonRock Cavalier (credentials stolen by infostealers on infected machines). The report shows how many breaches the email appears in, what information leaked in each one, how recent they are (last 12 and 24 months), and whether there’s double confirmation when the same email shows up both in a breach and in stealer logs. It won’t change your passwords for you, but it tells you precisely what real exposure that address has so you can decide whether to rotate credentials or harden the account.
The complete guide to email lookups with OSINT
A professional-grade email lookup goes far beyond checking whether the address exists. An email is the entry point into a digital identity: from the domain backing it to the platforms where that address has left a trace. This guide walks through how to validate an email address, find out who an email belongs to, and rule out impersonation in a single flow. That’s why it covers the dimensions IntelMind evaluates on every email lookup, to deliver an actionable executive verdict without needing to check five different tools.
SMTP validation: how to check that an email address is real and active
To run an email lookup, SMTP validation queries the domain’s MX records and simulates the handshake with the remote server up to the
RCPT TO command — without ever sending the message. This way of checking an email address without notifying the owner reveals whether the mailbox accepts mail, is disabled, is a
catch-all (accepts any address on the domain), or instead responds with a soft bounce. IntelMind also combines Hunter.io and
MailboxLayer to cross-check the result from two different engines, and checks the domain against its own database of
72,710+ disposable domains (a merge of the Disposable Email DB and Burner Email Providers lists, hot-reloaded without a restart). As a result, you can tell whether an email is real and active, and distinguish it from a temporary address created in seconds or a dead mailbox that no longer bounces. The report’s deliverability score summarizes all of this as one of the 4 risk dimensions on a
0–100 scale, with consistent LOW / MEDIUM / HIGH / CRITICAL levels (high = more risk of non-delivery).
SPF and DMARC: how to validate an email from the sending domain
To validate an email at the sending-domain level, the two core protocols are SPF and DMARC. SPF (Sender Policy Framework) defines which servers are authorized to send email on behalf of a domain.
DMARC (Domain-based Message Authentication, Reporting & Conformance), for its part, defines the policy a
receiver should apply if SPF fails (none, quarantine or reject) and lets the domain owner receive abuse reports. Together they form the
modern standard against identity impersonation. A domain with no DMARC, or with p=none, is an open vector
for phishing: anyone can send spoofed email from that address without receivers rejecting it. That’s why IntelMind checks the
presence, policy and alignment of SPF and DMARC when evaluating a domain, and adds complementary signals like MTA-STS,
TLS-RPT, BIMI and DNSSEC — indicators of a domain’s operational maturity.
OSINT presence across platforms: Holehe, Gravatar and an email’s digital footprint
An email lookup doesn’t stop at the mailbox: the same address is often registered on dozens of platforms (professional networks, social media, cloud services, gaming, e-commerce), and every registration leaves a public trace. That’s why IntelMind uses Holehe — an OSINT tool that queries dozens of platforms that accept an email as a login identifier (Twitter, Spotify, Adobe, Imgur…) passively, without ever notifying the mailbox owner — and groups the results into categories (professional, social, technology, commerce, entertainment, gaming, other). It also cross-checks Gravatar, which can reveal a public avatar linked to the email’s MD5 hash, and Microsoft Account, to confirm whether the address is registered in the Microsoft ecosystem. Altogether, this builds identity traceability: how many platforms know this email and what digital profile it describes.
Phishing detection: how to verify an email’s authenticity and rule out impersonation
To verify an email’s authenticity and rule out phishing or identity impersonation, a single signal is rarely enough — it’s usually the result
of several small anomalies stacking up. That’s why, on every email lookup, IntelMind checks for patterns typical of fraud campaigns: domains registered only a
few days ago (via RDAP), missing or overly permissive DMARC, SPF with ~all (softfail) instead of -all,
suspicious MX providers, generated-looking local parts (random letters and numbers), and the domain’s presence in its
historical age record as verified via Wayback Machine. When two or three of these signals line up, the
risk score rises and the executive verdict recommends a block or manual review. That said, the tool doesn’t replace
forensic header analysis — it enables a fast, reproducible triage.
Disposable emails and role addresses: when there’s no real person behind it
Not every email represents an actual person. On one hand, disposable emails — created in seconds through
services like Mailinator, Guerrilla Mail or 10minutemail — exist for one-off signups and are abandoned once the session expires.
On the other hand, role addresses (info@, support@, admin@, no-reply@) are
generic mailboxes that usually forward to entire teams and don’t identify an individual. For any sales, antifraud
or compliance team, telling these two categories apart during an email lookup is critical: a lead with a disposable email rarely converts, and a signup from a
role address should never be treated as identity verification. IntelMind detects both patterns and reports them as
informational flags that penalize the identity dimension of the score.
