Multiple usernames
Check several handles in one run, or limit the run to chosen sites.
Sherlock OSINT searches are often the first thing an investigator runs on a new username: one command, a few hundred sites, a list of profile URLs. It is free, open source and deliberately simple, which is both its strength and the source of most mistakes made with it.
The Sherlock OSINT tool is a free, open-source command-line program that checks whether a username exists on 400+ social networks and websites. It is written in Python, released under the MIT license and maintained by the Sherlock Project on GitHub. It suits investigators and researchers comfortable with a terminal. There is no paid tier and no official web version.
It takes one or more usernames, requests each site's profile URL, and reports which ones appear to exist. It does not read or analyze the profiles.
The project describes Sherlock as a tool to "hunt down social media accounts by username across social networks" (GitHub repository). You give it a handle; it returns a list of URLs where an account seems to exist, saved by default to a text file per username. No names, photos or bios are extracted, and no judgment is made about who owns the accounts.
The repository is one of the most followed OSINT projects on GitHub, with about 90,800 stars and 2,922 commits on 10 October 2026. The latest version, 0.16.2, was published to PyPI on 10 September 2026, a year after 0.16.0 (PyPI). This review is based on the repository, source code and documentation as published on that date.
A small feature set aimed at fast, scriptable checks rather than analysis.
Check several handles in one run, or limit the run to chosen sites.
A text file per username by default, with spreadsheet exports for review and record-keeping.
Route requests through a proxy and set timeouts for slow sites.
Loads the current site list from the project by default, or a local file you control.
Sites flagged NSFW are skipped unless you opt in.
Official install routes, plus community packages for several Linux distributions and Homebrew.
Each site uses one of three tests: the HTTP status code, an error message in the page, or a redirect to another URL. Most use the status code.
| Method | Sites (of 481) | How it works | Typical failure |
|---|---|---|---|
| Status code | 327 | A missing profile returns an error code such as 404 | Sites that answer 200 for every name, or block the request, give false hits or misses |
| Error message | 127 | A known "not found" text appears when the profile is missing | A redesign changes the text and the check silently breaks |
| Response URL | 27 | A missing profile redirects somewhere else | Login or consent redirects look like "not found" |
Counts are from the project's site data file on 10 October 2026 (data.json). The source code also recognizes some Cloudflare and AWS challenge pages and reports them as blocked rather than found; a comment there notes that web application firewalls "will occasionally block Sherlock and lead to false positives and negatives" (sherlock.py).
The project says 400+. The data file held 481 entries on 10 October 2026, and the number moves as sites break and are removed.
The project site and repository both say "400+" (sherlockproject.xyz). The working figure changes because maintainers remove sites that Sherlock can no longer test reliably. A dedicated list records those removals and the reason for each, for example a site that began reporting every username as available, or one that redirected every query to a general page (removed sites). Sherlock also applies an upstream exclusion list by default; an option to ignore it is documented as one that "may return more false positives".
A larger count is not automatically better: every extra site is another check that can drift out of date.
Free under the MIT license. The project offers no paid plan, hosted service or bot.
| Option | Cost | Notes |
|---|---|---|
| pipx, pip or uv install | Free | Python 3.9 or later; package name sherlock-project (PyPI) |
| Official Docker image | Free | Runs without a local Python setup |
| Distribution packages | Free | Debian, Ubuntu, Homebrew, Kali and BlackArch packages are community-maintained; the README warns some are broken |
| "Sherlock online" sites and bots | Varies | Not listed by the project; treat them as unrelated third-party services |
Checked 10 October 2026 on the repository. Searches for "Sherlock OSINT online" or a Sherlock Telegram bot lead to services the project does not list. Typing a subject's username into an unknown website or bot discloses your investigation to whoever runs it.
