Reliable public-source intelligence

Investigate any digital footprint
with MyRecon

Search usernames across a wide range of platforms, analyze emails and breach exposure, and investigate domains, DNS, and IP addresses — all from accurate, public data sources.

Broad platform coverage Breach detection Password exposure WHOIS · DNS · IP No server-side storage
Run a lookup

Saved investigations

Pin the searches you want to keep. Stored privately in your browser.

Search history

Recent lookups, stored privately in your browser.

Built for accurate investigations

Every tool draws from documented, reliable sources — no scraping guesswork, no fabricated results.

Username search

Check a handle across social, developer, and community platforms with per-platform validation to cut false positives, then enrich matches with avatars and bios.

Email intelligence

Provider and deliverability analysis, disposable detection, Gravatar and linked accounts, plus breach exposure from public breach databases.

Domain & WHOIS

Registration lifecycle, registrar, DNSSEC, and nameservers via RDAP — the standardized successor to WHOIS.

DNS records

A, AAAA, MX, NS, TXT, CNAME, SOA, and CAA resolved over DNS-over-HTTPS for accuracy and privacy.

IP & geolocation

Geolocation, ISP/ASN ownership, hosting and proxy flags, and reverse DNS resolution.

Password exposure

Check a password against 900M+ credentials recovered from breach dumps. It is hashed in your browser and only the first five characters of the hash are ever sent — the password itself never leaves your device.

Export & history

Export any result as JSON or CSV and revisit recent investigations — kept privately in your browser.

Now on Android

The same investigation, run from your own phone — where platforms answer far more readily than they answer a server.

MyRecon for Android checks a username across a wide range of platforms directly from your handset, watches for newly published data breaches without ever sending your address anywhere, reads the metadata still buried in a photo, and shows you where a QR code actually leads before you open it.

  • No account, no signup. Nothing to create, nothing to remember.
  • Every result is verified. A site answering “200 OK” is not treated as proof an account exists — and anything unconfirmed says so instead of padding the total.
  • Photos and passwords never leave the phone. Metadata is read on-device; a password is hashed before anything is sent.

Get it on Google Play What it does

How MyRecon works

MyRecon turns a single starting point — a username, email, domain, or IP address — into a structured picture of a public online footprint. It queries documented, reliable sources and verifies each result before showing it, so you spend time on real leads instead of noise.

1

Enter a target

Pick a tool and enter what you already know: a handle, an email address, a domain name, or an IP. No account, no sign-up, and nothing about your search is stored on our servers.

2

We gather and verify

MyRecon checks the target against public sources — platform profile pages, breach databases, RDAP/WHOIS registries, DNS-over-HTTPS resolvers, and IP geolocation providers — and scores each finding for confidence so false positives are filtered out.

3

Investigate and pivot

Results arrive as clean cards you can open, export as JSON or CSV, and pivot from: a discovered domain, email, or handle becomes a one-click next lookup, so an investigation flows naturally from one lead to the next.

Read the archive

Alongside the tools, MyRecon publishes a written record of how personal data actually gets exposed: a daily breach archive, long-form case files on the incidents that changed the rules, and practical guides to reducing your own exposure.

Case Files

Long-form accounts of the landmark breaches — Equifax's unpatched web form, the contractor's password that stopped a pipeline, the API that had no lock on it. What happened, how, what it cost, and what it changed. Sourced from regulatory findings, court records and company disclosures.

Browse the case files →

The Breach Files

Every breach worth understanding as it is confirmed: who was hit, what was taken, how many people it reached, and what each exposed field means for the person it belongs to. Updated daily, with our own severity scoring and analysis on every entry.

Open the breach archive →

Guides

How the underlying systems work and what to do about them — checking an address against known breaches, reading DNS and WHOIS records, spotting phishing, shrinking a public footprint, and verifying an OSINT finding before acting on it.

Read the guides →

Who uses MyRecon

Open-source intelligence is useful far beyond security teams. MyRecon is built for anyone who needs to understand what public data says about a person, brand, or piece of infrastructure.

Protect your own footprint

Search your own username and email to see which platforms and breaches expose your data, then lock down or remove what you no longer use. A quick self-audit is the fastest way to understand your exposure.

Security researchers

Enumerate a target's public profiles, map a domain's DNS and hosting, and correlate identities across platforms during authorized assessments and responsible-disclosure work.

Recruiters & verification

Confirm that a candidate's professional profiles and portfolio links are consistent, and check that a company domain's registration and mail setup look legitimate.

Fraud & trust teams

Check whether an email is disposable, whether a domain was registered recently, and whether an IP belongs to a hosting provider or proxy — useful signals when assessing risk.

Journalists & OSINT

Build a verifiable picture from public records: who registered a domain, where a server is hosted, and which accounts share a handle — all with sources you can cite.

Developers & sysadmins

Inspect DNS records, mail configuration, nameservers, and reverse DNS quickly during setup and debugging, without stitching together half a dozen command-line tools.

Frequently asked questions

Is MyRecon legal to use?

MyRecon only aggregates information that is already publicly available, which is legal in most jurisdictions. What matters is how you use it. MyRecon is intended for lawful purposes such as reviewing your own footprint, authorized security research, verification, and journalism. Using it to harass, stalk, or harm someone, or to violate a platform's terms of service, is prohibited — see our Terms of Use.

Do you store my searches?

No. MyRecon does not require an account and does not save your search queries or results to a database. Your recent-lookup history lives only in your browser's local storage and never leaves your device. Results may be held briefly in an in-memory cache to speed up repeated lookups, then expire automatically.

How accurate are the results?

MyRecon deliberately favours reliable, documented sources — RDAP for registration data, DNS-over-HTTPS for records, official APIs for breach and profile data — and verifies username matches with confidence scoring rather than assuming a profile exists just because a page loads. No tool that relies on public data can be perfect, so matches are labelled by confidence and you should always confirm anything important.

What is the difference between the WHOIS and DNS tools?

WHOIS/RDAP tells you about a domain's registration — who registered it, when, the registrar, and its expiry. DNS tells you how the domain currently resolves — its A, MX, TXT, NS, and other records. The Domain tool combines both plus the resolved server's geolocation; the DNS tool focuses purely on records. Our guidesDeep Search explain each in depth.

Is it safe to type a password into the password checker?

Yes, and you don't have to take our word for it. Your password is hashed with SHA-1 inside your browser, and only the first five characters of that hash are sent to the Pwned Passwords service — a technique called k-anonymity. That prefix is shared by many thousands of different passwords, so it identifies nothing. The matching is done locally on the list that comes back. Your password never reaches MyRecon's servers, is never written to your browser storage, and is never placed in a URL. We also ask the service to pad its response so its size gives nothing away.

Does MyRecon search the dark web?

Honestly: not in the way that phrase is usually sold. Nobody can crawl dark web marketplaces live for free, and services that genuinely infiltrate criminal forums charge thousands per month. What MyRecon does is check your email and passwords against the breach corpora — the credential dumps that were traded on those forums and have since been published and catalogued. That is the same underlying data most consumer "dark web monitoring" products actually check, and every source we use is documented and free.

Is MyRecon free?

Yes. All of the core lookups — username, email, password exposure, domain, DNS, and IP — are free to use with no account. The service is supported by non-intrusive advertising and is rate-limited to keep it fast and available for everyone.

Can I remove my information from MyRecon?

MyRecon doesn't host a database of people — it queries public sources live at the moment you search. To reduce what appears, you need to reduce your public footprint at the source: delete unused accounts, tighten privacy settings, and change passwords exposed in breaches. Our guide on reducing your digital footprint walks through exactly how.