How to find someone's business email address

How to find someone's business email address: company pages, email patterns, search operators and finder tools, then how to check it before you send.

  • #sales
  • #b2b
  • #business-email
Three steps: find a likely address like jane.doe@acme.io, check that acme.io is a company domain that receives mail, then send one email. 1 Find jane.doe@acme.io team page, pattern, or just ask 2 Check acme.io company domain receives mail 3 Send one relevant email easy opt-out

To find someone’s business email address, start with public sources: the company’s website, its press releases and the person’s own published work. If the address isn’t listed, work out the company’s email pattern from addresses that are (for example first.last@acme.io), confirm it with a search or an email finder tool, or simply ask someone who knows. Before you send, check that the domain is a real company domain that receives mail, and send one relevant message rather than a sequence.

One thing to be clear about up front: isBusinessEmail doesn’t find email addresses, and it doesn’t verify that a mailbox exists. It tells you what kind of address you already have, which is the checking step near the end of this post.

Start with the right person and the right domain

Before you search, pin down three things:

  1. The person’s full name, as they use it at work. “Kate” or “Katherine” changes the pattern, so check a company bio or a conference talk.
  2. Their current employer. People change jobs, and an address from an old press release may be dead.
  3. The company’s email domain. It’s usually the website domain, but not always. A company on acme.com might send mail from acmecorp.com, regional teams may use acme.de, and acquired brands keep their old domains for a while. Look at any address published on the company’s site, or check the domain with the MX lookup tool: a domain with no MX records doesn’t receive mail. How to find out which email provider a company uses explains how to read the result.

Also ask whether you need this person’s inbox at all. For a press inquiry, a partnership or a support issue, the published press@, partners@ address or contact form is often the route the company wants you to use, and someone actually triages it.

Method 1: Check the company’s website

Companies publish more addresses than you might expect. Look at:

  • Team, about and leadership pages. Smaller companies often list direct addresses.
  • Press and media pages. Press contacts are usually named people with direct addresses, which also reveals the pattern.
  • Blog author bios and newsletters.
  • Careers pages and job listings, such as “send your portfolio to …”.
  • Legal pages. Privacy policies often name a data protection contact, and in Germany the legally required Impressum must include an email address.
  • PDFs: brochures, reports, slide decks and price lists.

Even if the person you want isn’t listed, every address you find tells you something about the company’s pattern.

Method 2: Work out the email pattern

Most companies generate addresses from a fixed format. With two or three real addresses from the same domain, you can usually predict the rest.

Pattern Jane Doe at acme.io
first.last jane.doe@acme.io
first jane@acme.io
flast jdoe@acme.io
firstl janed@acme.io
first_last jane_doe@acme.io
f.last j.doe@acme.io
last.first doe.jane@acme.io
Jane Doe at acme.io with five candidate addresses; two known addresses, tom.lee@ and ana.ruiz@, show the pattern is first.last, which selects jane.doe@acme.io. JD Jane Doe acme.io Common patterns jane.doe@acme.io jane@acme.io jdoe@acme.io janed@acme.io doe.jane@acme.io Known addresses tom.lee@ ana.ruiz@ pattern first.last
Known addresses reveal the pattern; apply it to the name

To do it well:

  1. Collect known addresses from the same domain, using Method 1 and Method 3.
  2. Match them to names. tom.lee@ and ana.ruiz@ both say first.last.
  3. Apply the pattern to your person, then allow for the usual exceptions: duplicate names (jane.doe2@), hyphenated or double surnames, accented letters (józef usually becomes jozef), nicknames, and early employees who kept a short jane@.
  4. Commit to one well-supported guess. Sending to every variant produces bounces, and bounces hurt your sending reputation with every mailbox provider.

Very small companies often use first names only, while larger ones need a format like first.last that avoids collisions. Treat that as a hint, not a rule.

Method 3: Search engines and public sources

Search engines index addresses that appear on public pages. A few operators narrow things down:

"@acme.io"                              pages that mention addresses on the domain
site:acme.io "@acme.io"                 addresses on the company's own site
"jane doe" "@acme.io"                   the person and the domain together
site:acme.io filetype:pdf "@acme.io"    addresses inside the company's PDFs

Other public places worth checking:

  • Press releases and news wires, which often name a media contact.
  • Conference and webinar pages, podcast show notes and guest posts.
  • Academic papers and technical standards, which list authors’ contact addresses.
  • The person’s own website or newsletter, where they may say how they prefer to be contacted.

