Subdomains and hosts
Combines certificate logs, passive DNS and scan datasets to list hostnames and IP addresses tied to a domain.
theHarvester OSINT tool is a free, open-source program that collects email addresses, subdomains, hosts and names linked to a domain from search engines, certificate logs, DNS datasets and threat-intelligence APIs. This review is based on the official GitHub repository, its documentation and the Kali Linux package page, checked on 10 October 2026.
theHarvester OSINT tool is a Python command-line program for the first stage of an authorized security assessment: it maps the email addresses, subdomains, hosts and IP addresses an organization exposes publicly. It suits penetration testers, red teams and defenders checking their own attack surface. The tool is free under GPL-2.0, but many of its best sources need paid or free-tier API keys.
An open-source reconnaissance tool that takes a domain or organization name and returns the emails, subdomains, hosts and names it finds in public sources.
The project describes itself as an "E-mails, subdomains and names Harvester" and says it gathers open-source intelligence about a domain or organization from search engines, certificate transparency logs, DNS datasets, code repositories and threat-intelligence platforms (GitHub). It was created by Christian Martorella and is maintained today by Matt Brown and Jay Townsend, with Lee Baird listed as a main contributor.
The README is explicit about purpose: use the tool "during the early reconnaissance stage of an authorized security assessment" and run it "only against targets you own or have explicit permission to test." That framing matters. theHarvester is built for mapping an organization's external footprint before a penetration test or for a defender's own audit, not for profiling individuals.
It is also one of the most widely used tools in its niche: the repository shows about 17,300 stars, and the tool ships in Kali Linux's default metapackage (Kali Tools).
Most of its 59 discovery sources are passive lookups in third-party datasets; a smaller set of DNS, HTTP and screenshot actions touch the target directly and must be selected on purpose.
The README lists 59 discovery sources. Of the 54 passive ones, 22 work without an API key, three take an optional key and 29 require one (GitHub). Keys are stored in an api-keys.yaml file.
| Source group | Examples named in the README | Key needed? |
|---|---|---|
| Certificate transparency and passive DNS | crtsh, certspotter, rapiddns, robtex, urlscan | No |
| Search engines and archives | duckduckgo, yahoo, baidu, commoncrawl, waybackarchive | Mostly no; brave and mojeek take keys |
| Internet scan data | censys, fofa, zoomeye, netlas, onyphe, leakix | Yes |
| Email and people data | hunter, tomba, rocketreach | Yes |
| Breach and leak data | haveibeenpwned, dehashed, intelx, leaklookup | Mixed |
| Code and threat intelligence | github-code, gitlab, sourcegraph, otx, virustotal, securityTrails | Mixed |
Beyond passive lookups, theHarvester can resolve and brute-force DNS names, run reverse and recursive DNS, take screenshots through a Playwright browser, check for possible subdomain takeovers, scan API paths and run HTTP, TLS, port and virtual-host actions. These steps send traffic to the target's infrastructure. The README notes that a takeover indicator is evidence for review, not proof that a resource can be claimed.
A scriptable command line, a local web app with a REST API, structured output and a large source catalog.
Combines certificate logs, passive DNS and scan datasets to list hostnames and IP addresses tied to a domain.
Surfaces email addresses and employee names that appear in public sources and email-finder APIs.
A local web interface and REST API on 127.0.0.1 with key authentication, run history, scheduling and Swagger docs.
JSONL is the main format for automation; completed runs are stored in a local SQLite database that can be exported.
Installs from source with uv (the README targets Python 3.14), runs in Docker Compose bound to localhost, or comes packaged in Kali.
DNS brute force, screenshots, takeover and API-path checks run only when you select them.
