Whatever a stranger puts in front of you online, one free page turns it face up
before you trust it —
a kit sorted by the moment you need it. No signup, no install, no skills.
⏳ THE RULE handle · domain · wallet · channel · shop → check its birthday first
born this month? → walk
I HAVE… OPEN
any ID · handle · domain ⏳ BIRTHDAY
a seller in my DMs 🧾 THE DM
a channel · an invite link 📢 THE GROUP
a new shop · a job offer 🏪 THE SHOP · THE JOB
a photo · a video 📸 THE PIC
a payment screenshot 🧾 THE PROOF
an unknown number ☎️ THE NUMBER
an email address 📧 THE EMAIL
a card · IBAN · wallet · QR 💸 THE PAYMENT
reviews · vouches ⭐ THE VOUCHES
one handle, want the rest 🔗 THE PERSON
a PDF · installer · APK 📄 THE FILE
a short link · airdrop URL 🔗 THE LINK
a second-hand phone 📱 THE USED PHONE
a place · coordinates 🗺️ THE PLACE
a name → everything 🔎 FIND (the original kit)
my own exposure 🪞 YOU
⏳ BIRTHDAY — I have any ID, handle, link, wallet or domain → I see the day it was born
Everything online carries its birthday. Fresh is the first tell of a fake.
Discord · paste any ID (user, server, channel, message — right-click → Copy ID) → exact creation date, nothing leaves your browser — discordtimestamp · with badges, connected accounts, live status — discord.dog
X · username → the exact DAY it was created (X itself shows month and year only) — Sorsa
Instagram · TikTok · YouTube · Threads · handle → its numeric ID — IDInfo → that ID → creation time — epochconverter
Telegram · @username → registration period — GramGPT. Telegram gives an estimate — its IDs carry no date; every platform above gives the exact day.
Reddit → exact signup date — Cake Day Checker ·
Steam → creation date + VAC bans — Skinflow ·
GitHub → created_atin plain JSON, zero tool —api.github.com/users/NAME
any domain → registration date straight from the registry, no ads — RDAP · every TLS certificate ever logged; the earliest one is the day the shop really went live — MySSL CT
ETH · BSC · SOL wallet → first-transaction date, days alive — CryptoLens
→ Born this month? Walk.
🧾 THE DM — a stranger offers a deal → I see if the seller is real
in Telegram · @username → permanent numeric ID + Telegram’s own scam and fake flags — tgkit · that ID → every past @username and display name (renamed to dodge a blacklist = caught) — username history with @SangMataInfo_bot
in Discord · user ID → flagged in the cross-server scam database — AntiScammer
in your browser · handle, wallet, phone or URL → Safe · Caution · Danger against 34,000 confirmed scam entries — GACS
India, official · the seller’s phone, UPI ID, account number, email or handle → already named in a cybercrime complaint — NCRP suspect search
handle + platform (Telegram, Discord, Instagram, OnlyFans, Patreon…) → chargeback and scam report count, CAPTCHA only — CopyrightShark
username, email or name → profiles on 175+ platforms in one pass (a “veteran seller” with one fresh handle = caught) — Lullar
→ Nine-day-old handle + zero history anywhere else = no deal.
📢 THE GROUP — a Telegram channel or Discord invite → I see official or clone
paste the invite → members, boost level, description, icon — without joining — Server Info Viewer · server or bot ID → age — discordtimestamp
in Telegram · open the channel → menu → Go to first message → the channel’s birth date from Telegram itself — how
paste the channel or user name → every Cyrillic, Greek or full-width lookalike letter exposed with its code point — Homoglyph Detector
→ Lookalike letters, or a channel born last week = clone.
🏪 THE SHOP · THE JOB — a new site, deal or recruiter → I see when it was born and who is behind it
domain → registration date + DNS/SSL + subdomains + reverse-IP neighbours + ownership history, one page — DomainIntel
shop URL → 0–100 risk + which signals fired, against 21,700 known fraud shops — FakeShops
URL → a graph of every domain sharing its favicon, certificate, IP or wallet = the whole clone farm — Alertoscan
official registries ·
company or CIN → incorporation date, address, directors with DIN — MCA ·
company → RC number + status — CAC ·
company name → registered or not — SECP ·
CNPJ → partners and administrators — gov.br ·
officer search — Companies House
→ Recruiter’s email domain born last month = fake job.
