Email finding

How to find someone's email address

Most work email addresses can be found in minutes if you know the person's name and where they work. Here are eight methods, from fastest to slowest, a worked example, and the rules for writing to the address once you have it.

Updated October 9, 2026 · 11 min read

Finding Maya Okafor's work email at example.com: address candidates checked, only maya.okafor@example.com is deliverable

How to find someone’s email address depends on what you already know. With a name and the company the person works for, you can usually find their work address in a few minutes: company addresses follow a pattern, and a mail server will tell you whether an address exists. With a name alone, it’s much harder, and for private addresses there is no public directory to look in.

This guide covers eight methods for finding work email addresses, ordered from fastest to slowest, then a worked example, how to verify what you found, and what the law says about writing to it.

#MethodCostBest for
1Email finder10 credits per searchAny work address when you know name and company
2Guess the format and verifyFreeCompanies with a consistent address format
3Company website, press pages, author biosFreeExecutives, press contacts, writers, researchers
4LinkedIn10 credits per searchPeople you found on LinkedIn or Sales Navigator
5Google search operatorsFreeAddresses published anywhere on the web
6GitHub and open-source commitsFreeDevelopers, for project-related contact only
7WHOISFreeRarely useful since 2018
8Ask a mutual contact or the companyFreeAnyone you can reach through others

1. The fastest way: name + company → email finder

An email finder takes a first name, a last name and a company domain and returns the person’s work address. The email finder on emailvalidation.io works this way: enter, for example, a first and last name and example.com, and you get the address back if one can be found. The finder checks every address with the mail server; on catch-all domains, which accept any address, it returns the most common pattern (first.last@) and marks it as risky. You can save the people you find to lists and export them as CSV.

What you need:

An email search costs 10 credits. The free plan includes 100 credits a month, so you can run 10 searches a month without paying (pricing).

2. Guess the email format and verify it

Most companies give every employee an address in the same format, such as first.last@ or flast@. If you know the format, you know the address. If you don’t, generate the candidates and let the mail server tell you which one exists:

  1. Enter the name and domain in the free email permutator. It lists the common formats: anna.becker@example.com, abecker@example.com, anna@example.com and so on.
  2. Check all candidates at once with the free bulk email verifier.
  3. The address the company’s mail server accepts is the real one; the others come back undeliverable with the reason invalid_mailbox.

One catch: catch-all domains. Some companies accept mail for every address, so every candidate is accepted and the check can’t tell you which one is real. When all candidates come back accepted, combine the guess with method 3: find one real address at the company, and use its format. Catch-all email addresses explains how verifiers detect these domains.

3. Check the company website, press pages and author bios

Companies publish more addresses than you’d think:

Even when the person you want isn’t listed, one published address from a colleague shows you the company’s format (method 2).

4. Find an email address from LinkedIn

If you found the person on LinkedIn, the LinkedIn email finder Chrome extension looks up their work email address from the profile. It works on profiles, in Sales Navigator, in Groups and in Recruiter, and saves the leads to your emailvalidation.io account. A LinkedIn email search costs 10 credits, the same as a search in the email finder.

Without the extension, look at the profile’s contact info section: some people list an email address or a personal website there.

5. Use Google search operators

Google’s search operators narrow results to the pages that are likely to contain an address. Google documents these (Refine web searches, checked October 9, 2026):

OperatorWhat it doesExample
" "Exact match of a word or phrase"Maya Okafor" "@example.com"
site:Results from one site or domain only"@example.com" site:example.com
filetype:Documents of one file type"@example.com" filetype:pdf
-Excludes a word"@example.com" -jobs -careers
before: / after:Pages last updated before or after a date"@example.com" after:2025

Don’t put a space between the operator and the search term. Useful patterns:

"Maya Okafor" "@example.com"
"@example.com" site:example.com
"@example.com" filetype:pdf
"@example.com" -jobs -careers

Searching for "@example.com" alone, without a name, is often the fastest way to learn the company’s address format, even if the person you want doesn’t show up.

6. GitHub and open-source commits (with an ethics note)

Every Git commit records an author name and email address. GitHub notes that the address you set in Git “will be visible in any future commits you push to GitHub from the command line” (GitHub Docs: setting your commit email address). Many developers therefore commit with a GitHub-provided noreply address instead of their own, in the form ID+USERNAME@users.noreply.github.com (GitHub email addresses reference).

Ethics note: a commit address was published so that people can attribute and discuss code, not so that it ends up in a sales sequence. GitHub’s Acceptable Use Policies say you may not use information from GitHub, “whether scraped, collected through our API, or obtained otherwise”, for spamming, “including for the purposes of sending unsolicited emails to users” (GitHub Acceptable Use Policies, section 7). Use a commit address only to contact someone about their project. If they commit with a noreply address, take that as a sign that they don’t want to be emailed, and use the project’s issue tracker or discussion forum instead.