LinkedIn

LinkedIn is the best place to confirm someone’s current role, exact name and employer. It isn’t a source of email addresses unless the person chooses to share one with their connections. Use it to confirm details and to message them directly. Don’t use scraping tools or browser extensions that harvest profile data: LinkedIn’s User Agreement prohibits scraping, and it can get your account restricted.

GitHub and other developer sites

Commits in public repositories can contain the author’s email address, which is why many developers use GitHub’s private noreply address instead. Even when an address is visible, GitHub’s Acceptable Use Policies prohibit using information from the service, including email addresses, to send unsolicited email. To contact a developer, use the channels they publish, such as a website or a contact link on their profile.

Method 4: Email finder tools

Email finder tools automate Methods 1 to 3. You enter a name and a company or domain, and the tool combines addresses it has seen on public pages with the company’s inferred pattern, often adds a mailbox check, and returns a likely address with a confidence score or status. Well-known options include Hunter, Apollo, RocketReach, Lusha and Snov.io, and many sales platforms and CRMs include a finder too.

What to look for when you choose one:

  • Sources. Can you see where and when an address was found?
  • A status you can act on. “Valid”, “accept-all” (a catch-all domain that accepts every address) and “unknown” mean very different things.
  • Data protection. Does the vendor explain where its data comes from, let people opt out of its database, and offer a data processing agreement?

However confident it looks, a finder’s answer is still a guess. Treat it like a pattern you worked out yourself, and check it before you send.

Method 5: Ask

The most reliable way to get someone’s work address is to have someone give it to you:

  • A mutual contact can introduce you by email, which also gets you a warmer reply.
  • The company’s front desk or general inbox will often forward your message or tell you who handles your topic.
  • A direct message on LinkedIn or another network, asking for the best address to send details to.
  • In person. If you meet at an event or on a call, ask then.

An address someone gave you is accurate, current and comes with permission to use it, which no search can promise.

Check the address before you send

Whatever method you used, there are two separate questions: is this a real company address, and does this exact mailbox exist? They need different checks. Email verification vs email classification covers the difference in depth.

Two cards. A classification check tells you acme.io is a company domain, it receives mail, it isn’t disposable or a relay, and whether it’s a role inbox. It can’t tell you whether jane.doe@ exists, whether Jane works there, or whether she expects your email. Tells you acme.io is a company domain It receives mail Not disposable or a relay Role inbox or a person Doesn't tell you jane.doe@ exists Jane still works there She expects your email
A classification check covers the address and its domain, not the person

1. Classify the address

This is the part isBusinessEmail does. Paste an address into the checker on the homepage or the free email provider checker, upload a list to the bulk email checker with a free account, or call the check endpoint. The API response includes:

Field What it tells you
category business, personal, disposable, relay, education, government, invalid or unknown
mail.has_mx Whether the domain can receive mail at all
did_you_mean A suggested fix when the domain looks like a typo of a popular provider
is_role_account Whether it’s a role inbox like info@ or sales@ rather than a person
workspace.google_workspace.detected, workspace.microsoft_365.detected Whether the company runs Google Workspace or Microsoft 365

How to read it:

  • business means the domain is the company’s own and receives mail. It doesn’t confirm the person works there.
  • personal means a shared provider such as Gmail. It may still be the right person, but it’s their private inbox, and stricter rules apply to marketing email sent there (see below).
  • invalid or disposable: don’t send. An invalid domain can’t receive mail at all.
  • unknown: a custom domain with little evidence, such as a very new, parked or forwarding-only domain. Look at the company’s website before you rely on it.

For a list in code, de-duplicate it and use the batch endpoint, which takes up to 100 addresses or domains per request. isBusinessEmail never stores full addresses, only domains plus a keyed hash of the local part; details are in privacy and data.