📸 THE PIC · THE VIDEO — a profile photo, a 'proof' video → I see shot, stolen or generated
drop the JPEG → re-compression flag = downloaded and re-saved, not shot (runs locally) — Photovoid
a “photo” → screenshot-of-a-photo verdict from device resolutions + missing camera data — Scanly · a camera JPEG → its embedded thumbnail against the image = a heatmap of what was edited — Thumbnail Scanner
image, video or PDF → Content Credentials: which tool made it, declared AI or not — TrueScreen C2PA · any file → AI probability + the likely model — Hive
drop a video → the encoder or app that last saved it + timestamps, nothing uploaded — EXIF.pro
reverse image on the Asian web (faces Google misses) — Bing Visual · Sogou 识图 · Baidu 识图
on the video call · ask them to turn the head fully sideways, pass a hand over the face, then hang up and call back — a live face-swap breaks on all three — the test
→ Re-saved + no camera data + the face found elsewhere = stolen.
🧾 THE PROOF — a payment, earnings or delivery screenshot → I see real or made
the carrier name in the status bar → its real country (“US Zelle” over a Jio bar = caught) — MCC-MNC
status-bar style, font, icons → the iOS year they belong to — Version Museum · Apple’s own icon table — status icons · Android by version — Google’s guideline
two or more screenshots from the same person → battery, clock and notifications must move forward together; a battery that climbs or a clock that runs backwards = made — the check
upload → verdict + reasons · UPI apps — ScamDekho · Venmo · Cash App · Zelle · PayPal — ScamCheck · edited-in-browser tells — FauxLens · receipts — checkreal. Feed each one a screenshot you know is real first, then the suspect one.
in your own bank app · the only proof is “Completed” on YOUR side — PayPal’s own status list
→ Wrong-country carrier, or a clock running backwards = the money never moved.
☎️ THE NUMBER — an unknown call or WhatsApp → I see carrier, burner or scam
any number → carrier, line type (VoIP burner), timezone, crowd spam score — CallTracer · scam flag + reports — Malwarebytes · line type + scam risk, in your browser — Kinvo
reported in India — WhoCalledMe ·
Anatel carrier, DDD, type — BuscaFIPE ·
spam reports — NoCall
the name strangers saved it under → the apps everyone already has: Getcontact · Eyecon · Truecaller · Whoscall
wa.me/NUMBER→ their WhatsApp photo + about without adding them ·t.me/+NUMBER→ their Telegram profile
TRAI rule · promo calls come only from 140-numbers, banks and government only from 1600-numbers — any other prefix “from your bank” is not your bank
→ VoIP line + fresh Telegram + saved as “scammer” by 40 strangers = block.
📧 THE EMAIL — an address in a DM or an offer → I see the face and the age behind it
in Google Docs · type the Gmail into the Share box → their real name + photo appear before you share anything
email → Gravatar photo, name, bio, linked accounts (it hashes for you) — OxINT Gravatar
at account.microsoft.com · type the email → “no account found”, or a password prompt = a Microsoft account exists
the part after @ → registration date + mail provider (fresh domain, temp-mail) — U2L whois
→ Domain born last week + no face anywhere = not the company.
💸 THE PAYMENT — a card, IBAN, wallet, PayPal.me, $cashtag or QR → I see who really gets the money
first 6–8 card digits → issuing bank + country (buyer “in Texas”, card from Lagos) — binlist · IBAN → bank, BIC, head office — IBANok
paypal.me/HANDLE·cash.app/$TAG→ their public page: real or business name, photo, city
in your own UPI app · type the UPI ID in Pay → the bank-registered name appears before the PIN (NPCI rule) · IFSC → bank + branch — ifsc.razorpay.com/IFSC
BTC · ETH · TRON + 12 chains → risk score + who it deals with (exchanges, flagged wallets) — Cryptnox · wallet age — CryptoLens
a screenshot of a payment QR → the raw recipient + amount BEFORE you scan it (runs locally) — QRSprint
→ Name on the page ≠ name in the chat = don’t send.
⭐ THE VOUCHES — reviews, vouch channels, screenshots → I see coordinated or real
on Trustpilot · click any reviewer → their whole history with dates; five 5★ for unrelated shops on one day = bought
Amazon listing → A–F grade, fake %, timing anomalies — Null Fake · paste 3+ reviews with dates → verified %, same-day clusters — Fake Review Detective · one review → 0–100 suspicion + which tells fired — Reviewz
two vouch texts → same author or not, 40+ writing fingerprints, in the browser — Stylometry Lab
the vouch avatar → every other page that face appears on — FaceOnLive
→ Same-day cluster + same writing fingerprint = one person.
