DEV Community

Rxkov
Rxkov

Posted on Originally published at blog.mago.team

An Email Is a Hash, a Commit, and a Mailbox Policy

Most email OSINT tutorials start at a breach index. Start at the mailbox string itself. Three public facts fall out of one address before anyone pays for a dump.

The local part plus the domain is a Gravatar hash. Git stores the same string as a commit author. The domain publishes SPF and DMARC. Together they tell you who the person is, where they commit, and whether anyone can spoof the name.

Hash the mailbox, do not guess the face

Gravatar still keys profiles on a digest of the trimmed, lowercased address. Automattic documents the identifier in the REST hash guide. The public JSON is https://en.gravatar.com/{hash}.json.

import hashlib, json, urllib.request

email = "user@example.com".strip().lower()
digest = hashlib.md5(email.encode("utf-8")).hexdigest()
url = f"https://en.gravatar.com/{digest}.json"
with urllib.request.urlopen(url, timeout=10) as resp:
    profile = json.load(resp)
entry = profile["entry"][0]
print(entry.get("displayName"), entry.get("preferredUsername"))
print(entry.get("thumbnailUrl"))
Enter fullscreen mode Exit fullscreen mode

A 200 with displayName is a public card. Display name, username, about text, and linked accounts are opt-in. A 404 means no public profile for that hash. It does not mean the mailbox is fake.

hashtray and similar tools reverse the hash by generating candidate addresses from the public card and hashing them until one matches. That is a dictionary attack on a public MD5. It is not a Gravatar "decrypt". Treat a reversed mailbox as a hypothesis until another source repeats it.

Git already published the author

Every Git commit embeds author and committer as name plus email. GitHub shows that metadata on public repos unless the user enabled email privacy. The GitHub API exposes it on commit objects.

GET https://api.github.com/search/commits?q=author-email:user@example.com
Enter fullscreen mode Exit fullscreen mode

Accept header must be application/vnd.github+json. A personal token raises the rate limit. Hits return repo, SHA, and the author login GitHub attached to that email.

GitHub documents two noreply forms. ID+login@users.noreply.github.com and login@users.noreply.github.com. Both name the login. A corporate mailbox on public commits is a stronger identity signal than a handle match on a signup page.

The commit search API is preview-stable under application/vnd.github+json. Sort by committer-date if you need the last live use of that mailbox. A 2019 commit and a 2026 commit are different leads.

Do not treat one commit as same-person proof. Shared CI bots, rewritten history, and --author spoofing exist. Two repos, a Gravatar card, and a matching login is a working cluster. One hit is a lead.

The domain tells you if the name can be forged

Look up the registrable domain, not the person, for mail policy.

dig +short TXT example.com
dig +short TXT _dmarc.example.com
Enter fullscreen mode Exit fullscreen mode

v=spf1 ... -all is an explicit fail. ~all is softfail. A missing SPF record is not a pass. DMARC p=none is monitor-only. p=quarantine and p=reject are the policies that stop spoofed From headers at receiving MTAs.

A mailbox on a domain with p=none can be impersonated in a phishing wave even when the person is real. That fact belongs in the identity report next to the Gravatar photo. It is not a side quest.

WHOIS on the same domain is registrar data. RU-CENTER, GoDaddy, and Squarespace abuse inboxes are not the human. Put those rows in infrastructure. Keep them out of the name field.

One selector, three hops

The useful first pass is boring on purpose.

  1. Hash the mailbox. Read the Gravatar JSON.
  2. Search public commits for author-email.
  3. Read SPF and DMARC on the domain.

Stop there if all three are empty. Pay for a breach index only when the public graph is thin and the case still needs it. Have I Been Pwned and similar services are keyed APIs. They are not the first hop.

mago.team runs this identity pack on a pasted mailbox. Gravatar, GitHub, and mail policy sit in the same report. Credits follow the spell table. The hunt is the mailbox. The dump is optional.

What not to mix into the name field

WHOIS registrant_name is often the registrar. "Regional Network Information Center, JSC dba RU-CENTER" is not a human identity. Squarespace abuse-complaints@ and NIC.RU tld-abuse@ are role mailboxes. Put them under registrar. Keep them out of the person's card.

GitHub handle collision is the other trap. A 200 on https://github.com/alice for mailbox alice@brand.com is a page, not same-person proof. The commit search with author-email is the join key. The handle is a maybe.

Disposable domains fail this pipeline on purpose. No Gravatar card. No corporate DMARC. No commit graph. That emptiness is the finding. Do not pad it with unconfirmed social URLs.

The first-pass identity report should be short. Photo if Gravatar has one. Login if commits join. Mail policy if the domain publishes it. Everything else is a pivot with a cost.

Top comments (0)