Can you actually find someone online for free?
Yes, and more completely than the paid industry would like you to believe.
Every technique that matters here has a free implementation, because most of them were built by researchers before anybody worked out how to charge for them. Handle checking, breach lookups, reverse image search, public record searches and search-engine operators are all available at no cost, and several of the free versions are the best available at any price.
What you cannot get free is somebody doing the assembly. Six tools return six answers in six formats, and turning those into a statement about a person is manual work. That is the honest description of what a paid service sells, including this one.
Worth saying who is telling you this. We sell the merged version, so treat the rest of this page as a description of what you can have without us.
What is the free route, in order?
Cheapest first, because most searches end in the first two steps and the rest is wasted if you skip them.
- The photograph, reverse searched. Ten seconds, and it settles a fake outright.
- The handle, across platforms. The highest-yield identifier anybody has.
- The email address, against breaches. Dates it, which is what turns a list into a history.
- The name, in a search engine with operators. Weakest, and worth doing last.
The order is not preference. A stolen profile photograph makes every later step irrelevant, and a handle with a decade of history makes most of them unnecessary.
The reasoning behind that ordering is set out in which identifier finds the most accounts.
Most searches genuinely end at step one or two. The instinct to start with the most personal detail you hold, usually a phone number or a full name, is the instinct that costs the afternoon.
What does a search engine still do best?
Exact strings and constrained sites, which is a narrower job than people expect and one nothing else does as well.
Put the handle in quotation marks and the engine stops guessing at synonyms. Add site: and it searches one platform properly, which is often better than that platform's own search. Add a second term you already know — a city, an employer, a year — and a common name becomes tractable.
Use more than one engine, and not for thoroughness. They index differently and personalise differently, so a result that appears in one and not another is a fact about the indexes rather than about the person. Anything genuinely public tends to appear in both.
The one thing engines do badly is a bare common name. That is not a technique problem, it is that hundreds of people share it and nothing distinguishes them.

Six tools, an afternoon, and a pile of results nobody has joined up. The joining is the part you would be paying for.
Which free tools check handles?
Two, and between them they are better than anything sold for this specific job.
Sherlock checks a username across a few hundred sites and is the one to start with. Maigret checks several thousand and pulls out profile details rather than just existence, at the cost of a longer tail of dead sites in the output.
Both run on your machine, which matters more than it sounds: nothing you search is logged by anybody. If the handle you are checking is your own, that is the strongest privacy position available and it happens to be the free one. Our own username lookup covers 71 platforms and merges the result, which is a different trade rather than a better one.
Free is sometimes just better. No paid service checks more handles than Maigret. When a free tool leads its category, saying so is the only version of this article worth reading.
How do you check an email address for free?
Two tools, covering the two halves of the question.
Have I Been Pwned answers breach exposure, free, and is the authority the rest of the industry defers to. If your question is whether an address has leaked and when, stop here and pay nobody.
Holehe answers the other half: which services have an account registered to the address. It drives the forgotten-password flow across 120+ sites and does not alert the address owner. Roughly 30 of its modules rate-limit frequently, so a clean run takes patience.
Between them these two answer the two useful questions about an address: has it leaked, and where is it registered. What neither does is line the answers up, so a breach from 2016 and an account still live in 2026 stay two separate facts in two separate windows.
How that lining-up actually works is covered in the five-step procedure.
How do you check a photograph for free?
Reverse image search, and this is the one step where free is not merely adequate but genuinely the best option available.
Google Lens and TinEye both take an upload and find other places the same image appears. If a profile photograph turns up under a different name on a modelling site or somebody's abandoned account, the question is answered and nothing else needs doing.
We do not run reverse image search and would be worse at it than either of them. What our photo analysis reads is different: the data the camera wrote into the file, which is usually stripped by the time a picture reaches you through a messaging app.
So the honest split is that the free tools own the image question outright and we own a different one. Use both, in that order.
