
GITNUXSOFTWARE ADVICE
Cybersecurity Information SecurityTop 10 Best Doxing Software of 2026
Ranking roundup of doxing software tools for OSINT workflows in 2026, including Snusbase, Hunter.io, ThatsThem, Maltego, and Recon-ng.
How we ranked these tools
Core product claims cross-referenced against official documentation, changelogs, and independent technical reviews.
Analyzed video reviews and hundreds of written evaluations to capture real-world user experiences with each tool.
AI persona simulations modeled how different user types would experience each tool across common use cases and workflows.
Final rankings reviewed and approved by our editorial team with authority to override AI-generated scores based on domain expertise.
Score: Features 40% · Ease 30% · Value 30%
Gitnux may earn a commission through links on this page — this does not influence rankings. Editorial policy
Snusbase is the best pick when analysts need rapid identity candidate lists from leaked credential and personal-data sets for OSINT investigations, while Hunter.io suits automated email discovery and verification for known domains, and ThatsThem works when you want case-style identity consolidation without building pipelines.
Editor’s top 3 picks
Three quick recommendations before you dive into the full comparison below — each one leads on a different dimension.
Snusbase
Reverse username lookup that ties handle-based input to consolidated identity results across datasets.
Hunter.io
Editor pickBuilt-in email validation checks for candidate addresses directly in the discovery workflow.
ThatsThem
Editor pickCase compilation that preserves identity links across multiple search passes for analyst review.
Related reading
Comparison Table
This ranking targets analysts and operators who need verifiable intelligence workflows for identity and breach investigations without turning automation into guesswork. The comparison emphasizes mechanisms like query coverage across leaked datasets, email and contact enrichment patterns, and API or workflow integration for repeatable OSINT pipelines.
Snusbase
vertical specialistData breach search engine allowing queries across leaked credential and personal data sets.
Reverse username lookup that ties handle-based input to consolidated identity results across datasets.
Snusbase is geared toward compiling a PII-centric dossier by running search requests and surfacing matching records from multiple breach and public datasets. Identity correlation is the core mechanic, with features like reverse username lookup and contact detail search designed to reduce manual cross-referencing. The platform also provides an investigation path that tends to stay within a single interface rather than requiring many separate data broker integrations.
A key tradeoff is limited visibility into how each individual source record was derived, which can constrain validation-heavy investigations. Snusbase fits best when an analyst needs quick candidate identification and evidence grouping before moving to deeper verification in external sources.
- +Username and contact searches return fast identity candidate matches
- +Cross-breach correlation supports quicker triage than single-source queries
- +Export-friendly results help feed casework and reporting workflows
- +Investigation stays inside one interface for many common lookups
- –Source lineage detail can be thin for strict validation workflows
- –Less useful for infrastructure-focused enumeration like subdomains or DNS
- –Bulk investigation can hit speed ceilings without careful batching
- –Governance controls for team workflows are limited compared with enterprise audit suites
Fraud analysts
Link suspected accounts across datasets
Shorter investigation start window
Incident response teams
Correlate breach sightings to people
Faster enrichment of suspects
Show 2 more scenarios
Private investigators
Assemble a dossier for interviews
Better leads for follow-up
Compile consolidated identity matches to guide document requests and field follow-ups.
OSINT researchers
Prioritize targets from leaked datasets
Reduced manual cross-referencing
Use identity correlation to rank candidates before spending time on open web checks.
Best for: Fits when analysts need rapid identity candidate lists for OSINT investigations.
More related reading
Hunter.io
API-firstEmail finder and verifier that locates personal and professional email addresses by domain.
Built-in email validation checks for candidate addresses directly in the discovery workflow.
Hunter.io is distinct because its core loop is domain-first email discovery and validation rather than broad OSINT graph expansion. It provides tools for exporting results, grouping findings by domain, and running confirmation checks on candidate addresses. An OSINT team can feed domains from prior reconnaissance into Hunter.io to generate an initial outreach-ready list, then correlate outcomes in downstream tooling.