Sherlock is the minimal checker. Maigret goes deeper, WhatsMyName is a shared dataset, and Blackbird adds email checks on top of WhatsMyName.
| Tool | What it is | Site list | Beyond found or not found | License |
|---|---|---|---|---|
| Sherlock | Command-line checker | Own list, 481 entries | Little: URLs and exports | MIT |
| Maigret | Checker, web UI and Python library | Own database, 5,203 enabled sites in version 0.6.6 | Profile parsing, recursive search, reports | MIT |
| WhatsMyName | Dataset plus a free web app | 717 entries, community-maintained | Depends on the tool that reads it | CC BY-SA 4.0 |
| Blackbird | Command-line checker | WhatsMyName data plus 16 email checks | Email lookup, PDF report, AI summary | No license file shown |
Figures are from each project's repository on 10 October 2026; see the individual reviews for sources. For other categories of tools, see our OSINT tools guide.
Sherlock reports that a URL responds like a profile. Whether that profile belongs to your subject is a separate question it cannot answer.
Popular handles exist on most large sites, owned by different people. Sherlock lists them all with equal confidence.
A site that changes its error page or starts answering every request with a 200 code turns into a source of false hits until the entry is fixed.
Sherlock checks the handle you type. Variants with dots, underscores or numbers need separate runs.
Use Sherlock for a defined, lawful purpose, keep only what that purpose needs, and never use it to track or harass a private person.
A Sherlock result tied to a named individual is personal data. Organizations subject to the GDPR need a lawful basis and must limit collection to what the purpose requires (GDPR); the fact that profiles are public does not remove that protection (joint statement on data scraping). Results from dating or adult sites can reveal special category data and should be left out unless strictly necessary.
Reasonable uses include checking your own or your company's handles for impersonation, research on public figures' public accounts, and leads in a lawful investigation that a human then verifies. Locating or monitoring a private person without a lawful purpose is not one of them.
Technical users who want a quick, free, scriptable first pass and will verify every hit themselves.
Good fit: analysts comfortable in a terminal, security teams scripting handle checks for staff and brands, and researchers who want every check visible in a public file.
Poor fit: anyone who needs profile content, identity confirmation or a report fit for a client, court or HR decision; anyone uncomfortable installing Python tools; and anyone tempted to treat a list of URLs as proof.
When a username matters to a legal, HR or fraud decision, the work is confirming or rejecting each match and documenting why.
Our username investigations start where Sherlock stops: each candidate account is tested against independent signals and graded, and rejected matches are recorded so nobody acts on them later. Confirmed accounts can feed wider social media investigations or anonymous account attribution. Work is quoted at a fixed price after written scoping, and a senior analyst reviews every report. See our full range of OSINT services for companies and law firms.
Send us the username and what you need to decide. We reply with a scope, a fixed quote and a delivery date.
Sherlock checks whether a username exists on 400+ websites and lists the matching profile URLs. It is free, open source under the MIT license and installed from PyPI or Docker (repository). Install it only from those official routes, ideally in an isolated environment, and check your employer's policy first: it sends hundreds of requests to third-party sites from your network.
The project does not list an official website version or bot; its repository and site describe a command-line tool installed with pipx, pip, uv or Docker. Sites and bots using the Sherlock name are third-party services. Before typing a subject's username into one, consider that the operator can log your searches, and that you have no assurance about how results are produced.
Because Sherlock only tests whether a profile URL responds like an existing account. Most of its 481 checks rely on HTTP status codes, and common handles exist on many sites under different owners. Open every hit, compare photos, bios, links, locations and activity dates, and keep only accounts with several independent signals pointing to the same person. Treat the rest as unconfirmed.
Sherlock's data file held 481 entries on 10 October 2026, and the project advertises 400+ (data.json). Larger databases, such as Maigret's, cover more niche sites and may find more, but every extra check is another that can break and return false hits. More coverage means more verification work, not more certainty.
Not on its own. Sherlock output shows that profile URLs responded at a point in time; it says nothing about who controls the accounts. Courts typically expect evidence of attribution and a record of how the material was captured and preserved. Use the output as leads, then verify, capture and document each relevant account properly, or instruct an investigator to do so.
Running it on the handle of an account abusing you is generally a reasonable, proportionate step, provided you use the results only to protect yourself, for example to report the accounts or support a complaint. Do not confront, expose or harass the person you suspect. If the abuse is serious, preserve the evidence and involve the platform, the police or a lawyer, who can obtain account records through legal process.
Sources checked 10 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.