Skip to content

theHarvester

Collect public contact and host data for a domain

VerifiedOSINT· Email & DomainBeginnerGNU GPL v2Open sourceEntry revised 2 Jan 2026
  • Linux
  • macOS
  • Windows
  • Kali
  • Parrot
  • Docker
  • Source
This entry is thinner than the rest of the directory — missing sections are shown as such rather than filled with filler.Improve this pageContribute

Overview

4 commands documented

theHarvester queries a set of public sources — search engines, certificate transparency, and services whose APIs you configure — for email addresses, subdomains, hosts and employee names tied to a domain you are researching.

Its output is a starting list, not a conclusion. Sources differ in coverage and freshness, so record which source produced which record and re-verify anything you rely on.

Supported platforms

7

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

osint, domain, email, subdomains, cert transparency

Dataset entry

theharvester.ts

Reviewed 2026-01-02

Installation

Grouped by platform. Elevation requirements are marked per method.

Homebrew

AlternativeHomebrew
brew install theharvester

Package availability follows your distribution and enabled repositories. Entry revised 2 Jan 2026 — confirm the current release on the project's own download page.

Commands

4 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Collect emails and hosts for one domain

bash

Queries the enabled sources and prints the deduplicated lists.

theHarvester -d example.org -b all -l 200

Notes

  • `-l` caps results per source, which keeps a first pass quick and readable.

02Use specific sources

bash

Named sources behave predictably and are faster than 'all'.

theHarvester -d example.org -b virustotal,certspotter,github -l 100

Notes

  • Several sources require API keys in `theHarvester/api-keys.yaml`; without them they silently return nothing.

03Save a report for the case file

bash

Writes a file whose extension determines the format.

theHarvester -d example.org -b all -f reports/example.org

Notes

  • Produces HTML plus XML, which keeps the raw records machine-readable for later correlation.

04Verify discovered hosts resolve

bash

Adds a resolution pass so the host list reflects live names rather than historic records.

theHarvester -d example.org -b certspotter -c

Notes

  • `-c` performs a virtual-host check; treat a 200 from a default vhost as 'not a distinct site'. The CT log itself is the durable record: https://crt.sh/?q=example.org

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

Sources return nothing with no errorCause 1/2

Possible causes

  • Missing API keys, or the search engine throttled/blocked the request.

Usual fix

Run with `-v` to see per-source failures, add keys where a source needs them, and space out repeat runs.

ModuleNotFoundError on a fresh pip installCause 2/2

Possible causes

  • Dependencies pinned by the project conflict with the system Python.

Usual fix

Use pipx or a venv, or install the distribution package instead of a global pip install.

Tips

  • Record the date of every run: public data goes stale within weeks.
  • Cross-check the subdomain list against certificate transparency yourself before treating it as complete.

Alternatives & comparisons

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in OSINT