Email Enumeration by Domain

Testing Methodology

  1. check the same domain (i.e. microsoft.com) using each tool
    • count the number of results
  2. rate difficulty of deployment
  3. rate quality of output
  4. rate development health
  5. rate automation potential

Phonebook.cz

phonebook.cz

  • requires IntelX account to use (free signup)
  • 39,601 results for microsoft.com

Hunter

Hunter search

Example Results

  • 35,830 results
  • also shows email format (i.e. {f}.{last}@domain.com

Deployment Difficulty

  • web hosted (easy difficulty)
  • has API

Output

  • can export subset of records from web interface
  • can export full records using API (if credits available in account)

Pricing

  • $50-400/month depending on plan
  • free plan available, limited quota per month

Infoga

Infoga repository

  • "Infoga is a tool gathering email accounts informations (ip,hostname,country,...) from different public source (search engines, pgp key servers and shodan) and check if emails was leaked using haveibeenpwned.com API"
  • Language: python

skymem.info

Warning: I have not confirmed this is a legitimate site.

skymem.info

Example Results

  • 36631 results

Deployment Difficulty

  • web hosted (easy difficulty)
  • No API

Pricing

  • varies by results size, not transparent
  • large lists get into $2000-3000 range!!!