How to Find a GitHub Account by Email: What Real Lookups Returned

GitHub has no public search for hidden emails, but commit attribution links addresses to accounts. Four manual checks, what an email lookup adds, and seven public-record cases where a court or sanctions address led to a GitHub profile created years before the case.

Patrick Saif9 min read

ShareXLinkedInHacker News
Dark editorial cover with small white nodes joined by thin lines into a chain beside the words Find a GitHub account by email
Dark editorial cover with small white nodes joined by thin lines into a chain beside the words Find a GitHub account by email

You can find a GitHub account by email even when the profile shows no email at all. We ran 136 email addresses printed in court filings, Treasury sanctions entries and investigative reporting through an OSINTsearch email lookup. Ten of them resolved to a GitHub account. In seven cases that we can discuss against the public record, the account carried a name, a persona or a company that the record already ties to the person, and every one of those seven accounts was created before the case became public.

Below: four manual checks, what a lookup adds, the seven cases, how to read a match, and the settings that protect your own address.

Can you find a GitHub account by email?

Not through a single official search box. GitHub hides account emails by default, and a community member answering on GitHub's discussion forum in June 2025 puts it plainly: "GitHub does not provide a direct way to search accounts by email for privacy and security reasons."

What GitHub does expose is commit metadata. Per GitHub's documentation, "GitHub uses the email address set in your local Git configuration to associate commits pushed from the command line with your account on GitHub." That association is what every working method relies on. If someone once verified an address on their account and committed with it, the address and the account are linked, whether or not the profile page displays it.

Four manual checks, and what each one needs

  1. User search with in:email. GitHub's user search supports in:email, which matches words in a user's public profile email. It only finds people who chose to show an address, and GitHub notes that "for privacy reasons, you cannot search by email domain name."
  2. Commit search with author-email:. The commit search qualifiers author-email: and committer-email: match the full address. A hit shows commits in public repositories, and the avatar next to each commit shows which account GitHub attributed it to.
  3. Attribution in a repository you own. Because attribution follows the author email, a commit written locally with the address in question and pushed to your own private repository will display the account that has that address verified, if one exists. Use it only on addresses you have a legitimate reason to check.
  4. Password reset, for your own address only. The same thread suggests entering your address at GitHub's password reset page. If an account exists, the reset link arrives in your inbox.
MethodWorks whenReturnsLimit
in:email user searchThe address is public on the profileAccountMost people hide their email
author-email: commit searchThe address authored public commitsCommits and the attributed accountDefault branch only; private repos and accounts with no commits stay out
Attribution in your own repoThe address is verified on an accountAccount handle and avatarManual, one address at a time
Password resetYou own the mailboxYes or no, by emailUseless for anyone else's address
OSINTsearch email lookupThe address is linked to an accountHandle, display name, creation date, location, company, website, bio, commit countProfile fields are self-reported

What an email lookup adds

An OSINTsearch email search checks GitHub along with roughly 175 platforms in one pass and returns the profile itself rather than a yes or no. For a GitHub match that means the handle, the display name, the account creation date, the self-reported location, company and website fields, the bio and the commit count. It also returns Gravatar and WordPress profiles tied to the address. Our guide to seeing behind an email address covers the wider set of checks.

Seven GitHub matches, checked against the public record

The 136 addresses come from 49 cybercrime cases. Every address below was printed by a court filing, a Treasury sanctions entry or a named news source, and every person below has been charged, convicted or sanctioned. Those still only charged are presumed innocent. We describe handles generically unless the public record already prints them.

Case (record)Address in the recordGitHub resultAccount createdWhat lines up
Dmitry Khoroshev, alleged LockBitSupp (indicted, sanctioned May 2024)[email protected] (Krebs, 2024)Account on the handle nerowolfeNovember 2011Krebs, citing Intel 471, reports the address registered more than a dozen NeroWolfe forum accounts between 2011 and 2015
Kenneth Schuchman, Satori (pleaded guilty 2019)[email protected] (Krebs, 2018)Account on the handle NexusZetaJune 2017Company field "ZetaSec" and website field nexusiotsolutions[.]net, both named in the same Krebs article
Kirill Firsov, deer.io (sentenced to 30 months)[email protected] (Krebs, 2020)Account on the handle firsov, bio "Security researcher"June 2011Krebs reports the forum persona Isis linking to GitHub code under the username Firsov
Blake Benthall, Silk Road 2.0 (arrested 2014)[email protected] (Krebs, 2014)Display name "Blake"July 2009Krebs published a screenshot of Benthall's GitHub profile in 2014; the handle matches the Facebook profile Krebs linked
Colton Grubbs, LuminosityLink (pleaded guilty 2018)[email protected] (Krebs, 2018)Display name "Colton Grubbs", 189 commitsAugust 2016Full legal name
Maksim Rudenskiy, TrickBot (sanctioned and indicted 2023)[email protected] (OFAC)Display name "Max Rudensky"December 2015Transliteration of the sanctioned name
Andrey Zhuykov, TrickBot "Defender" (sanctioned and indicted 2023)[email protected] (OFAC)Display name "Andrey", location "Россия" (Russia)September 2013First name and country

The other three GitHub matches in the set belong to cases we do not cover in this post. The Grubbs trail is told in full in our KFC Watermelon case study.

