High-Throughput Silent Phone Number OSINT & Identity Footprinting Suite
Uncover account registrations, masked emails, display names, and profile photos across major platformsβwithout ever dispatching an SMS or alerting the target.
Most phone number tools stop at basic format parsing or risk blowing an investigation by triggering loud 2FA/SMS verification codes to the target's mobile device.
phonsint is engineered for silent, high-fidelity reconnaissance. It interrogates pre-authentication discovery endpoints, recovery validation flows, and cryptographic challenge APIs (such as Meta LOX proof-of-work) to determine account existence and extract rich profile metadataβcompletely silently.
- Guaranteed Silent Operation: Exploits unauthenticated query endpoints and pre-dispatch recovery flows that never send SMS verification codes or push notifications to the target.
- Deep Identity Enrichment:
- π§ Masked Email Addresses: Surfaces linked emails (e.g.
j******e@gmail.com) associated with the phone number. - π€ Full Display Names: Pulls account owner names from public platform recovery APIs.
- πΌοΈ High-Resolution Avatars: Extracts direct CDN profile photo URLs without logging in.
- π’ Tenant & Region Routing: Identifies regional datacenters (e.g., Zoho US, EU, IN, CN, JP).
- π§ Masked Email Addresses: Surfaces linked emails (e.g.
- High-Throughput Concurrency: Built with Python
asyncioandcurl_cffifor browser TLS fingerprint impersonation (bypasses Cloudflare, Akamai, and Shape Security without heavy headless browsers). - Zero False Positives: Uses strict, dual-state validation markers (matching the design philosophy of
user-scanner). - Multi-Format Reports: Automated structured exports to JSON and CSV for immediate ingestion into investigation pipelines.
Checking phone: +14155552671
== SOCIAL SITES ==
[β] Facebook (+14155552671) [Registered]
βββ name: John Doe
βββ masked_email: j******e@gmail.com
βββ avatar: https://scontent.xx.fbcdn.net/v/t39.30808-1/s200x200/412...
[β] Instagram (+14155552671) [Registered]
βββ contact_point: Phone Number Verified
== AUTH SITES ==
[β] Microsoft (+14155552671) [Registered]
βββ auth_type: Live ID / Account Exists
== SHOPPING SITES ==
[β] Amazon (+14155552671) [Registered]
βββ claim_endpoint: Active Sign-in Route
== SUMMARY ==
Total Sites Scanned: 5
Registered / Found: 4
# Clone the repository
git clone https://github.com/kaifcodec/phonsint.git
cd phonsint
# Create and activate virtual environment
python3 -m venv .venv
source .venv/bin/activate # On Windows: .venv\Scripts\Activate.ps1
# Install dependencies and package in editable mode
pip install -e .pip install phonsintphonsint -p +14155552671If a target number does not include an international + country prefix, specify the default ISO country code:
phonsint -p 07911123456 -r GB
phonsint -p 9876543210 -r IN# Scan authentication providers only (e.g., Microsoft)
phonsint -p +14155552671 -c auth
# Scan specific platforms
phonsint -p +14155552671 -m facebook,instagram
# List all available modules and categories in a clean table
phonsint -l# Show all results including unregistered platforms and diagnostic reasons
phonsint -p +14155552671 --all -v
# Export results to JSON or CSV
phonsint -p +14155552671 -o report.json
phonsint -p +14155552671 -f csv -o report.csvIn phone OSINT, accidental SMS verification codes sent to the target's phone are a critical operational failure. phonsint operates 100% silently by default, targeting pre-dispatch query endpoints, session credential checks, and unauthenticated recovery validations that do not dispatch SMS messages.
Any module that could potentially trigger a notification is registered under LOUD_MODULES in phonsint/core/helpers.py and will be automatically skipped unless the user explicitly passes --allow-loud.
We welcome contributions! Adding a new platform check takes around ~30 lines of clean Python. Check out CONTRIBUTING.md for developer conventions, validator signatures, and instructions.
Distributed under the MIT License.