What problem does it solve? An email address is often the highest-value selector in an OSINT investigation, but proving it exists is hard and the techniques that do so expose the investigator. This Skill provides a disciplined, passive-first workflow for extracting intelligence from an email address without tipping off the subject. ## Core Features & Use Cases - Validation and Parsing: Distinguishes syntactic, MX/domain, and SMTP-level validation, handles Gmail dot and plus-tag normalization, and infers corporate email formats from known addresses. - Footprint Discovery: Checks Gravatar by MD5 hash, searches breaches and indexed documents for account registrations, and pivots the local part into username investigations. - Header Forensics: Reads the Received chain bottom-up, interprets SPF, DKIM, and DMARC verdicts, and fingerprints sending platforms via Message-ID and X-Mailer fields. - Use Case: During phishing triage, trace a suspicious invoice email back through its headers to identify the actual sending infrastructure, then check whether the claimed sender address appears in breach corpora. ## Quick Start Investigate the email address j.doe@example.com and report its validity, breach exposure, and likely owner with confidence grades.