The primary tradeoff is that Hunter.io does not replace full investigation tooling for identity graph mapping, subdomain footprinting, or metadata extraction. It fits best when a workflow needs fast email address coverage for known organizations, then hands off verified candidates to CRM, ticketing, or case management systems for action. It is also less suitable as a standalone tool for de-anonymization work that depends on multiple independent public sources.
- +Domain-first search quickly returns candidate email addresses for an organization
- +Validation checks reduce the share of obviously undeliverable results
- +API supports automated enrichment inside recon and intake pipelines
- +Exportable findings help reuse targets across investigations
- –Limited coverage for non-email identity artifacts like social profiles
- –Results quality varies by domain and requires iteration on inputs
- –High-volume runs can trigger rate limits during automation
- –Requires governance to avoid collecting and retaining PII improperly
OSINT analysts
Generate contact lists from known domains
Faster verified address collection
Incident response teams
Triage likely breach communication addresses
Reduced time to reach stakeholders
Show 2 more scenarios
Security engineering teams
Automate enrichment via API
Higher throughput discovery pipeline
Use the API to batch-enrich domains from internal asset inventories and recon results.
Compliance and investigations
Curate address lists with export controls
Cleaner investigation documentation
Export findings for case workflows while keeping discovery scope tied to named domains.
Best for: Fits when email discovery needs to be automated for known target domains and verified before downstream use.
ThatsThem
SMBFree people search engine for reverse phone, email, and IP address lookups.
Case compilation that preserves identity links across multiple search passes for analyst review.
ThatsThem supports iterative people-search workflows that emphasize match review and identity consolidation, which fits OSINT aggregation use cases where multiple partial identifiers must agree. The workflow model centers on building a case from search results and then refining which linked records are retained for further correlation. The strongest fit appears in investigations that need consistent handling of multiple candidates tied to a single person profile.
A key tradeoff is that identity compilation relies on available third-party data, so coverage can vary for low-data or alias-heavy subjects. That makes ThatsThem most useful when the target has common identifiers like usernames, known profile handles, or documented contact points that improve cross-source match quality.
- +Case-oriented people linking that groups matching records for review
- +Repeatable investigation flow for consolidating identity evidence across runs
- +Focused output organization aimed at downstream case handling
- +Supports iterative refinement when multiple candidates appear
- –Coverage depends heavily on third-party record availability
- –Limited visibility into the underlying match logic per source
- –Workflow depth can lag tools built for granular enumeration
- –Export formats may require extra cleanup for analyst pipelines
OSINT analysts in casework
Consolidate matches for a single identity
Faster analyst reconciliation
Investigations team
Build relationship evidence trails
Cleaner relationship narratives
Show 2 more scenarios
Compliance and risk teams
Triage individuals for review
Reduced manual lookups
Compiles person-facing signals into an internal case-ready output for triage.
Digital forensics support
Reconcile partial identifiers
More complete subject profiles
Helps unify fragmented identifiers into a single investigative view.
Best for: Fits when investigations need case-style identity consolidation without building custom OSINT pipelines.
BeenVerified
SMBConsumer people search engine aggregating public records, contact details, and social profiles.
Address history and phone-linked profile compilation provide timeline reconstruction from consumer data.
BeenVerified is a people-search and data-broker aggregation service that focuses on compiled identity profiles and record links. It is distinct for its emphasis on end-user oriented profile pages that bundle phone, address, and age-related fields into one view.
Core capabilities include reverse phone and address searches, historical address aggregation, and alias-style identity matching across multiple sources. It also supports exportable search results for OSINT operators who need repeatable evidence collections from consumer-style datasets.
