MailAccess is designed for:
- Security research — investigating the exposure of your own or client-authorized addresses
- OSINT investigations — open-source intelligence gathering in professional or journalistic contexts
- Penetration testing — with explicit written authorization from the target organization
- Personal exposure audits — checking your own email addresses against breach databases and public sources
Every data point MailAccess retrieves comes from publicly accessible sources: breach notification databases, public APIs, DNS records, WHOIS registries, and the open web. MailAccess does not exploit vulnerabilities, bypass authentication, or access any non-public system or dataset.
MailAccess is not designed or intended for:
- Unauthorized access to accounts, systems, or private data
- Surveillance, stalking, or targeted harassment of individuals
- Aggregating personal data about individuals without their consent or a lawful basis
- Any activity that violates the Computer Fraud and Abuse Act (CFAA), the UK Computer Misuse Act, GDPR, or equivalent laws in your jurisdiction
By using MailAccess you accept sole legal and ethical responsibility for how you deploy and use it. The authors provide this software as-is, without warranty of any kind. If you are unsure whether a particular use is lawful in your jurisdiction, consult a qualified attorney before proceeding.
Misuse of this tool may violate federal, state, or local laws. The project maintainers are not liable for any misuse or damage arising from use of this software.