Run a lookup

Guide

Which social accounts use this email address

Every sign-up form has to tell you when an address is already taken. That obligation is the entire mechanism.

10 min read The DetectiveCheck team
EmailSocial mediaGuide
A worn intercom panel with labelled buttons

The short answer

You find the social accounts on an email address by asking each platform whether an account is registered to it. Sign-up and password-reset forms have to answer that question to work at all, so the answer is public. On DetectiveCheck 71 sources are asked at once and the replies are merged into one report.

  • The mechanism is a side effect: a sign-up form that did not say when an address was taken would let two people share an account.
  • A run measured in July 2026 on a public address returned 19 confirmed accounts and 60 breach records out of the 74 sources asked, in 24 seconds.
  • 11 of those sources errored and 4 were rate-limited. That is normal and it is why an empty line is not the same as a no.
  • Several large platforms have deliberately closed this behaviour. Instagram is one, and no tool can check it today.

How do you find social accounts from an email address?

You ask every platform the one question it is obliged to answer, and you ask them all at the same time.

The question is: is there an account registered to this address? A person typing into a sign-up form needs to be told when the address is already taken, or two people end up sharing a login. Somebody who has forgotten a password needs to be told when it is not, or the reset goes nowhere. Both answers are given to anybody who asks, because the form cannot tell a stranger from a customer.

A lookup is the act of asking a few dozen of those forms in parallel and putting the replies side by side. Nothing is broken into and nothing is guessed.

@one address inAccounts confirmedDisplay namesBreach recordsJoin datesRefused to answer@one address inAccounts confirmedDisplay namesBreach recordsJoin datesRefused to answer
One address, and what each kind of source gives back. The dashed one is a platform that has stopped answering.

Why do platforms answer this question at all?

Because the alternative is a worse product, and every platform has quietly made the same trade.

Hide whether an address is registered and your sign-up form has to accept a duplicate and fail later, your password reset has to claim it sent mail it did not send, and your support queue fills with people who cannot tell which of their three addresses they used. Each of those is a real cost paid by real customers, every day.

The privacy leak, meanwhile, is invisible and diffuse. So the trade gets made in favour of the customer in front of you, which is a defensible decision and also the reason this technique works at all.

This is why the technique is stable. It does not depend on a leak, a scraper or a bug. It depends on a design decision that platforms keep making on purpose, which is why it has kept working for fifteen years.

What does a real result look like?

We ran one against a well-known public address while writing this, so the numbers below are a measurement rather than an illustration.

Seventy-four sources were asked in a run measured in July 2026. Nineteen confirmed an account. Sixty breach records came back. The whole thing took 24 seconds, because the sources run in parallel and the report waits for the slowest one.

Eleven sources errored and four were rate-limited in that same run measured in July 2026. That is a fifth of it, it is normal, and it is the single most important thing to understand about reading one of these reports: a source that failed is not a platform that said no. Any tool that shows you only the hits is hiding the difference, and the difference is where wrong conclusions come from.

OutcomeCountWhat it means
Account confirmed19The platform said yes
Breach records60The address appears in known dumps
Errored11The source failed. Unknown, not no
Rate-limited4Asked too often. Try again later
Sixty breach records are sixty services that once held a credential of yours, most of them years ago. That is what turns a list into a timeline.

Sixty breach records are sixty services that once held a credential of yours, most of them years ago. That is what turns a list into a timeline.

Which platforms have stopped answering?

Enough of them that naming the gaps is more useful than listing the wins, and one name matters more than the rest.

Instagram cannot be checked today. Not by us and not by the tools that say they can. It rate-limits requests from data centres, it requires a logged-in session for the endpoint that used to answer, and the public page returns the same shell for a real handle and an invented one. Anything promising you an Instagram result is reselling stale data or reading a page that no longer says anything.

Others have made the smaller change of answering the same way whether an address is registered or not, which is the correct fix and costs them the support burden described above. Expect this list to grow, and expect any tool's real coverage to be smaller than its marketing.

What do breach records add?

Two things that account checks cannot give you: proof of age, and a reason to act.

An account check tells you an address is in use now. A breach record tells you it was in use in 2016, on a service that got dumped, alongside whatever else that service held. That turns a flat list into a rough timeline, and a timeline is what distinguishes an address somebody has had for a decade from one created last month for one purpose.

If the address is yours, the records are also the only part of the report that asks something of you. Sixty appearances means sixty services that once held a password of yours. The useful response is not alarm, it is checking whether any of them shared a password you still use.

What if the address returns nothing?

Then you have learned something, as long as you can tell an empty result from a failed one.

A genuinely empty report — sources answered, none confirmed an account, no breach contains it — usually means the address is young, is used only to receive mail, or does not exist. If somebody has been writing to you from an address with no history whatever, that is worth knowing, and it is the answer to the question you actually asked.

A report where a third of the sources errored is a different object entirely. It means try again, not that there is nothing there. This is why every source is listed here with its own outcome instead of being folded into a score.

Can you check an email address for free?

Partly, and it is worth knowing exactly which part, because the free half is the half most people want.