- +Compiled identity profiles combine phone and address signals in one record view
- +Reverse phone search reduces the need for manual cross-referencing across sources
- +Address history helps reconstruct likely residence timelines for attribution work
- +Result exports support repeatable collection during OSINT investigations
- –Limited automation tooling reduces suitability for large-scale OSINT pipelines
- –API access and extensibility details are not built around OSINT-style job orchestration
- –Some identity matches depend on fuzzy linking and can introduce false joins
- –Governance controls like RBAC and audit logs are not positioned for enterprise administration
Best for: Fits when OSINT workflows need quick consumer-record correlation for a single identity case.
Whitepages
enterprisePeople search and reverse phone lookup platform offering contact and address data.
Identity resolution across phone and address fields that returns geographic context for linkage decisions.
Whitepages aggregates identity and contact details from public and proprietary sources and exposes them through a search experience aimed at people search workflows. It is distinct for being built around name, phone, address, and related identity matching that returns both contact and geographic context.
For OSINT-style use, it functions as a third-party data broker interface that can feed PII compilation and cross-referencing pipelines. Its value in a doxing-adjacent workflow comes from record linkage and disambiguation rather than from active network discovery.
- +Fielded search supports name, phone, and address lookups for rapid pivoting
- +Results include location signals that reduce manual address normalization work
- +Identity matching helps disambiguate common names across connected records
- +Workflow fits analysts who need broker-style record retrieval at scale
- –Returns are not designed for provenance review of each attribute
- –Limited automation surface reduces API-first OSINT orchestration options
- –Output is less suitable for graph-wide enrichment compared with dedicated tooling
- –Governance controls for high-risk workflows are not clearly auditable
Best for: Fits when analysts need fast contact and location record retrieval for targeted cross-referencing.
SpyCloud
enterpriseCompromised credential and personal data intelligence platform sourced from breach data.
Breach dataset correlation that links identities across leaked account artifacts and normalized identifiers for fast analyst triage.
SpyCloud focuses on breach and identity intelligence workflows that generate people-centric matches from leaked data. It provides enrichment for account discovery and identity correlation, then outputs results suitable for investigations and OSINT pipelines.
The strongest differentiation is how it operationalizes breach correlation to accelerate link building across identifiers rather than starting from raw sources every time. It also offers interfaces for automation and case workflow integration so teams can run repeatable de-duplication and alerting logic.
- +Breach correlation accelerates identifier linkage across investigations
- +Automation interfaces fit batch enrichment and recurring monitoring runs
- +De-duplication and normalization reduce noisy duplicate matches
- +Case-ready outputs support analyst review and triage
- –Results depend on coverage of specific breach datasets and identifiers
- –Governance and data handling rules require deliberate admin configuration
- –Less suitable for deep source-specific scraping and harvesting
- –API usage requires building mapping logic to internal identifiers
Best for: Fits when teams need repeatable breach-based identity correlation and enrichment in OSINT investigations.
LeakCheck
vertical specialistBreach data search platform for finding leaked credentials and personal information.
Evidence-oriented identifier validation workflow that converts checks into investigation-ready, normalized outputs.
LeakCheck is positioned around people-data validation workflows that surface exposure signals for identifiers before OSINT pivoting. It focuses on compiling check results across multiple sources into a workflow output that can feed further investigation steps.
LeakCheck’s distinct value is the end-to-end repeatability of “identifier to exposure status to evidence” rather than only raw extraction. The tool is best evaluated for automation and integration depth in pipelines that handle PII compilation and cross-referencing pipelines.
- +Workflow output ties identifier checks to investigation-ready evidence artifacts
- +Automation-friendly runs support repeatable cross-referencing pipelines
- +Search result normalization reduces manual cleanup during investigation
- +Focused scope keeps outputs consistent across identifier types
- –Limited breadth compared with graph-first OSINT tooling
- –Governance controls for multi-analyst access may require extra process discipline
- –Lower transparency when source-level provenance details are needed
- –Throughput can become a constraint during large batch identifier runs
Best for: Fits when teams need repeatable identifier exposure checks feeding OSINT pivots without building custom correlation logic.
