E-mail, Phone & Network
Email OSINT
Where an e-mail address is registered, and in which breaches it appears
GET
/
api
/
email-osint
curl "https://www.osintcat.net/api/email-osint?query=user%40example.com&purpose=fraud+prevention" \
-H "X-API-KEY: YOUR_API_KEY"
import requests
url = "https://www.osintcat.net/api/email-osint"
params = {"query": "user@example.com", "purpose": "fraud prevention"}
headers = {"X-API-KEY": "YOUR_API_KEY"}
response = requests.get(url, params=params, headers=headers, timeout=60)
print(response.status_code, response.json())
const response = await fetch("https://www.osintcat.net/api/email-osint?query=user%40example.com&purpose=fraud+prevention", {
headers: { "X-API-KEY": "YOUR_API_KEY" },
});
console.log(response.status, await response.json());
<?php
$curl = curl_init("https://www.osintcat.net/api/email-osint?query=user%40example.com&purpose=fraud+prevention");
curl_setopt_array($curl, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => ["X-API-KEY: YOUR_API_KEY"],
]);
$response = curl_exec($curl);
$status = curl_getinfo($curl, CURLINFO_RESPONSE_CODE);
curl_close($curl);
echo $status . " " . $response;
package main
import (
"fmt"
"io"
"net/http"
)
func main() {
req, _ := http.NewRequest("GET", "https://www.osintcat.net/api/email-osint?query=user%40example.com&purpose=fraud+prevention", nil)
req.Header.Set("X-API-KEY", "YOUR_API_KEY")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(resp.StatusCode, string(body))
}
{
"results": {
"register": [
{
"site": "example-shop.com",
"exists": true
}
],
"breach": [
{
"name": "Example 2021",
"date": "2021-04-02"
}
],
"api": []
},
"_meta": {
"plan": "investigator",
"lookups_left": 739
}
}
Checks which websites and services an e-mail address is registered with and in which breaches it appears. Every request must state its purpose.
See Errors for the responses every endpoint can return.
A request without a purpose (parameter
purpose, header X-Purpose, or Purpose: ... at the end of your User-Agent) is refused with 400 USER_AGENT_IDENTITY_REQUIRED.Parameters
string
required
The e-mail address (
email is accepted as well).string
Why you run the lookup, e.g.
fraud prevention. Required unless sent as a header (below).Headers
string
required
Your API key.
string
The purpose, instead of the
purpose parameter.Usage
Counts as one lookup against your plan’s daily allowance (Max: unlimited). When the allowance is used up, the lookup can continue at a per-lookup price charged to your balance (the module’s page in the dashboard shows the price); a lookup that finds nothing is not charged.Example request
curl "https://www.osintcat.net/api/email-osint?query=user%40example.com&purpose=fraud+prevention" \
-H "X-API-KEY: YOUR_API_KEY"
import requests
url = "https://www.osintcat.net/api/email-osint"
params = {"query": "user@example.com", "purpose": "fraud prevention"}
headers = {"X-API-KEY": "YOUR_API_KEY"}
response = requests.get(url, params=params, headers=headers, timeout=60)
print(response.status_code, response.json())
const response = await fetch("https://www.osintcat.net/api/email-osint?query=user%40example.com&purpose=fraud+prevention", {
headers: { "X-API-KEY": "YOUR_API_KEY" },
});
console.log(response.status, await response.json());
<?php
$curl = curl_init("https://www.osintcat.net/api/email-osint?query=user%40example.com&purpose=fraud+prevention");
curl_setopt_array($curl, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => ["X-API-KEY: YOUR_API_KEY"],
]);
$response = curl_exec($curl);
$status = curl_getinfo($curl, CURLINFO_RESPONSE_CODE);
curl_close($curl);
echo $status . " " . $response;
package main
import (
"fmt"
"io"
"net/http"
)
func main() {
req, _ := http.NewRequest("GET", "https://www.osintcat.net/api/email-osint?query=user%40example.com&purpose=fraud+prevention", nil)
req.Header.Set("X-API-KEY", "YOUR_API_KEY")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(resp.StatusCode, string(body))
}
SDK example
The same request with the official SDKs. Each one reads your key fromOSINTCAT_API_KEY.
