OSINT Tools List, Organized by the Question You Are Answering
Most OSINT tool lists are alphabetical directories of several hundred links, which is the least useful possible ordering. You do not have a category. You have a question.
This list is grouped by the question, kept short on purpose, and each entry says what the tool is actually for. Last reviewed 4 September 2026.
- Passive collection only.
- Public sources.
- Findings carry their record.
- Domains only, never a person.
Who runs this domain, and what does it expose?
Osintpro domain footprint
- Use it when
- You need the answer in a form somebody else will review.
- Note
- DNS, registration, certificate authorization and hosting in one scoped pass, every finding sourced and timestamped.
dig / DNS-over-HTTPS resolvers
- Use it when
- You want one record, exactly, right now.
- Note
- Nothing is faster or more precise. You are the evidence chain.
RDAP (rdap.org)
- Use it when
- You need registration data in structured form.
- Note
- The standardized replacement for port-43 WHOIS. JSON, per-registry, and it tells you which server answered.
crt.sh
- Use it when
- You need hostnames that DNS enumeration missed.
- Note
- Certificate transparency logs surface names that were issued for and then forgotten. Often the best single source for a forgotten estate.
OWASP Amass
- Use it when
- You need depth and you have time.
- Note
- The most thorough open-source mapping there is. Long runs, real output.
Shodan / Censys
- Use it when
- You need to know what is listening.
- Note
- Active scanning at their end. Excellent on your own estate; think about authorization before pointing it elsewhere.
Is this company what it says it is?
Companies House (UK)
- Use it when
- The counterparty is UK registered.
- Note
- Free, structured, and includes filing history, officers and charges. One of the best public registries anywhere.
SEC EDGAR (US)
- Use it when
- The counterparty is a US public filer.
- Note
- Full text search across filings. Slow to learn, extremely rich once you can read a 10-K.
OpenCorporates
- Use it when
- You do not know the jurisdiction yet.
- Note
- Aggregates many registries. Coverage and freshness vary by jurisdiction, so treat it as a pointer to the primary source rather than the source.
National sanctions and PEP lists
- Use it when
- You have a compliance obligation.
- Note
- Use the official publisher, not a mirror. The date of the list matters as much as the hit.
Domain registration age
- Use it when
- The company is new to you.
- Note
- Cheapest fraud check available. See the WHOIS lookup tool.
Can this domain be abused against us?
SPF, DKIM and DMARC posture
- Use it when
- Anyone can send mail claiming to be you.
- Note
- The single highest-value ten-minute check on any estate. Run it with the DNS lookup tool.
CAA records
- Use it when
- You want to close the certificate issuance surface.
- Note
- Without CAA any publicly trusted authority may issue for your name.
Lookalike domain registration
- Use it when
- Your brand is being imitated.
- Note
- New registrations resembling your name, with the registration evidence attached, are the start of most phishing infrastructure.
Certificate transparency monitoring
- Use it when
- You want to know when someone issues for a name near yours.
- Note
- CT logs are public and near real time.
What is deliberately not on this list.
No people-search, username-lookup or reverse-email tools appear here, and that is not an oversight.
Those tools exist, they get enormous search volume, and building a page around them would be the easiest traffic on this site to win. They also point at exactly the use we refuse to serve, and a list that quietly includes them while the rest of the site promises authorized use only would be dishonest.
Where a lawful basis genuinely exists, for example consent-backed corporate screening, that work belongs inside a scoped case with the basis recorded, not inside a lookup box. Our position is set out in full on social media OSINT and in the FAQ.
More OSINT tools and lookups
New to the category? Start with open source intelligence, then see how a scoped case runs or read the analyst notes on the blog.
Run one scoped sweep and see what a sourced finding looks like.
The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.
- Passive collection only, from public sources.
- A domain, never a person. There is no input for one.
- Your case data stays yours. No card required.