Skip to main content

mailaccess

License: MIT Python 3.10+ Docker Compose PyPI version PyPI downloads

mailaccess.pro  ·  Docs  ·  PyPI  ·  Changelog

Self-hostable OSINT platform for investigating email addresses. Fan out across breach databases, social networks, DNS records, and the open web, then get back a unified exposure score and structured findings you can export or pipe into Maltego.

Built for security researchers, OSINT analysts, and penetration testers operating under authorization. Read DISCLAIMER.md before use.

Install

pip install mailaccess
mailaccess investigate you@example.com

The CLI auto-starts and stops the backend for each investigation. Use mailaccess serve when you want a persistent server, install mailaccess[ml] for optional spaCy-based name classification, or mailaccess[browser] (then playwright install chromium) for the optional headless-browser account-existence oracles.

Full install options (Docker, persistent server, self-hosting) in docs/self-hosting.md.

Quick Start

mailaccess investigate you@example.com
mailaccess investigate you@example.com -o report.pdf
mailaccess harvest-emails --domain company.com
mailaccess harvest-emails --domain company.com --export harvest.csv
mailaccess find-email --name "Jane Doe" --domain company.com
mailaccess keys set HIBP_API_KEY your-key
mailaccess pro
mailaccess upgrade
mailaccess serve

Pipeline, stdin, JSONL, and CI examples in docs/integrations.md.

What It Does

  • Identity graph: cross-platform correlation of accounts, usernames, names, avatars, breach data, and profile links. View it at /investigation/:id/graph or export with GET /api/report/{id}/graph.
  • Name Consensus Engine: synthesizes independent name signals into confirmed, probable, possible, or unknown identity bands.
  • Defender's Brief: security-manager-ready risk summary with prioritized findings and a concrete next action.
  • Credential Risk Score: separate 0-100 credential exposure band with top drivers and recommended next steps.
  • Domain email harvesting: harvest-emails discovers organization addresses across Common Crawl, GitHub, CT logs, registries, keyservers, dorks, employee pages, and patterns. (Pro adds the decision-makers behind the domain.)
  • Company email patterns: find-email turns a name plus an employer domain into one honestly-graded likely address, offline from a bundled 384K-domain pattern index. Microsoft 365 mailboxes are verified where the provider allows.
  • 5,300+ platform corpus: a native username-platform engine over a MailAccess-verified corpus of 5,300+ platform definitions, with two-marker detection and zero runtime dependencies. Plus a native account-existence engine covering 357 email-checkable services — consumer apps, SaaS, and community forums, checked non-intrusively (full platform list & methods) — and native Google-account intelligence.
  • Deep breach mode: probes the highest-severity breach corpus for account-existence risk.
  • 6 export formats: JSON, CSV, PDF, Markdown, STIX 2.1, and Maltego XML.

MailAccess Pro

Your free harvest finds the addresses that are public. It does not find the people who make the decisions.

The names that matter, heads of security, procurement, and engineering, rarely show up in Common Crawl, CT logs, or a GitHub commit. MailAccess Pro closes that gap. Add a Pro key and any lead-gen harvest is enriched with real business contacts, each carrying name, role, company, email, and LinkedIn, aggregated from publicly-available and third-party commercial sources. One command turns a bare domain into a working outreach list:

$ mailaccess harvest-emails --domain acme.com
  312 addresses found

$ mailaccess harvest-emails --domain acme.com --mode public-business-contact
  312 found · 968 available with Pro
  ──────────────────────────────────────────────────────────────────
  Dana Reed    VP Security           Acme   dana.reed@acme.com   in/danareed
  Sam Okoye    Head of Procurement   Acme   s.okoye@acme.com     in/samokoye
  Priya Nair   Director, Platform    Acme   priya@acme.com       in/priyanair
  … 653 more business contacts (name, role, company, email, LinkedIn)

Why teams upgrade:

  • See the gap before you pay. Every free harvest prints the exact number of extra contacts Pro would add for that domain. No guessing, no vague multiplier.
  • Coverage the open web cannot give you. Reach the budget-owners and inboxes that public crawling misses entirely.
  • Company-name resolution. Skip the domain lookup: --company "Stripe" resolves it for you.
  • Founder pricing: $5/mo for the first 100 seats, then $9/mo. Locked for life, limited seats remaining. Run mailaccess pro for live availability.

