Email Exposure Self-Audit: What Public References Can Reveal
A privacy-conscious way to review public references to your own email address, decide what matters, and reduce unnecessary exposure.
An email address is often both a contact method and a durable identifier. It can appear in old profiles, documents, newsletters, community posts, repositories, and public contact pages. A self-audit can reveal where it remains visible, but visibility is not automatically a problem and a result is not proof of account ownership.
Make a bounded inventory
List active addresses, retired addresses, intended public contact routes, and any work or personal separation you want to maintain. Run one address at a time and record only the public pages that are relevant to the audit question.

Classify each result
| Classification | Meaning | Action |
|---|---|---|
| Expected | An intentional public contact page. | Confirm it remains current and protected. |
| Stale | An old profile, document, or account reference. | Update, remove, or close it where possible. |
| Uncertain | A page without enough context to attribute. | Do not claim ownership; retain only if follow-up is authorized. |
| High impact | A public reference that could misdirect or expose a sensitive role. | Use the relevant owner or security process. |
Reduce exposure deliberately
Use a dedicated public contact route where it makes sense, remove abandoned profile information, and review forwarding and recovery details on accounts you keep. Avoid publishing personal addresses where an approved form or role-based mailbox is sufficient.

SpiderFoot.tools can help surface public email leads in an approved audit, but results require context. The goal is not total invisibility; it is intentional, current, and secure public contact information.
// USEFUL_INTEL?
Signal that this research note was useful.