PeopleFinders
SMBPeople search and reverse lookup platform for finding contact details and public records.
Address-history centric result pages that connect names to prior locations for manual lead triage.
PeopleFinders is a people search site that compiles public-facing profiles into a browsable result experience. Its core capability centers on address history, phone and address matching, and name-to-location linking for OSINT-style workflows.
The site also supports record-level views that help triage lead quality before deeper cross-referencing. PeopleFinders is best treated as a curated starting point for PII compilation rather than an extensible automation surface.
- +Name-to-address linking helps quickly narrow candidate identities
- +Record view format supports manual triage for lead quality
- +Phone and address matching reduces time spent on initial sorting
- +Geographic hints from results speed up location-focused verification
- –No documented public API for automation or system integration
- –Limited provenance detail for each field complicates evidentiary use
- –Results depend on matching heuristics that can mislink similar names
- –Designed for browsing rather than high-throughput reconnaissance workflows
Best for: Fits when analysts need fast, human-readable address and identity leads before cross-checking elsewhere.
WhoisXML API
API-firstWhoisXML API supplies WHOIS, DNS, reverse DNS, subdomain, and threat intelligence data through APIs.
Entity-focused WHOIS enrichment with monitoring-friendly retrieval patterns for iterative OSINT workflows.
WhoisXML API supplies programmatic WHOIS and related public-record datasets via an API built for OSINT aggregation. The product centers on high-volume data retrieval workflows such as WHOIS harvesting, domain enrichment, and continuous record monitoring for entities.
Its automation surface is driven by API endpoints that return structured results for downstream correlation and PII compilation pipelines. Data freshness and normalization are practical strengths for cross-referencing pipelines that need consistent identifiers across repeated lookups.
- +Structured WHOIS lookup responses for immediate pipeline ingestion
- +Monitoring-style workflows for recurring enrichment and change tracking
- +High-throughput API patterns for batch OSINT aggregation
- +Consistent entity identifiers that support cross-source correlation
- –WHOIS-centric coverage leaves gaps for non-WHOIS intelligence needs
- –Response interpretation requires data cleaning for reliable comparisons
- –Complex request flows can slow governance for larger deployments
- –Automation often depends on building and maintaining correlation logic
Best for: Fits when investigators need automated WHOIS harvesting and recurring entity enrichment inside an existing OSINT pipeline.
DomainTools
enterpriseDomainTools provides WHOIS history, DNS intelligence, passive DNS, and domain-investigation data.
WHOIS harvesting plus DNS footprinting history in a single workflow for domain-centric investigations.
DomainTools is built around managed intelligence collection for domain, IP, and identity research, with an emphasis on records aggregation rather than interactive graph building. Core capabilities include WHOIS harvesting, DNS footprinting tied to domain and host history, and enrichment workflows that compile signals into investigation outputs.
The product also supports data export patterns used in OSINT pipelines, with an API surface for pulling and automating lookups at scale. Governance is oriented around enterprise account administration and auditability rather than analyst-level notebook automation.
- +WHOIS harvesting tied to domain and hosting context supports repeatable research
- +DNS footprinting helps track infrastructure changes across time
- +API access enables automated enrichment in OSINT workflows
- +Enterprise-style account controls fit regulated investigation programs
- –Less suited to analyst-led visual OSINT graph workflows
- –Automation depth depends on using the API and exports effectively
- –Data coverage is concentrated on domain related signals over broad social targeting
- –Requires disciplined input hygiene to avoid noisy correlation outputs
Best for: Fits when teams need repeatable domain and infrastructure intelligence automation across investigations.
Conclusion
After evaluating 10 cybersecurity information security, Snusbase stands out as our overall top pick — it scored highest across our combined criteria of features, ease of use, and value, which is why it sits at #1 in the rankings above.