Multidimensional 4D risk scoring: deliverability, domain posture, identity and operational
IntelMind’s 4D score weighs four independent dimensions — all measuring risk, on the same 0–100 scale (high = high risk) — to produce the final score for every email lookup: deliverability (12%) — SMTP, MX, role address, catch-all, disposable domain; domain posture (13%) — SPF, DMARC, DNSSEC, MTA-STS, TLS-RPT, BIMI and the SSL Labs grade; identity (30%) — public traceability (Holehe, Gravatar, Microsoft, GitHub/Keybase/DEV.to profiles) and the local-part pattern; operational (45%) — presence in stealer logs (HudsonRock), historical breaches (HIBP), leaked ID numbers, partial card numbers or passwords, and recency. Operational carries the highest weight because breaches and stealer logs are the most predictive antifraud signal — real credentials in circulation, not inferences. The levels are consistent across all four dimensions and in the final weighted risk: LOW (0–19, standard process), MEDIUM (20–39, attention and contextual verification), HIGH (40–64, additional verification or a soft block), and CRITICAL (65–100, reject or escalate). The report shows all 5 score boxes (final risk + the 4 dimensions) with the same color scheme on screen and in the signed PDF.
Use cases: antifraud triage, due diligence and B2B lead analysis
The value an email lookup with OSINT delivers changes a lot depending on the context. This OSINT email analysis works equally well for investigating leads, vetting counterparties or filtering fraudulent traffic. An antifraud team, for example, uses the tool to review emails tied to suspicious payment attempts, mass signups or dubious refund requests. A SOC team, on the other hand, folds it into phishing ticket triage to decide whether to escalate. A due diligence professional documents a counterparty’s email reputation before signing a contract; and a B2B sales team qualifies web-form leads to avoid burning campaign budget on fake contacts. In every case, the same analysis delivers an exportable PDF report with an executive verdict, scoring, technical evidence and an actionable recommendation.
Stealer logs and infostealers: how to check if credentials are circulating on black markets
An infostealer is a type of malware that, once installed on a victim’s computer, exports every password saved in the browser, session cookies, autofill data and sensitive files. That data ends up in stealer logs, credential packages that circulate on black markets and Telegram channels. That’s why, on every email lookup, IntelMind checks the address against the public HudsonRock Cavalier databases (free, no signup required): if the email appears, it means at least one of the owner’s machines has been infected and its credentials are potentially compromised.
The report also shows the number of incidents detected, the date of the last compromise, the operating system and name of the affected machine, and the first characters of the leaked passwords. It’s a signal no conventional SMTP checker can give you, and in fraud investigation, it can make the difference between accepting a seemingly valid email and rejecting it over reused-credential risk. This layer turns OSINT email analysis into a real prevention tool, not just formal validation.
Cross-checking presence: finding out where an email is registered
An email only gives one clue about its owner: the local-part (the part before the @). IntelMind combines two complementary OSINT engines to trace the owner’s public digital footprint: Holehe queries the email directly on platforms that accept it as a login (Twitter, Spotify, Adobe, Imgur…), and Maigret searches for the local-part as a username on public technical networks (GitHub, Keybase, DEV.to). On their own, both engines produce noise — Holehe returns false positives on sites that accept any email, and Maigret produces accidental matches on platforms with very common usernames.
That’s why IntelMind only publishes double matches: presence confirmed by both an email search and a username search. It’s the rigorous way to find out who an email belongs to and trace an email address back to verified public profiles of its owner — a technique an OSINT analyst would otherwise run by hand in minutes, which IntelMind performs as a standard part of every email lookup. The result is a clean map of the owner’s digital footprint, not an inflated list of unconfirmed hits — avoiding the classic case of «the email says one thing, the confirmed profiles say another.»
Corporate domain exposure: full due diligence for M&A, KYB and compliance
When the email belongs to a corporate domain (not Gmail, Outlook or Yahoo), IntelMind runs a dedicated corporate domain exposure analysis with HudsonRock Cavalier during every email lookup: how many credentials for the whole domain (not just the one email) are circulating in stealer logs, how many belong to employees versus external users, when an employee’s last documented compromise happened, and the overall scale of the exposure.
