Verify OSINT Account Matches
A username match answers whether a page may exist under a handle. It does not answer who controls the page. Use this decision process to distinguish a candidate, a corroborated public link and a claim you cannot support. It works for self-audits and research with a defined authorization.
MyRecon editorial · Updated 2026-10-03
Key takeaways
- Start with a known reference
- Check that the result is actually a profile
- Rank evidence by independence
Start with a known reference
Write the claim you are checking before opening results. For example: does this profile belong to the maintainer of the official project? Use a reference controlled by that project, such as its website account-links page. A search snippet, scraped directory or another username checker is not an independent reference if it repeats the same source. For your own old account, saved signup emails and a recognized login can be useful private confirmation, but do not publish those records as evidence.
Check that the result is actually a profile
Open the exact candidate URL. Note the current handle, page type and final destination. A platform may return a login page, generic application shell or soft error with a successful HTTP status. A username embedded in a URL is therefore insufficient. A user page can also redirect to an organization or a renamed account. In MyRecon, keep found, not found and unknown distinct; a check that was blocked or timed out cannot be promoted to either a confirmed account or a confirmed absence.
Rank evidence by independence
An official website linking directly to an account is stronger for a public association than a similar display name. Two profiles using the same avatar are not necessarily two independent clues: images are copied. A reciprocal link can help, but note that compromised accounts can also publish misleading links. Record each source and explain why it is independent. Stop short of establishing a legal identity or current control unless your task has a separate authorized verification process.
Use a decision log rather than a numerical confidence score
Make columns for claim, candidate URL, observation, supporting source, conflicting evidence and conclusion. Useful conclusions are candidate only, public association corroborated, conflicting evidence and unable to verify. Do not turn a percentage generated without a validated model into evidence. When details conflict, write the conflict directly: the official project links to a different handle, or the candidate advertises an unrelated organization. Absence of a backlink is not by itself a disproof.
| Evidence available | Conclusion | Follow-up |
|---|---|---|
| Matching handle or copied avatar only | Candidate only | Look for an independent official link |
| Official project page links to exact profile | Public association corroborated | Record source URL, date and current-control limit |
| Official link points to a different profile | Conflicting evidence | Preserve both sources; avoid merging identities |
| Login wall, challenge or timeout | Unable to verify | Record access context; do not infer absence |
Download the blank register with one illustrative example (CSV)
Worked example: a reused handle
Illustrative case: a project website links to github.com/example-studio, while a social profile named example_studio uses a similar avatar but has no project link. The GitHub association is supported by the project source. The social profile remains a candidate because the matching handle and avatar could have been copied. Add a follow-up only if the research purpose requires it; do not infer that the accounts share a person, email address or location. Record the observation date because links and handles can change.
Write a report another reviewer can challenge
Include the claim, original URLs, observation time, positive evidence, conflicts and unavailable sources. Distinguish what was visible while signed out from anything shown under an authorized login. Leave irrelevant personal details out. If you cannot reproduce a page later, preserve the prior observation as dated evidence rather than quietly changing the conclusion. A defensible result may be unresolved; the goal is a supportable answer, not the largest connected-account graph.
Check a public username
Guest previews and account limits apply. See current pricing. Verify each candidate at its source.
Frequently asked questions
Does the same avatar prove two accounts are linked?
No. Images can be copied. Look for independent, source-controlled links and record conflicts.
What should I do with a blocked profile?
Record unable to verify, including the blocked source and date. Do not treat a block as proof of existence or absence.
Can public links verify a legal identity?
They can support a public association. Legal identity and current account control require a separate verification process.
Sources and method
Worked examples are illustrative unless explicitly labeled as observed. Product limits were checked against the release source; linked provider instructions describe external workflows, not a claim that every account flow was tested.