Where does the free route stop?
At the join, and that is a narrower limit than 'free is worse' but a real one.
Run all of the above and you have a terminal window of handle results, a browser tab of breach dates, a page of image matches and a search history. Nothing has told you that the display name in the third tool is the same string as the handle in the first, or that the account created in 2013 predates the breach from 2016 and therefore corroborates it.
The other stop is coverage of the account-existence check. Holehe covers 120+ sites; our email lookup runs 71 sources against an address and 71 platforms against a handle, merged, with the failures listed. Whether that difference is worth money depends entirely on how often you do this.
What does free actually cost you?
Two things, and the second is the one people miss.
Time. The free route is an afternoon for one person: installing two Python tools, running four searches, reading four outputs and reconciling them by hand. A merged lookup is under half a minute.
If you do this once, the afternoon is obviously cheaper. The arithmetic changes somewhere around the third search, and it changes permanently if you ever have to redo one because you cannot remember what you already checked.
A log, sometimes. Free splits into two kinds. Sherlock and Maigret run locally and nobody sees what you searched. Hosted free tools run on somebody's servers, and they are businesses.
That distinction matters most when the identifier you are checking is your own.
When is paying actually worth it?
Three situations, and outside them the free route is the right answer. This is worth stating plainly because the alternative — implying that free is second-rate — is the thing every other article on this query does.
- You do this repeatedly. The afternoon stops being cheap somewhere around the third search.
- You need it written down. A merged report with sources attached is something you can hand to somebody else. A terminal window is not.
- You need to know what failed. Free tools mostly print hits. Which sources were checked and did not answer is the difference between a gap and an absence.
If none of those apply, use the free tools. An article that told you otherwise would be an advertisement, and you would find out within an afternoon.
Common questions
Can you really find someone online for free?
Most of it, yes. Search engines cover public mentions, Sherlock and Maigret check handles across hundreds to thousands of sites, Have I Been Pwned covers breach exposure, Holehe checks which services an address is registered to, and Google Lens covers photographs. What no free route does is merge those answers into one report.
What is the best free people search tool?
There is no single one, because each covers a different identifier. For handles, Maigret checks the most sites of anything at any price. For breaches, Have I Been Pwned is the authority. For photographs, Google Lens or TinEye. For email account checks, Holehe. Most real work uses three of them together.
What should I search first?
The photograph, through a free reverse image search. It takes ten seconds and settles a stolen picture outright, which makes every later step unnecessary. Then the handle, because people reuse one for a decade. The name goes last: it is the weakest identifier and a common one returns nothing usable.
Are free OSINT tools as good as paid ones?
For single tasks, often better — no paid service checks more usernames than Maigret. The gap is assembly rather than capability. Six free tools return six outputs in six formats, and reconciling them into a statement about one person is manual work that paid services do for you.
Do free tools tell the person I searched them?
No. Handle checks read public profile pages, breach lookups query indexed files, and Holehe drives the forgotten-password flow without sending mail to the address. What can reach somebody is what you do afterwards, such as opening a profile on a network that shows visitors.
Is it safe to use free tools on my own details?
Depends which kind. Sherlock and Maigret run on your machine, so nothing you search is logged anywhere — that is the strongest privacy position available and it is free. Hosted free tools run the search on somebody else's servers and are businesses, which is worth knowing before typing in your own address.
How long does the free route take?
An afternoon for one person, most of it setup and reconciliation rather than searching: installing two Python tools, running four searches, then reading four different output formats and joining them by hand. A merged lookup is under half a minute, so the trade is time against money.
Is it legal to search for someone using free tools?
Searching publicly available sources is legal in the United States and the EU, and running the tool locally does not change that in either direction. Use is restricted: in the US, decisions about employment, housing, credit, insurance or tenancy fall under the Fair Credit Reporting Act. In the EU and UK, public personal data still needs a lawful basis under GDPR.
