To find someone's work email, start with their full name and company domain. Check an intentionally published professional contact page or LinkedIn Contact info, then generate likely company-address patterns and verify the result before sending. Overloop's free pattern finder ranks candidates and checks whether the domain can receive mail; it does not confirm that a specific mailbox exists. The 17 methods below explain what each source can and cannot prove.
To find someone's work email, combine their full name with the company domain. Check an intentionally published professional contact first. If none is available, generate likely company patterns, validate the domain, and use a mailbox-level verifier when you need stronger evidence before sending. A candidate address, a mail-ready domain, and a confirmed mailbox are three different results.
Disclosure: Overloop publishes this guide and sells prospecting and outbound software. The free tools linked here are separate from the paid platform. We include Overloop where it fits and state what each tool can and cannot verify.
The short answer
- Use a professional address the person or company deliberately published whenever possible.
- A full name plus company or domain is usually enough to generate plausible work-email patterns; a name alone is not.
- DNS and MX checks show whether a domain is configured for email. They do not prove that a named mailbox exists.
- Choose a pattern generator, contact database, or mailbox verifier according to the result you actually need.
- Record the source and intended use before outreach. Finding an address does not create blanket permission to email it.
Which email-finding method should you use?
The best method depends on both your input and the evidence you need. Do not treat every result labelled “valid” as equivalent.
| Starting point | Method | What you get | What it does not prove |
|---|---|---|---|
| Name + company website | Team, press, or contact page | An intentionally published work contact | Permission for every marketing purpose |
| Name + domain | Pattern generator | Ranked candidate addresses | That any candidate mailbox exists |
| Company domain | Domain-search database | Addresses associated with the company | That every record is current or suitable |
| Candidate address | Syntax and DNS check | Format and domain mail readiness | Mailbox ownership or deliverability |
| Candidate address | Mailbox-level verification service | A provider-specific status such as valid, invalid, catch-all, or unknown | Future delivery, consent, or recipient interest |
| No reliable public signal | Ask the person | Their preferred contact route | Nothing beyond the purpose they agreed to |
17 ways to find someone's work email
1. Guess the company's email pattern
Companies often apply one address format across a domain. Common candidates include firstname.lastname@company.com, firstname@company.com, and flastname@company.com. Look for an address the company has already published for another employee, identify its structure, then apply that structure to the person you need.
Use this as candidate generation, not verification. Names with accents, compound surnames, aliases, subsidiaries, or duplicate employees can change the pattern. The free email pattern finder automates the permutations and ranking.
2. Search the web with precise operators
Search engines can surface professional contact details that a person or company intentionally placed on a staff page, conference biography, PDF, or partner page. Queries such as "First Last" "@company.com", site:company.com "First Last", or site:company.com contact narrow the result set.
Open the source and check its date and context. Do not use addresses from exposed lists, cached private documents, data breaches, or pages clearly published by mistake.
3. Check LinkedIn Contact info
On the person's LinkedIn profile, open Contact info. An email may appear when the member has chosen to share it with you. This is a stronger signal than an inferred pattern because the address came from the account holder, but it may still be old or intended only for existing connections.
Use LinkedIn's normal interface and respect the context in which the detail was shared. Do not automate profile scraping or bypass access controls.
4. Review your own LinkedIn data export
LinkedIn lets members download a copy of their account data. Your connections export can include email addresses that connections elected to share under LinkedIn's settings. Many rows will have no email, and an exported address is not automatically permission for a new campaign.
This method is appropriate for checking your own relationship data. It is not a route to another person's account export or a justification for buying exported lists.
5. Check the company website
Review the company’s Team, About, Contact, Press, Investor Relations, and author pages. Smaller organizations may publish individual work addresses; larger ones often provide a role address or contact form. A role address can be the better choice when your request matches that team's remit.
Use the contact in the published context. A privacy, security, abuse, or data-protection address is not a general sales inbox, and hidden page-source data should not be treated as intentionally published contact information.
6. Use a free email pattern finder
Overloop's free email finder takes a first name, last name and company domain. In your browser, it generates likely corporate address patterns, ranks the candidates and checks the domain's MX records through Google Public DNS. Bulk mode accepts up to 500 people and exports candidates to CSV.
It does not query a contact database, open an SMTP connection or confirm which mailbox exists. Use it when you need a transparent shortlist from known inputs, then decide whether a mailbox-level check is warranted. Generate candidates with the free finder.
7. Search a domain with Hunter
A domain-search service such as Hunter Domain Search can return work addresses associated with a company domain, along with the source or confidence information the provider makes available. This is useful when you know the employer but are still identifying the right contact.
Review the underlying source, recency, role, and status instead of copying the first result. Vendor databases, quotas, and labels change, so confirm current behavior on the provider's own site.
8. Review public professional profiles
Consult the person's official biography, portfolio, author page, university profile, professional association page, or personal business site. Use a work address or contact link that was deliberately displayed for professional enquiries.
