theHarvester OSINT Tool Review: Emails, Subdomains and Hosts

theHarvester OSINT tool is a free, open-source program that collects email addresses, subdomains, hosts and names linked to a domain from search engines, certificate logs, DNS datasets and threat-intelligence APIs. This review is based on the official GitHub repository, its documentation and the Kali Linux package page, checked on 10 October 2026.

  • Free, GPL-2.0 license
  • Python command line plus local web app
  • 59 discovery sources
  • For authorized assessments only

Not tested by OSINT-S. Based on vendor documentation, the repository and package pages. No affiliation with the project.

Short answer

theHarvester OSINT tool is a Python command-line program for the first stage of an authorized security assessment: it maps the email addresses, subdomains, hosts and IP addresses an organization exposes publicly. It suits penetration testers, red teams and defenders checking their own attack surface. The tool is free under GPL-2.0, but many of its best sources need paid or free-tier API keys.

What Is theHarvester?

An open-source reconnaissance tool that takes a domain or organization name and returns the emails, subdomains, hosts and names it finds in public sources.

The project describes itself as an "E-mails, subdomains and names Harvester" and says it gathers open-source intelligence about a domain or organization from search engines, certificate transparency logs, DNS datasets, code repositories and threat-intelligence platforms (GitHub). It was created by Christian Martorella and is maintained today by Matt Brown and Jay Townsend, with Lee Baird listed as a main contributor.

The README is explicit about purpose: use the tool "during the early reconnaissance stage of an authorized security assessment" and run it "only against targets you own or have explicit permission to test." That framing matters. theHarvester is built for mapping an organization's external footprint before a penetration test or for a defender's own audit, not for profiling individuals.

It is also one of the most widely used tools in its niche: the repository shows about 17,300 stars, and the tool ships in Kali Linux's default metapackage (Kali Tools).

How theHarvester Collects OSINT: Passive Sources and Active Modules

Most of its 59 discovery sources are passive lookups in third-party datasets; a smaller set of DNS, HTTP and screenshot actions touch the target directly and must be selected on purpose.

The README lists 59 discovery sources. Of the 54 passive ones, 22 work without an API key, three take an optional key and 29 require one (GitHub). Keys are stored in an api-keys.yaml file.

Source groupExamples named in the READMEKey needed?
Certificate transparency and passive DNScrtsh, certspotter, rapiddns, robtex, urlscanNo
Search engines and archivesduckduckgo, yahoo, baidu, commoncrawl, waybackarchiveMostly no; brave and mojeek take keys
Internet scan datacensys, fofa, zoomeye, netlas, onyphe, leakixYes
Email and people datahunter, tomba, rocketreachYes
Breach and leak datahaveibeenpwned, dehashed, intelx, leaklookupMixed
Code and threat intelligencegithub-code, gitlab, sourcegraph, otx, virustotal, securityTrailsMixed

Beyond passive lookups, theHarvester can resolve and brute-force DNS names, run reverse and recursive DNS, take screenshots through a Playwright browser, check for possible subdomain takeovers, scan API paths and run HTTP, TLS, port and virtual-host actions. These steps send traffic to the target's infrastructure. The README notes that a takeover indicator is evidence for review, not proof that a resource can be claimed.

Key Features for Emails, Subdomains and Hosts

A scriptable command line, a local web app with a REST API, structured output and a large source catalog.

Discovery

Subdomains and hosts

Combines certificate logs, passive DNS and scan datasets to list hostnames and IP addresses tied to a domain.

People

Emails and names

Surfaces email addresses and employee names that appear in public sources and email-finder APIs.

Interface

HarvestView web app

A local web interface and REST API on 127.0.0.1 with key authentication, run history, scheduling and Swagger docs.

Output

JSONL, JSON, XML, SQLite

JSONL is the main format for automation; completed runs are stored in a local SQLite database that can be exported.

Deploy

uv, Docker, Kali

Installs from source with uv (the README targets Python 3.14), runs in Docker Compose bound to localhost, or comes packaged in Kali.

Active

Opt-in active checks

DNS brute force, screenshots, takeover and API-path checks run only when you select them.

Is theHarvester Free? Pricing, License and Maintenance

The software is free under GPL-2.0 and actively maintained; the real cost is the API keys for the commercial data sources you choose to enable.

ItemDetail (checked 10 October 2026)
Software priceFree
LicenseGNU GPL version 2 (LICENSE)
LanguagePython
Latest release4.11.1, 3 June 2026; previous releases 23 May 2026 and 22 February 2026 (Releases)
Kali package4.11.1, in the default metapackage (Kali)
Optional data costsSet by each provider. Examples: Shodan sells a $49 one-time membership and plans from $69 a month (Shodan); Censys gives free users 100 credits a month (Censys)

With only the keyless sources, theHarvester still returns useful certificate and passive DNS results. Coverage of email addresses and scan data improves noticeably once paid keys are added, so budget for the providers that matter to your use case.

Who It Suits and Who It Does Not

It suits technical users who need a fast first map of a domain's footprint; it does not suit investigators who need verified findings about people or a court-ready report.