Corpus contacts are live-only: they render in their own Pro surface and never touch your exports, local database, or history. If the service is unreachable, the harvest shows the full open result. Without a key, nothing changes.

Start with Pro → · how it works

Staying Up To Date

MailAccess checks PyPI for a newer release (cached, best-effort, never blocking) and prints an upgrade hint after a command when you're behind. Update in place with:

mailaccess upgrade

Silence the check with MAILACCESS_NO_UPDATE_CHECK=1. Prefer email? Get release notes in your inbox.

Modules

75 modules over a 5,300+ platform corpus. Investigations probe a bounded, evidence-first wave of the highest-signal platforms (~700 vetted by default) rather than the whole corpus. Full module reference in docs/modules.md.

API Keys

Most modules work with zero keys. Optional keys unlock more coverage. Full list in docs/api-keys.md.

Export Formats

Save reports as JSON, CSV, PDF, Markdown, STIX 2.1, or Maltego XML with -o. Full export reference in docs/exports.md.

Self-Hosting

Run the CLI locally or launch the full web stack with Docker Compose. Full guide in docs/self-hosting.md.

Sponsors

MailAccess is free and MIT licensed. Sponsors keep the corpus and infrastructure running.

Sponsor this project →

Self-hosting guide Docker Compose, .env reference, PostgreSQL, proxy/Tor, Maltego setup
Module reference All modules, findings schema, adding new modules
False-positive controls Common-name, disposable-domain, clustering, health, and scoring controls
API reference REST endpoints, WebSocket events, authentication
Export formats Supported formats, MIME types, filename conventions
Integrations Maltego, Slack, Discord, generic webhooks
Brand assets Logo lockups, palette, typography, clearspace, downloadable SVGs
Contributing Adding modules, adding exporters, code style, PR checklist

License

MIT. All data queried by MailAccess comes from public sources. See DISCLAIMER.md for authorized use cases and legal responsibility.


If MailAccess saved you time, a ⭐ on GitHub helps other researchers find it.

Metadata

Release files for mailaccess 0.18.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mailaccess 0.18.1
File Size Uploaded
mailaccess-0.18.1.tar.gz 26.5 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for mailaccess 0.18.1
File Interpreter ABI Platform
mailaccess-0.18.1-py3-none-any.whl Python 3 none any Details

Total release size: 32.0 MB

Release files / mailaccess-0.18.1.tar.gz

Download URL mailaccess-0.18.1.tar.gz
Size 26.5 MB
Tags Source
SHA-256 checksum
How to use checksums
83fdab0f665647291ea0bd19f45ff2670d09f09ba1ef17781ead7a18f0f30862
BLAKE2b-256 checksum
How to use checksums
67394e287998e560257b7ed2eec302fb608baa480f3226717ddbabd9963eb659
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.7

Release files / mailaccess-0.18.1-py3-none-any.whl

Download URL mailaccess-0.18.1-py3-none-any.whl
Size 5.5 MB
Tags Python 3
SHA-256 checksum
How to use checksums
363220e9c267d2e77c19978d210447eed97afd4c905ae73620b69919fcd45003
BLAKE2b-256 checksum
How to use checksums
d20a3ef1b2535af893710a9805883520eb244a8d8b05d3dd839669aecccb3d7f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.7

Release history Release notifications | RSS feed

This release

0.18.1 This release

2 release files

0.18.0

2 release files

0.17.8

2 release files

0.17.7

2 release files

0.17.6

2 release files

0.17.5

2 release files

0.17.4

2 release files

0.17.3

2 release files

0.17.2

2 release files

0.17.1

2 release files

0.17.0

2 release files

0.16.0

2 release files

0.15.0

2 release files

0.14.5

1 release file

0.14.4

1 release file

0.14.3

1 release file

0.14.2

1 release file

0.14.1

1 release file

0.14.0

1 release file

0.13.4

1 release file

0.13.3

1 release file

0.13.2

1 release file

0.13.1

1 release file

0.13.0

1 release file

0.12.9

1 release file

0.12.8

1 release file

0.12.7

1 release file

0.12.3

1 release file

0.12.2

2 release files

0.12.0

2 release files

0.9.0

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.5

2 release files

0.5.3

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.4.3

2 release files

0.4.0

2 release files

0.3.8

2 release files

0.3.7

2 release files

0.3.6

2 release files

0.3.5

2 release files

0.3.4

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page