Bar chart of how many years each of seven email-linked GitHub accounts existed before the public-record event cited for its case, from 1.2 years for Schuchman to 12.5 years for Khoroshev
Years between the GitHub account's creation date and the public-record event cited in the table. All seven accounts predate the case.

How to read a GitHub match

A match proves one narrow thing: at some point, whoever controls the GitHub account verified or committed with that mailbox. The rest is corroboration, in grades.

  • A full name in the display field. "Colton Grubbs" and "Max Rudensky" are the strongest results in the set because they repeat the record's name on an account anchored to the record's address.
  • A persona or company the record already names. The NexusZeta account's company and website fields match the registrant organization and control domain in Krebs's reporting. The nerowolfe account matches the persona Krebs tied to the same address.
  • A first name or a country. "Andrey" in Russia and "Blake" mean little alone. They matter only because the address came from a sanctions entry or a charging record.
  • Dates. The nerowolfe account opened in November 2011, inside the 2011 to 2015 window in which Krebs, citing Intel 471, says the same address registered NeroWolfe forum accounts. An account created long before a case went public is hard to explain as an impersonator. An account created after would need to be treated as a possible squatter until proven otherwise. For more on reading dates, see how to find when an account was created.

The next step is a second hop: run the GitHub handle through a username search. On the handle behind the Rudenskiy address, a username search returned an open source developer forum profile from 2000 whose display name matches the sanctioned name, but whose location differs from the city on the sanctions entry. That makes it a consistency question, not a confirmation. Here, four platforms on the same handle display the name "Blake Benthall", which is a lead worth checking rather than confirmation, while other accounts on the same string display entirely different people's names. That contrast is the reason the email anchor matters: a handle alone collects strangers, and an address from the record narrows it to one account.

Check your own email first

The same method works as a privacy audit. The reverse direction is simpler still: anyone can read the author email on a user's public commits, which is why the settings below matter. Run your own addresses through a free OSINTsearch email search and see what a stranger would see. If a GitHub account comes back, open GitHub's Emails settings and review three things:

  • Keep my email addresses private. GitHub then uses your noreply address for web-based Git operations, which, for accounts created after July 18, 2017, GitHub documents as "an ID number and your username in the form of [email protected]".
  • Block command line pushes that expose my email. With this setting on, a push is refused when its latest commit is authored with one of your private addresses.
  • Your local Git config. Set git config --global user.email to the noreply address so new commits never carry the personal one.

None of this rewrites history. Commits already pushed with a personal address keep it, and anyone can still read it from those commits. Our free digital footprint audit walks through the rest of the checks.

FAQ

Can I search GitHub by email address directly?

Only for addresses that users made public on their profile, using in:email in user search. For everything else, GitHub links addresses to accounts through commit attribution, so commit search or an email lookup is the practical route.

Why does a lookup find an account when the profile shows no email?

Because the link lives in GitHub's account records and commit attribution, not on the profile page.

Does a GitHub match prove who owns the account?

No. It proves the account and the mailbox were connected at some point. Ownership needs corroboration: a name or detail that matches an independent record, dates that fit, and ideally a second platform that agrees.

What does it mean if the email returns no GitHub account?

That the lookup found no GitHub account with that address attached as a verified email. Treat it as a result for that one address, not a verdict on the person: they may use GitHub under a different mailbox, so run every address you have, then search the handles those results return.

Start with one address

One email can carry a handle, a name and a creation date, often enough to confirm or rule out a lead. Run a free OSINTsearch email search on the address you are checking, or on your own, and see which accounts it still opens. For the wider pattern of how these links surface in real investigations, read how hackers get caught.

ShareXLinkedInHacker News
All articles

Privacy9 min

Can a Burner Email Be Traced? What Court Records and Real Lookups Show

Yes, but rarely through the burner itself. Court records show persona addresses traced through registrar logins, a shared VPN address, domain records and leaked forum databases. An email lookup finds no registrations for those addresses, consistent with the records, while the owners' everyday mailboxes still return registrations.

Security9 min

How Do Hackers Get Caught? 9 OPSEC Mistakes From Court Records

How do hackers get caught? In the cases that reach court, usually through their own history: an old personal email, a reused password, a login from home, a crypto account opened with real ID, or a trip abroad. Here is how the FBI and journalists made the link in real cases, with a primary source for each, and what those published addresses still return today.

Try it

Run a live search on any username.

Free preview, no account needed. Sign up to view available profile details.

For other identifiers, try reverse email lookup or phone number lookup.