🔗 THE PERSON — one handle → I see their other accounts and their timezone
github.com/USER.keys·.gpg· any commit URL +.patch→ SSH keys, GPG identity, commit email
Reddit username → deleted and removed posts restored — Rosint · 7×24 posting heatmap with estimated timezone — Rosint+ · Karmic
wallet address → every BitcoinTalk post that ever carried it, with its author — Talksearch
→ Sleeps 02:00–09:00 at UTC+5:30 = not in New York.
📄 THE FILE — a method PDF, an installer, an APK → I see who made it, when, and what is inside, before opening
PDF or DOCX → author, company, software trail, revision count, macro and embedded-object flags — Recosint · document or hash → First Seen date, risk score, the exact CVE — Analyzer.sh · PDF → malware, signature tamper, content spoofing — PQ PDF
rebuild it flat with macros and phone-home stripped, open THAT — Protego · read a PDF as text + page images in the browser, nothing runs — zalt
drop any file → hashed locally → verdict; the file never leaves your device — iMalware · entropy heatmap (packed?) + strings + URLs inside — Binary Inspector · .exe → compile date, publisher, signed or not — EXE Viewer
APK → permissions + baked-in keys — BetaDrop · signing cert, packer, every domain in the code — Pithus
paste the HASH → what sandboxes already found: family, first seen, score, no upload — Triage · Hybrid Analysis · MalwareBazaar · Filescan. Get the hash with nothing installed: Windows Get-FileHash file· Macshasum -a 256 file· phone — local SHA-256
→ “New method”, first seen 2019 = recycled.
🔗 THE LINK — a short link or an airdrop URL → I see where it really goes, before clicking
add one character to the short link · bit.ly/xxx+·tinyurl.com/preview.xxx·cutt.ly/xxx@·is.gd/xxx-→ destination + click stats; the page never loads
URL → phishing verdict, redirect chain, DNS, tech stack, screenshot — Cloudflare Radar · Google’s own live verdict — Safe Browsing
in Telegram · link previews on → title, description and the real domain render before you tap; long-press copies the true URL in Telegram, WhatsApp and Discord
→ Destination ≠ what the message says = don’t tap.
📱 THE USED PHONE — a second-hand phone or laptop → I see stolen, locked, fake or genuine
dial *#06#→ the IMEI ·
lost, stolen, blocked — CTIA ·
genuine or blacklisted — KYM, or SMS KYM <IMEI>to 14422 ·
NEIR ·
CA ·
Anatel ·
DIRBS
IMEI → brand, exact model, chipset, year (the “Pro Max” is a Pro) — HiCellTek · a fabricated IMEI fails the check digit — CyTools
serial → purchase date + warranty; a serial Apple doesn’t know is not an Apple — Check Coverage ·
HP serial → warranty — HP
with the seller present · power on: “iPhone Locked to Owner” = walk — Apple · Android: factory reset; it asks for the previous Google account = still theirs
→ Blacklisted, locked, or a model that isn’t what they said = walk.
🗺️ THE PLACE — coordinates or a place name → I see what is there and who posted from there
place + radius → every geotagged YouTube video there — Geofind · flickr.com/map/?fLat=…&fLon=…→ public photos at that point ·tiktok.com/place/…→ every video tagged there, no login · Instagram pins on a map — InstaHunt
16,900 live traffic, city and port cams + flights + ships on one map — ARGOS ATLAS · the nearest live cams — OpenCCTV
coordinates → the exact address record — Nominatim · every ATM, bar, hotel within X km — FreeMapTools · a mountain photo → every peak labelled (iOS) — Skyline
→ “Live from Dubai” with a Karachi webcam behind them = not Dubai.
🔎 FIND — type one thing, find everything: handle → email → photo → place, each hit leads to the next (the original kit, kept whole)
A name · email · username · photo · phone → free point-and-click sites do the digging. No install, no signup, no skills.
