Method · Sources used
What Detrace looks at.
Detrace only touches public, open-source intelligence — no scraping behind logins, no paid leaked-data brokers, no gray-market resellers. Every claim cites the surface it came from.
Infrastructure & web
- WHOIS (registrars, registrant proxies, history)
- DNS records — A, AAAA, MX, TXT, CNAME, SPF/DMARC
- Certificate Transparency logs (Crt.sh, Censys)
- Reverse DNS, ASN, hosting fingerprint
- HTTP headers, robots.txt, sitemap.xml
- Wayback / archive snapshots
Email & identity
- Breach datasets (HIBP-style)
- Gravatar, account presence probes
- Google / Microsoft / Apple account hints
- GitHub commit emails, mailing-list dumps
- Mail header & deliverability signals
Social platforms
- Twitter/X, Reddit, GitHub, LinkedIn, Mastodon
- Instagram, TikTok, YouTube, Twitch, Snapchat
- Discord, Telegram, Steam, Roblox, Keybase
- Username availability sweeps across 40+ sites
Phone & messaging
- Carrier & line-type lookups
- WhatsApp / Telegram / Signal / iMessage presence
- Truecaller-style spam intelligence
- Country / region geocoding
Image & media
- Reverse image search across major engines
- EXIF / metadata extraction
- Face-aware similarity (public, opt-in)
- Stock-photo & AI-generation detection signals
Threat & breach intel
- Public credential dumps & paste sites
- Domain & IP reputation feeds
- Open ports / common-services signals
- CVE and exposure references
What it never touches
- • Private accounts, DMs, or login-gated data
- • Paid people-search brokers reselling unconsented PII
- • Government records that require lawful process to access
- • Anything obtained through credential stuffing or unauthorized access
Source list grows as the model gains tools. Every active source is cited in the brief.