import { OsintCatClient } from "osintcat";
const client = new OsintCatClient(); // reads OSINTCAT_API_KEY
const result = await client.email.lookup({
query: "user@example.com",
purpose: "fraud prevention"
});
console.log(result);
from osintcat import OsintCat
client = OsintCat() # reads OSINTCAT_API_KEY
result = client.email.lookup(
query="user@example.com",
purpose="fraud prevention",
)
print(result)
package main
import (
"context"
"fmt"
osintcat "github.com/OsintCatHQ/osintcat-go"
osintcatclient "github.com/OsintCatHQ/osintcat-go/client"
)
func main() {
client := osintcatclient.NewClient() // reads OSINTCAT_API_KEY
request := &osintcat.LookupEmailRequest{
Query: "user@example.com",
Purpose: "fraud prevention",
}
result, err := client.Email.Lookup(context.Background(), request)
if err != nil {
panic(err)
}
fmt.Printf("%+v\n", result)
}
<?php
require __DIR__ . '/vendor/autoload.php';
use OsintCat\OsintCatClient;
use OsintCat\Email\Requests\LookupEmailRequest;
$client = new OsintCatClient(); // reads OSINTCAT_API_KEY
$result = $client->email->lookup(
new LookupEmailRequest([
'query' => 'user@example.com',
'purpose' => 'fraud prevention',
]),
);
echo json_encode($result, JSON_PRETTY_PRINT), PHP_EOL;
Response
Results for the same address may come from a cache for up to 15 minutes.object
object
{
"results": {
"register": [
{
"site": "example-shop.com",
"exists": true
}
],
"breach": [
{
"name": "Example 2021",
"date": "2021-04-02"
}
],
"api": []
},
"_meta": {
"plan": "investigator",
"lookups_left": 739
}
}
Errors
| Status | Error | When |
|---|---|---|
| 400 | USER_AGENT_IDENTITY_REQUIRED | No purpose given. |
| 401 | API key required | No X-API-KEY header. |
| 402 | INSUFFICIENT_BALANCE | The allowance is used up and your balance does not cover the lookup. |
| 422 | EMAIL_NOT_ALLOWED | This address cannot be looked up. Not charged. |
| 424 | Provider Error | The lookup could not be completed. Not charged. |
Was this page helpful?
⌘I
curl "https://www.osintcat.net/api/email-osint?query=user%40example.com&purpose=fraud+prevention" \
-H "X-API-KEY: YOUR_API_KEY"
import requests
url = "https://www.osintcat.net/api/email-osint"
params = {"query": "user@example.com", "purpose": "fraud prevention"}
headers = {"X-API-KEY": "YOUR_API_KEY"}
response = requests.get(url, params=params, headers=headers, timeout=60)
print(response.status_code, response.json())
const response = await fetch("https://www.osintcat.net/api/email-osint?query=user%40example.com&purpose=fraud+prevention", {
headers: { "X-API-KEY": "YOUR_API_KEY" },
});
console.log(response.status, await response.json());
<?php
$curl = curl_init("https://www.osintcat.net/api/email-osint?query=user%40example.com&purpose=fraud+prevention");
curl_setopt_array($curl, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => ["X-API-KEY: YOUR_API_KEY"],
]);
$response = curl_exec($curl);
$status = curl_getinfo($curl, CURLINFO_RESPONSE_CODE);
curl_close($curl);
echo $status . " " . $response;
package main
import (
"fmt"
"io"
"net/http"
)
func main() {
req, _ := http.NewRequest("GET", "https://www.osintcat.net/api/email-osint?query=user%40example.com&purpose=fraud+prevention", nil)
req.Header.Set("X-API-KEY", "YOUR_API_KEY")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(resp.StatusCode, string(body))
}
{
"results": {
"register": [
{
"site": "example-shop.com",
"exists": true
}
],
"breach": [
{
"name": "Example 2021",
"date": "2021-04-02"
}
],
"api": []
},
"_meta": {
"plan": "investigator",
"lookups_left": 739
}
}