The software is free under GPL-2.0 and actively maintained; the real cost is the API keys for the commercial data sources you choose to enable.
| Item | Detail (checked 10 October 2026) |
|---|---|
| Software price | Free |
| License | GNU GPL version 2 (LICENSE) |
| Language | Python |
| Latest release | 4.11.1, 3 June 2026; previous releases 23 May 2026 and 22 February 2026 (Releases) |
| Kali package | 4.11.1, in the default metapackage (Kali) |
| Optional data costs | Set by each provider. Examples: Shodan sells a $49 one-time membership and plans from $69 a month (Shodan); Censys gives free users 100 credits a month (Censys) |
With only the keyless sources, theHarvester still returns useful certificate and passive DNS results. Coverage of email addresses and scan data improves noticeably once paid keys are added, so budget for the providers that matter to your use case.
It suits technical users who need a fast first map of a domain's footprint; it does not suit investigators who need verified findings about people or a court-ready report.
Expect stale and third-party records, treat active checks as testing that needs permission, and handle harvested emails and names as personal data.
Recon-ng and SpiderFoot are the closest open-source alternatives; Shodan and Censys add internet scan data; Maltego adds visual link analysis.
| Tool | How it differs | Price model |
|---|---|---|
| Recon-ng | Modular framework with workspaces and a database that chains results between modules | Free, open source |
| SpiderFoot | Automation tool with over 200 modules and a web interface | Free, open source (MIT) |
| Shodan and Censys | Search engines for internet-scan data on hosts, ports and certificates | Free tiers, paid plans |
| Maltego | Graph-based link analysis across many data sources | Free and paid plans |
For a broader catalog grouped by investigation task, see our guide to OSINT tools.
If you need a verified picture of your organization's external exposure rather than a raw list of hostnames, an analyst-led assessment is often faster.
theHarvester output is a starting point. Turning it into decisions means confirming which assets are yours, which emails belong to current staff, what an attacker could do with them and what to fix first. Our red team OSINT reconnaissance and organizational OSINT exposure audit deliver that as a scoped, authorized engagement with senior analyst review before reporting. Focused work usually starts from 10 business days after written scoping, at a fixed quote.
If you are comparing providers more widely, start with an overview of OSINT services for security teams.
Tell us which domains and brands are in scope and who authorized the work. We map what you expose and tell you what to fix first.
It finds email addresses, subdomains, hostnames, IP addresses and some employee names linked to a domain, drawn from certificate logs, passive DNS, search engines and threat-intelligence APIs. You can start with no paid accounts: 22 of its passive sources need no API key. Results improve once you add keys for commercial sources such as Censys, Hunter or SecurityTrails, priced by each provider. The tool itself is free under GPL-2.0 (GitHub).
It is in Kali's default metapackage, and on 10 October 2026 the Kali package was version 4.11.1, the same as the latest GitHub release from 3 June 2026 (Kali Tools). Packaged versions can lag behind, so if you need a source added after the last release, install from the repository with uv as the README describes. Either way, practice only on domains you own or lab targets your course provides.
Running passive lookups against your own domain is generally fine, and the README itself says to use the tool only against targets you own or have explicit permission to test. Be careful with active options such as DNS brute force, port and API-path checks: if your domain sits on cloud or hosting services you do not control, get the provider's rules and your internal sign-off first. Treat harvested employee emails as personal data and keep them only as long as the audit needs.
Most are not false positives so much as historical records. Certificate transparency logs and passive DNS keep names that were retired long ago, so a large share may no longer resolve. Run the DNS resolution option, drop names that do not resolve, check which IP ranges belong to your client rather than a CDN or shared host, and confirm anything important manually. Present the remaining assets with the source and the date you checked them.
They overlap and are often used together. theHarvester is the quickest for a first list of emails, subdomains and hosts. Recon-ng adds workspaces and a database so one module's output feeds the next. SpiderFoot automates scanning with over 200 modules and a web interface. Many teams run theHarvester for fast discovery, then enrich and correlate in another tool. All three are free; the shared cost is the API keys for commercial data sources.
Sources checked 10 October 2026. This review is based on official documentation, repositories and pricing pages; OSINT-S has not run the tool for this review and has no affiliation with the project or any data provider.