Start with one box
Max Intel — paste anything (name, email, username, phone, or a photo) and it fans across 960+ sources at once. No account, no keys. · Menu view: OSINT Framework
A USERNAME → every account they own
Sherlock · WhatsMyName · Fingerprint (700+ platforms, streams live)
AN EMAIL → who’s behind it
Epieos (the famous one) · Skopio (22+ sources, free daily lookup)
IS IT LEAKED? · email · password · phone in a breach
Have I Been Pwned (the classic — paste an email, see every breach) · InfoBreach (breach dumps + stealer logs)
A PHOTO → who is it
Yandex (best for faces + places) · TinEye · PimEyes (face search — scary-good)
A WEBSITE → owner + history
ViewDNS (whois, server-neighbours, history) · Wayback Machine (deleted / older versions)
The rare tricks — nobody lists these
A PHOTO → WHERE on Earth · no GPS in the photo needed
ShadowFinder (drops a pin from a shadow’s length — Bellingcat’s method, in your browser) · PhotoRadar (AI reads the visual clues) · Weather-locate (a weather-widget screenshot → when & where) · Signal & Shadow (sun-angle calculator)
A VIDEO → trace it back to the source
Frame Grab (no engine searches video directly — this pulls one sharp frame in your browser, nothing uploads) → then reverse-search that frame with Yandex or TinEye above
A PHOTO or VIDEO → is it even real
Lens (free browser extension — flags AI-made images as you scroll, checks the hidden watermark first) · Specula (upload one photo, get a verdict with the reasoning shown — free, first load can take a moment to wake up)
AN AUDIO CLIP → name the song / same voice or not
Vocuno (upload a clip, matches the acoustic fingerprint — works on voice memos too) · Voice Match Checker (upload two clips, get a same-person-or-not verdict)
WATCH THE WORLD LIVE
FlightRadar24 (any plane) · ADS-B Exchange (even the private jets FR24 hides) · MarineTraffic (any ship) · Zoom.earth (live satellite)
A WEBSITE → every OTHER site the same person runs
DNSlytics — unmask a whole network by the Google-Analytics / AdSense ID they reuse across their sites
A CRYPTO WALLET → follow the money
Chainabuse (is it a reported scam?) · Breadcrumbs (trace where the coins went)
A PHONE → who owns it
UserSearch · Max Intel · Phone · Line Type Check (mobile, landline, or a disposable VOIP number)
A PHOTO, FILE or PDF → its hidden data
Jimpl (drop a photo → GPS pin on a map + camera model) · Metadata2Go (hidden data inside any file) · PDFCheck (catches an edited or backdated PDF)
A NAME → address, phone, relatives · US public records
TruePeopleSearch · FastPeopleSearch · ThatsThem — all free, no signup
A NAME → is there a court case on them
CourtListener (free, non-profit — millions of real US court filings and case law, just search a name)
A COMPANY → who really owns it, who really works there
OpenCorporates (150M+ companies + their officers) · OpenSanctions (sanctions / PEP check) · Aleph (OCCRP’s leaks + records archive) — for the team behind it, search site:linkedin.com/in "company name" on Google, no tool needed
GOOGLE DORKS → surface what’s hidden in plain sight
DorkSearch (pre-built Google dorks, click to run — exposed files, logins, documents)
TELEGRAM → search channels + people
Lyzem · TGStat (channel stats + search)
THE DARK WEB → search it without getting lost
Ahmia (searches .onion sites — needs Tor Browser to open a result, that’s it, nothing else technical)
SEE ANY PLACE — past + present + what changed
Google Earth (historical-imagery time slider) · Historic Aerials (aerial photos back to the 1930s) · archive.today (snapshot / read deleted pages) · GeoSentinel (draw a box, pick two dates, see exactly what changed)
AN IP ADDRESS → who, where + is it a VPN
ipinfo.io (geolocation, ISP, VPN/proxy flags — plain language)
🪞 YOU — run every box on yourself first → I see what strangers see, then I delete it
every SIM issued on your ID + one-click “not mine” — TAFCOP ·
SIMs on your CNIC — 668 ·
dial *16001#·
lines + wallets on your ID — the My NTRA app ·
every account, loan and Pix key on your CPF — Registrato ·
every company you are listed at — Companies House
your email → the forgotten avatar and name shown on every WordPress comment — Gravatar check · your number, handle, face → run CallTracer, Lullar and FaceOnLive above on yourself
a service name → its direct deletion link + difficulty — JustDeleteMe · the three respected broker opt-out lists — BADBOOL · IntelTechniques workbook · Privacy Guides
pull yourself out — FaceCheck · Truecaller · Sync.me · a 15 min / 30 min / 2 h self-audit — UofT
→ What you find, they found first. Delete it.
🧠 10-second how-to — zero experience
- Pick the box that matches what you have — a name, email, username, photo, video, audio clip, or phone.
- Open a tool, paste your one thing, hit search.
- Each result is a public breadcrumb — one leads to the next (username → email → photo → place). The chaining is the whole skill; the tools do the work.
- Something a stranger just handed you? Start with
BIRTHDAY, then the box that matches — before you pay, join, click or open.
Everything here reads public info only — no hacking, no logins, no passwords.
⚠️ Use it right
Same tools journalists and security teams use to check who they’re dealing with — and to see your OWN exposure. Run your email through Have I Been Pwned right now; look yourself up first.
Links rot — a tool dies, drop a
reply with the newest working one. Kept current.

!