Use the comparison table and detailed reviews above to validate the fit against your own requirements before committing to a tool.
How to Choose the Right doxing software
This guide compares Snusbase, Hunter.io, ThatsThem, BeenVerified, Whitepages, SpyCloud, LeakCheck, PeopleFinders, WhoisXML API, and DomainTools for authorized OSINT investigations. Snusbase ranks first for rapid reverse username lookup and cross-breach identity correlation.
The tools differ by evidence source and workflow design. Hunter.io focuses on domain-based email discovery, SpyCloud and LeakCheck process exposed identifiers, and WhoisXML API and DomainTools support domain and DNS research.
OSINT workflow fit: correlation depth, automation surface, and evidence handling
Doxing software for authorized OSINT work is mainly judged by how fast it turns identifiers into analyst-ready leads. Snusbase converts handle input into consolidated identity candidates and accelerates triage with cross-breach correlation.
Identifier-to-identity correlation from different input types
Snusbase turns reverse username lookup into consolidated identity results across datasets. SpyCloud correlates normalized identifiers across breach artifacts to produce faster linkage for triage.
Evidence-ready output versus raw lookup results
LeakCheck outputs identifier checks as investigation-ready normalized artifacts. ThatsThem preserves identity links across multiple search passes so analysts can review case-style consolidation.
Automation and workflow reuse for recurring enrichment
WhoisXML API provides structured WHOIS lookup responses designed for monitoring-style recurring enrichment. BeenVerified is better for single-identity correlation because its automation tooling is limited for large-scale OSINT orchestration.
Email discovery with built-in validation checks
Hunter.io supports domain-first email discovery with built-in email validation checks for candidate addresses. Other tools in this set skew toward identity or infrastructure discovery rather than validated email outputs.
Infrastructure context for domain and DNS research
DomainTools combines WHOIS harvesting with DNS footprinting history for domain-centric investigations. WhoisXML API stays WHOIS-centric, so it leaves gaps for DNS-focused infrastructure change tracking.
Choose by input identifier, expected output format, and automation target
The correct tool choice depends on the first identifier available and the downstream artifacts needed by the investigation workflow. Snusbase and Hunter.io optimize different starting points, since Snusbase starts from usernames and Hunter.io starts from organization domains.
Pick the tool that matches the primary starting identifier
Choose Snusbase when the investigation begins with a username or handle and needs identity candidate consolidation across datasets. Choose Hunter.io when the investigation begins with a target domain and needs candidate email addresses with validation checks.
Select the output format that fits evidence review
Choose LeakCheck when identifier exposure checks must be converted into investigation-ready normalized outputs for OSINT pivots. Choose ThatsThem when cross-pass identity links must be preserved in a case-style compilation for analyst review.
Match the tool to automation and batch enrichment needs
Choose WhoisXML API when automated WHOIS harvesting and recurring entity enrichment must be ingested into an existing pipeline as structured responses. Choose SpyCloud when batch enrichment and recurring monitoring runs must correlate identities across breach artifacts.
Decide between consumer profile timelines and breach correlation
Choose BeenVerified when address history and phone-linked profile compilation must reconstruct timelines from consumer records in one view. Choose SpyCloud when the priority is breach dataset correlation that links identities across leaked account artifacts and normalized identifiers.
Use infrastructure-focused tools only when the workflow requires DNS context
Choose DomainTools when domain research must include DNS footprinting history alongside WHOIS harvesting. Choose WhoisXML API when WHOIS-centric monitoring is sufficient and DNS footprinting history is not required.
Choose governance-sensitive tools with deliberate admin configuration
Choose LeakCheck and SpyCloud when breach or exposure evidence handling requires deliberate admin configuration and governance discipline for multi-analyst access. Avoid using PeopleFinders and Whitepages as the automation backbone when the workflow needs API-first orchestration and detailed provenance per field.
