Method · Sources used

What Detrace looks at.

Detrace only touches public, open-source intelligence — no scraping behind logins, no paid leaked-data brokers, no gray-market resellers. Every claim cites the surface it came from.

Infrastructure & web

  • WHOIS (registrars, registrant proxies, history)
  • DNS records — A, AAAA, MX, TXT, CNAME, SPF/DMARC
  • Certificate Transparency logs (Crt.sh, Censys)
  • Reverse DNS, ASN, hosting fingerprint
  • HTTP headers, robots.txt, sitemap.xml
  • Wayback / archive snapshots

Email & identity

  • Breach datasets (HIBP-style)
  • Gravatar, account presence probes
  • Google / Microsoft / Apple account hints
  • GitHub commit emails, mailing-list dumps
  • Mail header & deliverability signals

Social platforms

  • Twitter/X, Reddit, GitHub, LinkedIn, Mastodon
  • Instagram, TikTok, YouTube, Twitch, Snapchat
  • Discord, Telegram, Steam, Roblox, Keybase
  • Username availability sweeps across 40+ sites

Phone & messaging

  • Carrier & line-type lookups
  • WhatsApp / Telegram / Signal / iMessage presence
  • Truecaller-style spam intelligence
  • Country / region geocoding

Image & media

  • Reverse image search across major engines
  • EXIF / metadata extraction
  • Face-aware similarity (public, opt-in)
  • Stock-photo & AI-generation detection signals

Threat & breach intel

  • Public credential dumps & paste sites
  • Domain & IP reputation feeds
  • Open ports / common-services signals
  • CVE and exposure references

What it never touches

  • • Private accounts, DMs, or login-gated data
  • • Paid people-search brokers reselling unconsented PII
  • • Government records that require lawful process to access
  • • Anything obtained through credential stuffing or unauthorized access

Source list grows as the model gains tools. Every active source is cited in the brief.