A social handle can also give you a direct way to ask for the correct channel. Avoid reconstructing private addresses from unrelated personal details.
9. Combine a permutator with domain checks
An email permutator produces possible addresses from a name and domain. A syntax or DNS checker can then remove malformed candidates and domains that are not configured to receive email. This is a useful free workflow, provided you keep its layers separate:
- Candidate: the address matches a plausible naming convention.
- Domain-ready: the domain publishes mail records.
- Mailbox status: a separate service attempts to assess the specific inbox.
The first two do not imply the third. Catch-all domains and privacy-conscious mail servers can also make mailbox-level results inconclusive.
10. Ask the person directly
Send a short message through a channel they use professionally: “What is the best work email for a brief question about X?” State the reason so they can choose whether and how to continue.
This is often the cleanest option when the contact is high-value, no professional address is published, or your request is sensitive. Their reply also removes ambiguity about the preferred address and context.
11. Use speaker and organizer contact pages
Conference sites may publish a speaker's business contact, company biography, or organizer route for event-related enquiries. Use only professional contact details deliberately published by the speaker, organizer, or company.
Do not use attendee-registration data, badge scans obtained for another purpose, or lists exposed by mistake. If the page offers only an organizer contact, ask the organizer to forward a relevant request.
12. Check press releases and official directories
Company press releases, official partner directories, government supplier listings, and professional associations sometimes include a named work contact. These sources can be useful when your message relates directly to the person's documented role.
Check that the listing is current and use the address only in the context for which it was published. Do not substitute WHOIS privacy, legal, or abuse contacts for a prospect's business email.
13. Check GitHub profiles and project contact pages
For developers and maintainers, use an email or contact link they deliberately published on a GitHub profile, personal site, project README, SECURITY.md, or support page. Match your message to the project or professional purpose stated there.
Do not mine commit metadata, patch files, or noreply addresses for unrelated outreach. Those fields can expose stale or personal data that was never presented as a contact channel.
14. Evaluate browser extensions carefully
Email-finder extensions can add a contact or domain lookup inside a company site, CRM, or professional network. Before installation, inspect the permissions, the provider's data sources, retention terms, supported sites, and whether use of the extension complies with the site you are visiting.
An extension's output may be a database match, an inferred pattern, or a verification status. Read the label and documentation before treating it as proof. Avoid tools that require broad access without a clear reason or automate prohibited scraping.
15. Use professional directories
Role-specific business directories, regulated-profession registers, official company listings, and association member pages can provide a relevant professional contact. Confirm that the person still holds the listed position and that your request fits the directory's purpose.
Do not use consumer people-search databases to uncover private home or personal email addresses for B2B outreach.
16. Ask within a professional community
If you meet someone in a work-related Slack, Discord, forum, or member community, ask which work address they prefer. A useful discussion in the community gives your request context and lets the person opt into moving the conversation to email.
Do not scrape member profiles, export contact data, or treat community membership as consent to an outbound list.
17. Use a newsletter reply or contact form
A company newsletter may have a monitored reply-to address, and a professional site may offer a contact form. Reply only when the channel invites responses and your note is relevant. Otherwise, use the form to ask for the right contact rather than guessing a personal inbox.
Subscribing to a newsletter does not create blanket permission to repurpose its sender details for unrelated marketing.
Email finder, database, and verifier: what is the difference?
“Email finder” is used for several different products. Compare the mechanism and output, not just the label.
| Tool type | Required input | Output | Best use |
|---|---|---|---|
| Pattern generator | Name + company domain | Likely address permutations | Transparent one-off or CSV candidate generation |
| Contact database / finder | Name, company, role, or filters | Stored or enriched contact records | Prospecting when you also need to identify people |
| Syntax and domain checker | Email address | Format, MX, and sometimes SPF/DMARC signals | Removing malformed addresses and non-mail domains |
| Mailbox-level verifier | Email address | Provider-specific mailbox, catch-all, risky, or unknown status | Stronger pre-send assessment when the provider can obtain a signal |
| Bulk/API workflow | CSV or application records | Results at scale with status fields | Repeatable enrichment with logging and review |
If Apollo is on your shortlist, our Apollo alternatives comparison covers the trade-offs beyond email finding.
How to find an email address by name
A name alone is rarely unique enough. Add the company name, company website, role, or city. Confirm the person's current employer on an official source, resolve the company's primary domain, then check a deliberately published contact before generating patterns.
If two people share the same name, do not choose based on the address that “looks right.” Match role and employer first, and ask directly when the identity remains ambiguous.
How to look up or search for an email address
A forward lookup starts with a person and company and tries to find a work address. A reverse email lookup starts with an existing address and tries to identify its public owner or context. Use the workflow that matches the data you already hold; neither should be used to uncover private contact details.
How to find someone's email for free
For a one-off lookup, combine the company website, LinkedIn Contact info, precise search queries, and the free pattern finder. Use the free verifier to remove malformed candidates and domains without mail records. These steps cost nothing, but they still may leave the specific mailbox unconfirmed.