  • Breach exposure. Have I Been Pwned answers this for free and is the authority. If that is your question, stop here.
  • A handful of account checks. Open-source tools such as Holehe run the same sign-up trick across a list of sites from your own machine.
  • Public mentions. The address in quotation marks, in more than one search engine.

What none of them do is run all of it at once and merge the answers, which is the work rather than the trick. Holehe returns a list of sites; it does not tell you which of those sites also appears in a breach from 2016, or that the display name on two of them is the same string.

Whether that merge is worth paying for depends entirely on how often you need it. For one address, once, the free route costs an afternoon and gets you most of the way.

Searching public sources is lawful in the United States and in the EU. What you do with the result is where the law actually lives.

In the United States, using a report to decide somebody's employment, housing, credit, insurance or tenancy puts you under the Fair Credit Reporting Act, and a consumer lookup service is not a consumer reporting agency. That use is not permitted here. In the EU and the UK, public personal data is still personal data and still needs a lawful basis under the GDPR.

Confirming an account is not confirming a person. An address can be shared, sold, inherited with a second-hand domain, or typed in by somebody else entirely. The report describes an address and what is attached to it. It does not describe who is holding the phone.

How to run one on DetectiveCheck

Three steps, and the third is the one worth your attention.

  1. Open the email lookup and paste the address. Variants with dots and plus signs are normalised, so the form you have is the form to use.
  2. Wait for the sources. Seventy-one sources run, they run in parallel, and a full report is usually under half a minute.
  3. Read the failures alongside the hits. Every source is listed with what it returned, including the ones that errored or were rate-limited, because those are the lines that decide how much the rest is worth.

The step most people skip is the one that pays. A display name or a handle that came back from one platform is a new identifier, and running that through the username lookup routinely returns more than the address did.

You can see the whole shape of a finished report in the sample report without creating an account.

Common questions

How do I find what accounts are linked to an email address?

Ask each platform whether an account is registered to it. Sign-up and password-reset forms must answer that to function, so the answer is public. Running the check across many services at once and merging the replies is what produces a report. On DetectiveCheck 71 sources are asked in parallel and a full run usually finishes in under half a minute.

Can you find someone's Instagram from their email?

No, and neither can anything else today. Instagram rate-limits requests from data centres, requires a logged-in session for the endpoint that used to answer, and serves the same public page for a real handle and an invented one. A service promising an Instagram result from an address is reselling old data or reading a page that no longer distinguishes the two.

Why did some sources fail in my report?

Because a fifth of a typical run does. In a run measured in July 2026, 11 of 74 sources errored and 4 were rate-limited. A source can be down, can be blocking the request, or can have changed its sign-up flow that morning. A failed source is unknown rather than negative, which is why each one is listed with its own outcome instead of being hidden.

Is it legal to look up an email address?

Searching publicly available sources is legal in the United States and the EU. Use is restricted: in the US, deciding employment, housing, credit, insurance or tenancy from a lookup falls under the Fair Credit Reporting Act and is not permitted with a consumer service. In the EU and UK, public personal data still requires a lawful basis under the GDPR.

Does the person find out I searched their email?

No. The check queries public sources and the account-existence behaviour platforms expose themselves. It sends no mail, no friend request and no password reset. What can reach them is what you do next: writing to the address, or opening a profile on a network that shows visitors, are both visible actions the search itself never takes.

What is the difference between this and Have I Been Pwned?

Have I Been Pwned answers one question extremely well: which known breaches contain this address. It does not check whether accounts currently exist on individual platforms. A full lookup does both and merges them, so a breach from 2016 and a live account in 2026 appear in the same timeline. For breach exposure alone, use Have I Been Pwned.

Can I do this with a work email address?

Yes, and a work address usually returns more. The domain is not a free provider, so it carries its own registration records, and the part before the at sign is normally built from a real name. That combination often identifies a person where a free-provider address would not. The same legal limits on how you use the result apply.

How accurate are the results?

Account confirmations and breach records are the reliable part, because they come from the platform or the breach corpus itself. Anything inferred, such as a full name guessed from the address, is the least reliable. A report worth reading marks the difference; treat any tool that does not distinguish confirmed from inferred as unverified throughout.

What should I do if my own address returns 60 breaches?

Not panic, and not change the address. Sixty appearances means sixty services once held a credential of yours, most of them years ago. The action that matters is checking whether any password you still use was among them, and changing that password everywhere you reused it. The address itself is rarely the problem.

In short

Platforms answer whether an address is registered because their own sign-up and reset forms have to. That is a deliberate design decision rather than a leak, which is why this technique has kept working for fifteen years.

Read the failures. A run measured in July 2026 checked 74 sources, confirmed 19 accounts and found 60 breach records, and 15 of those sources never answered at all. A source that failed is unknown, not negative, and Instagram now refuses everybody.

Written by the DetectiveCheck team

We build the lookup engine this site runs on, so the numbers in these guides are the ones our own reports use: 71 sources against an email address, 71 platforms against a username, 13 registers against a name, and 8 against a phone number. Where a module is thin, we say so rather than round it up.

Run one yourself

Create an account and the first report is a couple of minutes away. Nobody you look up is told.

Create my account

Plans from $15 a month. Cancel in one click. Or read a sample report first.

Try it on something you already have