  • Good fit: penetration testers and red teams at the start of a scoped engagement; security teams auditing their own subdomains and exposed hosts; bug bounty hunters working inside a program's published scope; trainers teaching reconnaissance.
  • Poor fit: people searches, background checks or due diligence on individuals; anyone who is not comfortable with a command line and API key management; teams that need findings explained, verified and written up for a non-technical audience.

Limits, Accuracy and Authorized Use of theHarvester OSINT Results

Expect stale and third-party records, treat active checks as testing that needs permission, and handle harvested emails and names as personal data.

  • Accuracy. Certificate logs and passive DNS keep historical names, so many subdomains no longer resolve. Search-engine results change and some sources rate-limit or block automated queries. Every result needs verification before it goes in a report.
  • Active steps need authorization. DNS brute force, port, TLS and API-path checks interact with systems you may not own. Running them without permission can breach provider terms and, depending on what you do, computer misuse laws such as the US Computer Fraud and Abuse Act. Keep a written scope and rules of engagement, as you would for any OSINT penetration test.
  • Personal data. Employee names and email addresses are personal data under the GDPR and similar laws. Collect only what the assessment needs, store it securely and delete it when the engagement ends.
  • Critical infrastructure. Operators of energy, water and transport systems should run reconnaissance against their own estate only through approved channels; we cover that context on our critical infrastructure page.
  • Exposed service. The README advises keeping the HarvestView API on localhost unless you add TLS and network access controls.

theHarvester Alternatives for OSINT Reconnaissance

Recon-ng and SpiderFoot are the closest open-source alternatives; Shodan and Censys add internet scan data; Maltego adds visual link analysis.

ToolHow it differsPrice model
Recon-ngModular framework with workspaces and a database that chains results between modulesFree, open source
SpiderFootAutomation tool with over 200 modules and a web interfaceFree, open source (MIT)
Shodan and CensysSearch engines for internet-scan data on hosts, ports and certificatesFree tiers, paid plans
MaltegoGraph-based link analysis across many data sourcesFree and paid plans

For a broader catalog grouped by investigation task, see our guide to OSINT tools.

Need the Answer, Not the Tool?

If you need a verified picture of your organization's external exposure rather than a raw list of hostnames, an analyst-led assessment is often faster.

theHarvester output is a starting point. Turning it into decisions means confirming which assets are yours, which emails belong to current staff, what an attacker could do with them and what to fix first. Our red team OSINT reconnaissance and organizational OSINT exposure audit deliver that as a scoped, authorized engagement with senior analyst review before reporting. Focused work usually starts from 10 business days after written scoping, at a fixed quote.

If you are comparing providers more widely, start with an overview of OSINT services for security teams.

Get a Scoped External Exposure Review

Tell us which domains and brands are in scope and who authorized the work. We map what you expose and tell you what to fix first.

theHarvester OSINT FAQ

I keep seeing theHarvester OSINT tool recommended for email and subdomain discovery — what exactly does it find for a domain, and do I need any paid accounts to get useful results?

It finds email addresses, subdomains, hostnames, IP addresses and some employee names linked to a domain, drawn from certificate logs, passive DNS, search engines and threat-intelligence APIs. You can start with no paid accounts: 22 of its passive sources need no API key. Results improve once you add keys for commercial sources such as Censys, Hunter or SecurityTrails, priced by each provider. The tool itself is free under GPL-2.0 (GitHub).

I'm running Kali Linux for a penetration testing course — is theHarvester already installed there, or should I install the GitHub version instead to get the newest sources?

It is in Kali's default metapackage, and on 10 October 2026 the Kali package was version 4.11.1, the same as the latest GitHub release from 3 June 2026 (Kali Tools). Packaged versions can lag behind, so if you need a source added after the last release, install from the repository with uv as the README describes. Either way, practice only on domains you own or lab targets your course provides.

Our security team wants to see what our own company exposes online before attackers do — is it legal for us to point theHarvester at our domain, and what should we avoid?

Running passive lookups against your own domain is generally fine, and the README itself says to use the tool only against targets you own or have explicit permission to test. Be careful with active options such as DNS brute force, port and API-path checks: if your domain sits on cloud or hosting services you do not control, get the provider's rules and your internal sign-off first. Treat harvested employee emails as personal data and keep them only as long as the audit needs.

I ran theHarvester against a client domain and got hundreds of subdomains, but many don't resolve — are these false positives, and how should I clean the results before reporting?

Most are not false positives so much as historical records. Certificate transparency logs and passive DNS keep names that were retired long ago, so a large share may no longer resolve. Run the DNS resolution option, drop names that do not resolve, check which IP ranges belong to your client rather than a CDN or shared host, and confirm anything important manually. Present the remaining assets with the source and the date you checked them.

We're choosing between theHarvester, Recon-ng and SpiderFoot for our internal red team — which one makes sense if we want automation, and can they be used together?

They overlap and are often used together. theHarvester is the quickest for a first list of emails, subdomains and hosts. Recon-ng adds workspaces and a database so one module's output feeds the next. SpiderFoot automates scanning with over 200 modules and a web interface. Many teams run theHarvester for fast discovery, then enrich and correlate in another tool. All three are free; the shared cost is the API keys for commercial data sources.