Skip to main content

MailAccess

License: MIT Python 3.11+ Docker Compose PyPI version PyPI downloads

Self-hostable OSINT platform for investigating email addresses. Fan out across breach databases, social networks, DNS records, and the open web — get back a unified exposure score and structured findings you can export or pipe into Maltego.

Built for security researchers, OSINT analysts, and penetration testers operating under authorization. Read DISCLAIMER.md before use.

Terminal Output

MailAccess terminal output

Install

pip install mailaccess
mailaccess investigate you@example.com

The CLI auto-starts and stops the backend for each investigation. Use mailaccess serve when you want a persistent server, or install mailaccess[ml] for optional spaCy-based name classification.

Full install options (Docker, persistent server, self-hosting) -> docs/self-hosting.md.

Quick Start

mailaccess investigate you@example.com
mailaccess investigate you@example.com -o report.pdf
mailaccess harvest-emails --domain company.com
mailaccess harvest-emails --domain company.com --export harvest.csv
mailaccess keys set HIBP_API_KEY your-key
mailaccess keys list
mailaccess serve
mailaccess modules

Pipeline, stdin, JSONL, and CI examples -> docs/integrations.md.

Investigation demo

Harvest emails demo

What It Does

  • Identity graph - cross-platform correlation of accounts, usernames, names, avatars, breach data, and profile links.
  • Name Consensus Engine - synthesizes independent name signals into confirmed, probable, possible, or unknown identity bands.
  • Defender's Brief - security-manager-ready risk summary with prioritized findings and a concrete next action.
  • Domain email harvesting - harvest-emails discovers organization addresses across Common Crawl, GitHub, CT logs, registries, keyservers, dorks, employee pages, and patterns.
  • 5,000+ platform corpus - a native username-platform engine over a MailAccess-verified corpus of 5,000+ platform definitions (data/mailaccess_sites.json), with two-marker detection and zero runtime dependencies; each investigation probes a bounded, rank- and health-prioritized subset of the highest-signal platforms. Plus a native account-existence engine covering 250+ email-checkable services, and native Google-account intelligence (unauthenticated, on by default).
  • Deep breach mode - probes the highest-severity breach corpus for account-existence risk.
  • Credential Risk Score - separate 0-100 credential exposure band with top drivers and recommended next steps.
  • 6 export formats - JSON, CSV, PDF, Markdown, STIX 2.1, and Maltego XML.

Identity Graph

Every investigation builds an identity graph linking accounts by shared usernames, photos, display names, and breach data. View it at /investigation/:id/graph, export it with GET /api/report/{id}/graph, or read the full model in docs/modules.md.

Name Consensus Engine

MailAccess collects name signals from profile modules and returns a defensible identity summary:

CONFIRMED IDENTITY
  Name:     Katriel Moses  [CONFIRMED]
  Sources:  GitHub . Gravatar . Keybase . PGP
  Reasoning: 4 independent sources agree.

Full confidence rules and source behavior -> docs/modules.md.

Defender's Brief

Every investigation includes a 30-second risk summary designed for security managers:

DEFENDER'S BRIEF
  Risk:    CRITICAL
  Summary: Active infostealer infection detected.
  1. Active credential theft   [CRITICAL]
     -> Rotate credentials immediately.
  Next action: Immediately rotate credentials and enforce hardware MFA.

Suppress it with --no-brief; full details live in docs/modules.md.

Modules

75 modules over a 5,000+ platform corpus. Investigations probe a bounded, evidence-first wave of the highest-signal platforms (~700 vetted by default) rather than the whole corpus. Full module reference -> docs/modules.md.

API Keys

Most modules work with zero keys. Optional keys unlock more coverage. Full list -> docs/api-keys.md.

Export Formats

Save reports as JSON, CSV, PDF, Markdown, STIX 2.1, or Maltego XML with -o. Full export reference -> docs/exports.md.

Integrations

Use Maltego, Slack, Discord, generic webhooks, JSONL pipelines, and CI workflows. Full integration guide -> docs/integrations.md.

Self-Hosting

Run the CLI locally or launch the full web stack with Docker Compose. Full guide -> docs/self-hosting.md.

Changelog

See CHANGELOG.md for release history.

Troubleshooting

Troubleshooting demo

Links

Self-hosting guide Docker Compose, .env reference, PostgreSQL, proxy/Tor, Maltego setup
Module reference All modules, findings schema, adding new modules
False-positive controls Common-name, disposable-domain, clustering, health, and scoring controls
API reference REST endpoints, WebSocket events, authentication
Export formats Supported formats, MIME types, filename conventions
Integrations Maltego, Slack, Discord, generic webhooks
Brand assets Logo lockups, palette, typography, clearspace, downloadable SVGs
Sponsors Current partners and categories accepting sponsors
Contributing Adding modules, adding exporters, code style, PR checklist
PyPI pip install mailaccess
GitHub Source code, issues, releases

License

MIT. All data queried by MailAccess comes from public sources. See DISCLAIMER.md for authorized use cases and legal responsibility.

Metadata

Release files for mailaccess 0.15.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mailaccess 0.15.0
File Size Uploaded
mailaccess-0.15.0.tar.gz 22.5 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for mailaccess 0.15.0
File Interpreter ABI Platform
mailaccess-0.15.0-py3-none-any.whl Python 3 none any Details

Total release size: 24.0 MB

Release files / mailaccess-0.15.0.tar.gz

Download URL mailaccess-0.15.0.tar.gz
Size 22.5 MB
Tags Source
SHA-256 checksum
How to use checksums
e9181307eeec487a48da25c771fb0adbd1e8e09bc608fdd230748daebe3d850d
BLAKE2b-256 checksum
How to use checksums
f579ee6f98df909abfc6073d0bc0ac07e50b96de0237b576c8f5dc8455e3a1e3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.10.6

Release files / mailaccess-0.15.0-py3-none-any.whl

Download URL mailaccess-0.15.0-py3-none-any.whl
Size 1.6 MB
Tags Python 3
SHA-256 checksum
How to use checksums
4b23043b6d58873e9889dc3516ae247d16108be59ef58c20b68345423565c91b
BLAKE2b-256 checksum
How to use checksums
21130e50eb98c81b025e6d691292e1cda3049fe2038755a986b92fdeaf678101
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.10.6

Release history Release notifications | RSS feed

0.18.1

2 release files

0.18.0

2 release files

0.17.8

2 release files

0.17.7

2 release files

0.17.6

2 release files

0.17.5

2 release files

0.17.4

2 release files

0.17.3

2 release files

0.17.2

2 release files

0.17.1

2 release files

0.17.0

2 release files

0.16.0

2 release files

This release

0.15.0 This release

2 release files

0.14.5

1 release file

0.14.4

1 release file

0.14.3

1 release file

0.14.2

1 release file

0.14.1

1 release file

0.14.0

1 release file

0.13.4

1 release file

0.13.3

1 release file

0.13.2

1 release file

0.13.1

1 release file

0.13.0

1 release file

0.12.9

1 release file

0.12.8

1 release file

0.12.7

1 release file

0.12.3

1 release file

0.12.2

2 release files

0.12.0

2 release files

0.9.0

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.5

2 release files

0.5.3

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.4.3

2 release files

0.4.0

2 release files

0.3.8

2 release files

0.3.7

2 release files

0.3.6

2 release files

0.3.5

2 release files

0.3.4

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page