2. Confirm the mailbox, if you need to

Classification can’t tell you whether jane.doe@ exists. Email verification services try to answer that, usually by asking the receiving mail server whether it would accept the address, without sending a message. It works on some domains and not on others: catch-all domains accept every address, and many large providers and security gateways don’t give a straight answer, so expect some “unknown” results. isBusinessEmail deliberately doesn’t do this kind of probing.

3. Let the first message confirm it

For one-to-one outreach, the simplest confirmation is the email itself. Send one short, relevant message. A hard bounce means the address is wrong, so remove it rather than trying variants in quick succession. A reply confirms it. Silence tells you nothing, so don’t follow up endlessly.

Ethics and compliance

Finding an address doesn’t make every use of it acceptable. This is general information, not legal advice; check the rules that apply where you and the recipient are.

Privacy law

  • A work address is personal data. jane.doe@acme.io identifies a person, so under the GDPR you need a lawful basis to collect and use it. For B2B outreach that’s usually legitimate interests, which means weighing your interest against the person’s rights and reasonable expectations.
  • Say where you got it. When you collect personal data from somewhere other than the person, Article 14 GDPR requires you to tell them who you are, why you’re processing it and where it came from, at the latest in your first message if you use it to contact them.
  • Stop on request. People can object to direct marketing at any time, and then you must stop using their data for it. Keep a suppression list so the next import doesn’t add them back.

Email marketing rules

  • EU and UK. National rules decide whether you may send unsolicited marketing email at all. Sending to individuals generally needs prior consent, and some countries are strict about business addresses too.
  • United States. CAN-SPAM covers all commercial email, including business-to-business. It doesn’t require prior consent, but it does require accurate sender and header information, honest subject lines, identifying the message as an ad, a valid postal address, a clear way to opt out, and honoring opt-outs within 10 business days.
  • Canada. CASL generally requires consent. A narrow exception covers an address someone has conspicuously published without saying they don’t want messages, when your message relates to their role.

Terms of service and good practice

  • Don’t scrape sites whose terms forbid it, including LinkedIn, and don’t harvest addresses from GitHub commits.
  • Don’t probe mail servers yourself to find out which guess exists. It amounts to user enumeration, mail providers block it, and it can get your servers blocked too.
  • Don’t load guessed addresses into automated sequences. Write to one person, say who you are and why you’re contacting them, and make opting out easy.
  • Record where every address you keep came from.

Next steps

  1. Pin down the person, their current employer and the company’s mail domain.
  2. Find a published address, or derive the pattern from two or three known ones.
  3. Classify it with the free email provider checker or the API, and fix anything invalid or mistyped.
  4. Send one relevant message that says where you got the address and how to opt out.
  5. For lists, check domains in bulk and keep the data clean over time, as described in CRM hygiene.

If you’re qualifying inbound leads rather than looking for addresses, see B2B lead qualification and lead scoring by email domain.

Frequently asked questions

How do I find someone's work email address for free?

Check the company's website, press releases and the person's own published work, then work out the company's email pattern from two or three addresses you can find. Search operators such as site:acme.io help, and asking a mutual contact or the company's general inbox often works best.

What is the most common business email format?

Widely used formats include first.last, first name only, and first initial plus last name, such as jdoe. The only reliable way to know a company's format is to look at a few real addresses from that company.

Can isBusinessEmail find an email address for me?

No. isBusinessEmail doesn't find addresses or verify mailboxes. It tells you whether an address you already have is a work or personal address, disposable, a relay or invalid, and whether the company uses Google Workspace or Microsoft 365.

How can I check if a business email address is real?

First check that the domain is a real company domain that receives mail, with an email classification tool or an MX lookup. Mailbox verification services can sometimes confirm the exact address, but catch-all domains accept everything, so a reply is the only certain confirmation.

Is it legal to email someone at their work address without consent?

It depends on where the recipient is. In the US, CAN-SPAM allows it if you follow its rules, such as a working opt-out and a postal address. In the EU and UK, national rules vary and some require consent, and the GDPR applies because a work address identifies a person.

Can I take email addresses from LinkedIn or GitHub?

Use LinkedIn to confirm someone's role and to message them, not to scrape addresses, which its User Agreement prohibits. GitHub's Acceptable Use Policies prohibit using information from the service, including email addresses, to send unsolicited email.