For a list, bulk mode in the pattern finder accepts up to 500 name-and-domain rows. Keep the candidate ranking and validation fields in your export so the next reviewer can see what was inferred.
How to verify an email before you send
Verification is a ladder, not a single yes-or-no check:
- Identity: confirm the person, employer, and domain.
- Syntax: check the local part,
@, and domain format. - Domain: confirm that the domain publishes MX records and is configured for mail.
- Mailbox: when needed, use a reputable mailbox-level service and preserve statuses such as catch-all or unknown instead of forcing a “valid” result.
Overloop's free email verifier checks syntax, MX, SPF, and DMARC at the domain level. It also flags duplicates, common domain typos, disposable services, role accounts, and free providers. It accepts up to 10,000 addresses, shows the first 200 rows in the browser, and includes all processed rows in the CSV export. It does not connect to the recipient's mail server or confirm a mailbox.
Free or paid: choose by the missing evidence
| Need | Reasonable starting point | Move to a paid service when… |
|---|---|---|
| One known person | Published source + free pattern finder | You need a stronger mailbox signal or cannot resolve the domain |
| Several known people | CSV pattern generation + domain checks | Manual review becomes inconsistent or you need auditable statuses |
| Find people and contacts | Company research and official directories | You need role, company, geography, and enrichment filters together |
| Recurring product workflow | Manual test on representative records | You need an API, CRM sync, usage controls, and monitoring |
Run a small, documented sample before committing to a provider. Record match coverage, status mix, source transparency, false matches found in review, data-handling terms, and total cost for your actual workflow. Do not compare vendors using self-reported accuracy percentages as if they came from one controlled test.
Legal and privacy considerations
Finding an address and using it for marketing are separate activities. The applicable rules depend on the recipient's location and status, the address source, your purpose, and the communication channel. A publicly visible address is not blanket permission to use it.
Before outreach, confirm the rule that applies, use a relevant professional address, identify the sender, explain the source and purpose where required, provide a simple way to object or unsubscribe, and honor that choice. Retain only the data you need and secure it appropriately. This is general information, not legal advice.
- European Union: GDPR official text
- United Kingdom: ICO guidance on B2B marketing
- United States: FTC CAN-SPAM compliance guide
- Canada: CRTC guidance on CASL
A practical, auditable workflow
- Confirm the person's full name, current company, role, and primary company domain.
- Check official and intentionally published professional sources.
- Generate candidate patterns only when no direct contact is available.
- Validate syntax and domain-level mail records; discard impossible candidates.
- Use a mailbox-level service when the risk and volume justify it, and keep catch-all or unknown statuses intact.
- Document the source, date, result type, intended purpose, and applicable outreach rule.
- Send only relevant messages, identify yourself, and maintain a suppression list for objections and opt-outs.
Have a name and company domain?
Generate ranked work-email candidates in your browser, then check the shortlist for syntax and domain-level mail records. No signup. Neither tool claims to confirm the mailbox.
Generate candidates → Check a list →Frequently asked questions
How can I find someone's work email for free?
Confirm the person's current company and domain, check the company website and LinkedIn Contact info, then generate likely address patterns. Overloop's free finder ranks candidates and checks the domain's MX records. It does not confirm a specific mailbox.
Can I find an email address with only a name?
Usually not reliably. Add the person's current company, company domain, role, or another professional identifier. A name alone can match multiple people and domains, so confirm identity before generating an address.
Does the free email finder confirm that a mailbox exists?
No. It generates and ranks likely work-email patterns and checks whether the domain publishes mail records. It does not query a contact database, connect to an SMTP server, or confirm mailbox ownership.
How should I verify a candidate email address?
First confirm the person's employer and domain, then check syntax and domain mail records. If you need stronger evidence, use a reputable mailbox-level verifier and preserve catch-all or unknown results instead of treating them as valid.
Is it legal to find and use a work email?
Finding an address and using it are separate activities. Rules depend on location, recipient type, source, purpose, and channel. A public address is not blanket permission. Check the applicable rule, identify the sender, provide required information and an opt-out, and honor objections. This is not legal advice.
Can I use this workflow to find a personal Gmail address?
No. Do not use this workflow to uncover a private Gmail address. If a person has not published a contact channel for your purpose, ask them directly. For B2B outreach, use a relevant professional address.
What is the best way to find work emails in bulk?
Start with a CSV containing confirmed names and company domains, keep candidate and validation statuses separate, and manually review a representative sample. The free pattern finder accepts up to 500 rows; a paid database or API may be appropriate when you also need contact discovery, mailbox-level statuses, CRM sync, or recurring automation.
Methodology & sources
How this guide was reviewed
We reviewed each method for the information it requires, the output it can actually return, and the privacy risk it creates. For Overloop's free tools, we checked the current browser implementation against the descriptions on this page.
We did not run a controlled cross-vendor accuracy benchmark, so this guide does not publish comparative accuracy scores. Third-party prices, quotas and features change; verify them on the vendor's own site.