7. WHOIS: mostly redacted since GDPR

Domain registration records (WHOIS) used to list the owner’s name and email address. Since the GDPR took effect, they mostly don’t:

So a WHOIS lookup today usually gives you a relay address or a web form, not the owner’s email. That relay is still a legitimate way to reach a domain owner about the domain itself, for example to ask about buying it. Look up a domain with ICANN’s own registration data lookup.

8. Ask a mutual contact or the company

The slowest method is often the most effective one:

None of these needs a tool, and all of them come with permission built in.

How to find someone’s email address by name only

With only a name, every method above gets harder, because the company domain is what makes them work. Find the employer first: search the name together with a job title, a city or an industry, and look for a professional profile, a team page or a conference program that says where the person works. Once you know the company, you’re back to methods 1 to 3.

Personal addresses at Gmail, Outlook.com or Yahoo are a different matter. They follow no company pattern, so there’s nothing to derive the address from, and verification doesn’t help either: a Gmail address made from Maya Okafor’s name may well exist and belong to a different Maya Okafor. The only reliable sources for a personal address are the person themselves, someone who knows them, or a page where they published it. The emailvalidation.io email finder doesn’t look for personal addresses: it finds work addresses at a company domain and is not a people search.

Worked example: finding a work email step by step

A fictional case: you want to reach Maya Okafor, head of procurement at a logistics company whose website is example.com.

Step 1: Confirm the email domain. The website is example.com. In this fictional case, an MX lookup of the domain shows mail servers. If a real company’s website domain has none, the company sends and receives mail on another domain, often visible in the footer of its press releases.

Step 2: Try the email finder. Enter Maya, Okafor and example.com in the email finder. If it returns an address that isn’t marked as risky, you’re done, at a cost of 10 credits. A risky result on a catch-all domain is only the most common pattern, so check it against the format you find in step 3.

Step 3: Find the format by hand. Search Google for "@example.com" site:example.com. Suppose a press release ends with “Media contact: Daniel Reyes, daniel.reyes@example.com”. That suggests the format first.last, so Maya’s address is probably maya.okafor@example.com.

Step 4: Generate and verify the candidates. Put Maya Okafor and example.com into the email permutator and paste the list into the bulk email verifier. If the server accepts maya.okafor@example.com and rejects the others, you have the address, and it matches the format from step 3.

Step 5: Handle a catch-all result. If every candidate is accepted, the domain is probably catch-all. The API can confirm it: with catch_all=1 (paid plans from Small) a catch-all domain comes back with catch_all: true. In that case, go with the format you found in step 3, send one personal message, and watch for a bounce.

Verify before you send

Whatever method you used, check the address before you write to it. Addresses found on the web are often outdated: the person changed jobs, the company changed its format, or the address was a typo to begin with. A bounce costs you more than the check:

For outreach at volume, the rules in the email deliverability guide apply as well: authenticate your domain, keep volumes low, and remove addresses that bounce.

Finding an address is one question; writing to it is another. The rules depend on where the recipient is and why you write. The following is a summary of the official sources, not legal advice.

In the European Union (GDPR and ePrivacy):

In the United States (CAN-SPAM):

The practical rule that keeps you safe almost everywhere: write to one person at a time, about something relevant to their job, say who you are and how you found them, and stop at the first “no”.

Sources

Checked October 9, 2026: Google: Refine web searches; GitHub Docs: setting your commit email address and email addresses reference; GitHub Acceptable Use Policies; ICANN Temporary Specification for gTLD Registration Data; ICANN Registration Data Policy; European Commission: What is personal data?; GDPR (Regulation (EU) 2016/679); ePrivacy Directive 2002/58/EC; FTC CAN-SPAM Act: A Compliance Guide for Business.

Stop bounces before they happen

Most hard bounces come from addresses that don't exist. An email verification asks the receiving server about the mailbox without sending anything, so you can remove bad addresses before your next send.

Frequently asked questions

How can I find someone's email address for free?

Look on the company website (team, press and blog pages), search Google with operators such as site: and quotes, check the person's own website or public profiles, or guess the address with the free email permutator and verify the candidates. The emailvalidation.io free plan includes 100 credits a month, enough for 10 email finder searches.

How do I find a work email address?

Find the company's email domain (usually its website domain), then either enter the person's name and the domain in an email finder, or work out the company's address format from addresses published on its website and verify the address that format gives you.

Can I find an email address by name only?

Rarely. A name alone matches thousands of people and there is no public directory of email addresses. With a name and the company the person works for, finding a work address is usually straightforward, because company addresses follow a fixed pattern.

Is it legal to email someone I found online?

It depends on where the recipient is and why you write. In the US, CAN-SPAM allows commercial email without prior consent if it is honest, includes a postal address and offers an opt-out. In the EU, the GDPR applies to any address that identifies a person, and marketing email to individuals generally needs prior consent. This is not legal advice.

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

/v1/info Email validation API Read the documentation

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "user": "support",
  "tag": "",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "catch_all": null,
  "role": true,
  "disposable": false,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox",
  "did_you_mean": ""
}

Keep reading

Start using our email validation software today!

Get 100 validations per month for free