End-to-end automation of email intelligence in OSINT workflows: Architecture and implementation


Aydemir B., Malkawi M., ALHAJJ R.

Array, cilt.30, 2026 (ESCI, Scopus)

  • Yayın Türü: Makale / Tam Makale
  • Cilt numarası: 30
  • Basım Tarihi: 2026
  • Doi Numarası: 10.1016/j.array.2026.100841
  • Dergi Adı: Array
  • Derginin Tarandığı İndeksler: Emerging Sources Citation Index (ESCI), Scopus, Compendex, Directory of Open Access Journals
  • Anahtar Kelimeler: Automation, Cybersecurity, OSINT, Threat intelligence, Web scraping
  • İstanbul Medipol Üniversitesi Adresli: Evet

Özet

Open Source Intelligence (OSINT) has become increasingly important in cybersecurity, digital risk assessment, and investigative research due to the growing volume of publicly available information. Traditional OSINT tools often operate in silos, focusing on narrow tasks such as domain lookup or metadata extraction, which limits their effectiveness in providing comprehensive intelligence. Meanwhile, manual workflows remain time-consuming and prone to errors in large-scale or time-sensitive scenarios. To address these challenges, this paper presents a fully automated framework for email-focused OSINT explicitly scoped at the domain level rather than individual mailbox verification. The system integrates asynchronous web scraping, DNS and WHOIS queries, MX record checks for domain-level mail infrastructure validation, and the analysis of email authentication protocols including SPF, DKIM, and DMARC. Unlike conventional approaches, the proposed pipeline incorporates a validation mechanism that combines real-time harvesting with domain-level checks, avoiding assumptions about individual email address existence and thereby improving infrastructure-level reliability while reducing noise from duplicate, role-based, or inactive addresses. Experimental evaluations conducted on 17 domains spanning academic, governmental, corporate, startup, and privacy-focused providers demonstrate that the framework achieves approximately a 90% infrastructure-level validation rate, while maintaining consistent performance and competitive execution times compared to existing OSINT workflows. These results highlight the potential of the system to support cybersecurity operations, digital forensics, and threat intelligence by enabling scalable, ethical, and autonomous reconnaissance of email-related intelligence at the domain infrastructure level without relying on intrusive verification techniques.