PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 26, 2026Array0 citationsOpen Access

End-to-end automation of email intelligence in OSINT workflows: Architecture and implementation

View Full Paper
BABengisu AydemirMMMalek MalkawiRAReda Alhajj

Key Points

  • The aim is to develop a comprehensive automated framework for email-focused OSINT to enhance data validation and reduce manual errors.
  • Implemented an end-to-end automated pipeline integrating asynchronous web scraping, DNS and WHOIS queries, and email authentication analysis.
  • Conducted experimental evaluations on 17 domains across various sectors to assess validation performance and execution time.
  • Employed a two-stage validation mechanism combining real-time data harvesting with MX record lookups for domain-level checks.
  • Achieved approximately 90% infrastructure-level validation rate across domains evaluated.
  • Demonstrated consistent performance and competitive execution times compared to traditional OSINT workflows.
  • Improved intelligence quality and reduced noise from inactive or role-based email addresses.

Abstract

Open Source Intelligence (OSINT) has become increasingly important in cybersecurity, digital risk assessment, and investigative research due to the growing volume of publicly available information. Traditional OSINT tools often operate in silos, focusing on narrow tasks such as domain lookup or metadata extraction, which limits their effectiveness in providing comprehensive intelligence. Meanwhile, manual workflows remain time-consuming and prone to errors in large-scale or time-sensitive scenarios. To address these challenges, this paper presents a fully automated framework for email-focused OSINT explicitly scoped at the domain level rather than individual mailbox verification. The system integrates asynchronous web scraping, DNS and WHOIS queries, MX record checks for domain-level mail infrastructure validation, and the analysis of email authentication protocols including SPF, DKIM, and DMARC. Unlike conventional approaches, the proposed pipeline incorporates a validation mechanism that combines real-time harvesting with domain-level checks, avoiding assumptions about individual email address existence and thereby improving infrastructure-level reliability while reducing noise from duplicate, role-based, or inactive addresses. Experimental evaluations conducted on 17 domains spanning academic, governmental, corporate, startup, and privacy-focused providers demonstrate that the framework achieves approximately a 90% infrastructure-level validation rate, while maintaining consistent performance and competitive execution times compared to existing OSINT workflows. These results highlight the potential of the system to support cybersecurity operations, digital forensics, and threat intelligence by enabling scalable, ethical, and autonomous reconnaissance of email-related intelligence at the domain infrastructure level without relying on intrusive verification techniques. • A fully automated pipeline is proposed for email-focused OSINT; this involves integrating multiple passive reconnaissance techniques, including web scraping, DNS and WHOIS queries, MX record validation, and the analysis of email authentication protocols such as SPF, DKIM, and DMARC. The pipeline enables end-to-end intelligence extraction without requiring interactive user input. • This study introduces a harvesting-based approach supported by context-aware HTML scraping and a two-stage validation mechanism, namely, (i) real-time data verification of the discovered addresses, and (ii) MX record lookups for domain-level validation. The approach performs concurrent validation during data acquisition, reducing reliance on third-party APIs and enabling real-time processing. These mechanisms improve domain-level validation reliability, reduce noise, and enable effective correlation between metadata, infrastructure, and web presence. • The system has been implemented using a modular and extensible architecture. This enables seamless integration of additional analysis modules and at the same time minimizes manual effort and mitigates common sources of human error inherent in traditional OSINT workflows. • The proposed framework contributes to multiple application domains, including cybersecurity, threat intelligence, investigative journalism, and digital risk monitoring, by enabling reliable and scalable discovery of email-related intelligence from public sources. • The effectiveness of the proposed system has been demonstrated through experimental evaluations by measuring domain-level validation performance, execution time, and data consistency across various operational scenarios, indicating system improvements in efficiency and intelligence quality.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Aydemir et al. (2026) studied this question.

synapsesocial.com/papers/69edab814a46254e215b3757https://doi.org/10.1016/j.array.2026.100841
Ask AI
Helpful
Bookmark
Share
View Full Paper