Common pitfalls that break evidence handling and automation goals
Many workflows fail when investigators treat a lookup tool as a universal OSINT graph engine. Several tools in this set focus on specific evidence sources, so output quality depends on matching the tool to the right starting identifier and evidence type.
Using Snusbase as an infrastructure enumeration engine for subdomains or DNS
Snusbase optimizes handle-based identity candidate consolidation, so results are less suited for subdomain or DNS-style enumeration workflows.
Treating LeakCheck outputs as authoritative without process governance
LeakCheck can produce normalized investigation-ready artifacts, but governance and evidence handling rules still require deliberate admin configuration for multi-analyst access.
Building large-scale OSINT automation around BeenVerified-style profile compilation
BeenVerified prioritizes consumer-record correlation for a single identity case and offers limited automation tooling, which reduces suitability for large-scale job orchestration.
Choosing PeopleFinders or Whitepages when the workflow needs API-first orchestration
PeopleFinders lacks a documented public API for automation, and Whitepages limits API-first OSINT orchestration options even though it supports targeted name, phone, and address lookups.
Expecting WHOIS tools to provide full infrastructure history without exports and data cleaning
WhoisXML API is WHOIS-centric, so DNS footprinting needs are better served by DomainTools, and WHOIS response interpretation often requires data cleaning for reliable comparisons.
How We Selected and Ranked These Tools
We evaluated Snusbase, Hunter.io, ThatsThem, BeenVerified, Whitepages, SpyCloud, LeakCheck, PeopleFinders, WhoisXML API, and DomainTools on feature fit for OSINT workflows, speed of turning identifiers into investigation artifacts, and evidence handling that supports analyst triage. Features counted for 40% of the score by comparing identity correlation patterns, evidence-oriented outputs, and workflow automation orientation across the set.
Ease counted for 30% by measuring how directly the tools match expected input types like usernames, domains, emails, phone numbers, and WHOIS entities to usable outputs. Value counted for 30% by weighing how well each tool avoids manual stitching for the workflows it is designed to support, and Snusbase separated itself with reverse username lookup plus cross-breach identity correlation that reduces triage time versus single-source lookups.
Frequently Asked Questions About doxing software
Which tool list items provide reverse username lookup instead of email or domain discovery?
How do Hunter.io and WhoisXML API differ for automating OSINT pipelines?
What breaks if identity consolidation must persist across multiple search passes?
When should breach dataset correlation be used instead of manual record linkage?
How does LeakCheck convert exposure checks into evidence-oriented outputs?
Which tools return location context that supports timeline reconstruction?
What admin controls and governance controls are typical for domain intelligence platforms compared to people-search tools?
How do SSO and RBAC requirements affect tool selection for team deployments?
Which tool types are better for data model consistency during data migration from existing OSINT pipelines?
Tools reviewed
Primary sources checked during evaluation.
Referenced in the comparison table and product reviews above.
Keep exploring
Comparing two specific tools?
Software Alternatives
See head-to-head software comparisons with feature breakdowns, pricing, and our recommendation for each use case.
Explore software alternatives→In this category
Cybersecurity Information Security alternatives
See side-by-side comparisons of cybersecurity information security tools and pick the right one for your stack.
Compare cybersecurity information security tools→FOR SOFTWARE VENDORS
Not on this list? Let’s fix that.
Our best-of pages are how many teams discover and compare tools in this space. If you think your product belongs in this lineup, we’d like to hear from you—we’ll walk you through fit and what an editorial entry looks like.
Apply for a ListingWHAT THIS INCLUDES
Where buyers compare
Readers come to these pages to shortlist software—your product shows up in that moment, not in a random sidebar.
Editorial write-up
We describe your product in our own words and check the facts before anything goes live.
On-page brand presence
You appear in the roundup the same way as other tools we cover: name, positioning, and a clear next step for readers who want to learn more.
Kept up to date
We refresh lists on a regular rhythm so the category page stays useful as products and pricing change.