That makes this data invaluable for M&A due diligence, pre-contract KYB, private banking risk assessment or corporate compliance. Combined with the publicly visible subdomain inventory (gathered by theHarvester via Bing, DuckDuckGo, crt.sh, OTX and HackerTarget searches), the report delivers a full picture of the domain’s OSINT surface: exactly what a motivated attacker would find published about the organization in under five minutes. For lawyers, investment funds and compliance consultants, that’s the difference between closing a deal blind or with real visibility into a supplier’s or counterparty’s cyber risk.
Advanced technical posture: SSL Labs, security.txt RFC 9116, CAA, DNSSEC and MTA-STS
A domain’s security maturity is measured through objective signals that IntelMind audits on every analysis. The SSL Labs TLS grade (A+, A, B, C…), for example, reflects the quality of the encryption setup on the exposed servers. Likewise, the security.txt file defined by RFC 9116 publicly exposes an official channel for reporting vulnerabilities — a clear sign of an organization with a mature security program.
In turn, CAA records control which certificate authorities are allowed to issue certificates for the domain (mitigating fraudulent issuance). Likewise, DNSSEC cryptographically signs the DNS zone and prevents cache poisoning. Finally, MTA-STS publishes the expected TLS policy to reinforce the trust chain. Ultimately, the presence or absence of each of these elements in the report is a meaningful background signal: serious domains tend to have at least the first two, and that consistency feeds directly into the domain posture dimension (13% weight) of the report’s 4D score.
Sources and technical references
IntelMind combines information from the following public sources and technical standards. Check the official specifications for additional context:
- DMARC is defined in IETF RFC 7489, the official specification for the protocol.
- SPF is covered in IETF RFC 7208, the standard for sender authentication.
- DMARC is defined in IETF RFC 7489, the policy a receiver applies when SPF fails.
- For security.txt, see IETF RFC 9116, which standardizes the official vulnerability-reporting channel.
- CAA records are specified in IETF RFC 8659 (DNS Certification Authority Authorization).
- MTA-STS is defined in IETF RFC 8461.
- Wayback Machine — Internet Archive, for a domain’s historical age.
- BIMI has a draft IETF specification that is still evolving.
Email lookup: how to tell in seconds if an address is real
A modern OSINT email lookup means far more than checking whether an address is syntactically valid. IntelMind, for example, combines four layers in seconds: (1) technical validation — the address follows RFC 5322 syntax, its domain has MX records, and the SMTP server accepts delivery; (2) reputational validation — the domain has an archived history on the Wayback Machine and a consistent DNS posture (SPF, DMARC, MTA-STS); (3) OSINT validation — the alias shows up on known platforms (Holehe checks more than 100 services), has a public Gravatar or a linked Microsoft account, which points to genuine historical use; (4) contextual validation — the sending domain is well authenticated with SPF, DMARC and modern policies (MTA-STS, TLS-RPT, DNSSEC). So if all four layers come back green, the email is very likely real and active. But if a layer fails, IntelMind reflects it in the multidimensional score with an actionable explanation.
Checking disposable emails: Mailinator, TempMail, Guerrilla and similar services
Temporary or disposable email (Mailinator, TempMail, Guerrilla Mail, 10 Minute Mail, Yopmail, Maildrop) is one of the main fraud vectors in B2B forms and online signups. That’s why, on every email lookup, IntelMind detects disposable services by checking the email’s domain against a local database of 72,710+ known temporary domains (an in-house list plus GitHub’s Burner Email Providers repository), refreshed periodically. When a signup comes in with a temporary email, for example, the system flags the case («DISPOSABLE: true») in the report, along with the service category and an actionable recommendation — typically block it or ask for an alternative address. While disposable email has legitimate use cases (trial subscriptions, stack testing), in real B2B settings the share of signups with a disposable email that go on to become paying customers is essentially zero.
Is it trustworthy? How to check an email before you reply, hire or pay
When someone asks «is this email trustworthy?» before replying to a new client, hiring a supplier or paying an invoice, what they need is a fast verdict with clear reasons. That’s why, on every email lookup, IntelMind produces that verdict in a single report with 4D risk scoring, not a single opaque number: the deliverability dimension measures SMTP/MX/role/disposable (12% weight); domain posture evaluates SPF/DMARC/DNSSEC/MTA-STS/SSL (13% weight); identity measures the owner’s public traceability (30% weight); operational measures real breaches and stealer logs (45% weight, the most important because these are hard antifraud signals, not inferences). Specifically, the professional summary translates the four dimensions into one of five actions: accept, accept with caution, verify before proceeding, high risk, reject. Ultimately, that’s what an antifraud team, a lawyer or a salesperson needs: not a technical data dump, but an actionable decision with documented traceability.
