How to Find Someone’s Business Email Address (and What Guessing Actually Costs)
Guessing someone’s work email is easy. Guessing it right is not. We measured 1,917 attempts our own users made against real company domains: about one in four reached a live mailbox, and six sessions in ten finished without a single confirmed address.
This post covers where to look before you start guessing, which search operators genuinely narrow things down, what our data says about the patterns people try, and why a wrong guess costs more than the credit it burns.
Start with the two things you already know
Almost every method below needs the same two inputs: a person’s full name and the domain their company
uses for mail. The name is usually the easy part. The domain is where people go wrong, because the address on
the website is not always the address on the mailbox — a company can market itself at
acme.com and run mail through a domain it acquired years earlier.
The MX record settles it. It names the mail servers that accept mail for a domain, and it is public. A domain with no MX record at all is a warning sign worth checking before you spend anything, though it is not proof on its own — a server may still accept mail on the domain’s own address record. Our guide to how email verification works walks through the order these checks run in.
Look before you guess
A published address beats a guessed one every time, and published addresses are more common than people assume. Before generating a single candidate, check:
- The company’s own site. Team pages, author bylines, contact pages, careers pages.
Smaller companies often list individual addresses; larger ones list a
role-based address like
press@orsales@, which is a different thing with different rules. - Press releases and PDFs. Media contacts are published on purpose, and PDFs are frequently missed by people searching only web pages.
- Conference and event pages. Speaker profiles and programme committees regularly carry a direct address.
- Code repositories. Public commit history records the author address of every commit. If the person you want writes code, their work address may already be in a public log.
- Academic and industry papers. Corresponding authors publish a contact address as a condition of publication.
- Domain registration records. Worth a look, though registrant contact details are frequently redacted behind a privacy service.
Search operators that narrow it down
Search engines will find published addresses if you ask precisely. These are the queries worth running before you fall back on patterns:
site:acme.com "@acme.com"— addresses published anywhere on the company’s own site."Jane Porter" "@acme.com"— the person and the domain in the same document.filetype:pdf "@acme.com"— press kits, reports and slide decks.site:linkedin.com/in "Acme" "Head of Partnerships"— to confirm the person, the spelling of their name and that they still work there.
That last check matters more than it looks. A perfectly formatted guess aimed at someone who left the company eight months ago is not just a wasted credit — abandoned mailboxes are one of the routes an address becomes a spam trap.
The patterns people actually try
When nothing is published, most people fall back on a handful of shapes. For Jane Porter at
acme.com:
jane@acme.com— first name onlyjane.porter@acme.com— first name, dot, last namejporter@acme.com— first initial joined to last namej.porter@acme.com— first initial, dot, last namejanep@acme.com— first name, last initialporterj@acme.com— last name, first initial
Generating the list is free. Finding out which one is real is where the cost sits, and that is the part we can measure.
What 1,917 guesses taught us
We looked at every verification run through ClearBounce between 20 June and 19 August 2026 — 6,167 checks in total. From those we isolated what a guessing session looks like: the same user checking two or more different addresses at the same company domain within thirty minutes. Free mailbox providers such as Gmail and Outlook were excluded, since patterns do not apply there.
That gave us 548 sessions and 1,917 individual attempts. The results:
26.8% of guesses reached a live mailbox
Sessions averaged 3.5 attempts. In 334 of the 548 sessions — 60.9% — not one attempt came back deliverable.
ClearBounce verification data, 20 June – 19 August 2026. Business domains only.
We also looked at the shape of the addresses that did come back deliverable, across 2,102 business addresses:
| Shape of the part before the @ | Example | Share |
|---|---|---|
| Single word, eight characters or fewer | jane or jporter |
67.2% |
| Two words joined by a dot | jane.porter |
21.8% |
| Longer single word | janeporter |
8.7% |
| Underscore or hyphen | jane_porter |
1.4% |
| Contains a digit | jporter2 |
0.9% |
Three limits on how far you should push these numbers. They describe addresses ClearBounce users chose to
check, not a census of the internet. A session is inferred from timing, so some of those 548 will be routine
list checks rather than someone hunting for one person. And we classify by the text before the @, not by
matching it against the person’s real name — we do not hold the names — which is why
jane and jporter sit in the same row.
What the table does support is an order of attack. Nearly nine in ten deliverable addresses were either a single word or two words joined by a dot; underscores and digits together accounted for 2.3%. Try the common shapes first and treat the exotic ones as a last resort.
The catch-all wall
Of the 334 sessions that never produced a deliverable address, 156 — 46.7% — hit at least one result marked risky. That is usually one thing: a catch-all domain.
A catch-all domain accepts mail for every address, real or not. Ask it about
jane.porter@acme.com and it says yes. Ask it about xyzq@acme.com and it says yes to
that too. No mailbox check can separate your six candidates on such a domain, because the server itself does
not distinguish them — which is why we return risky rather than valid. Our post on
catch-all emails explains what to do when you land on one.
This is the honest ceiling on pattern guessing. On a catch-all domain, more attempts buy you nothing but spent credits.
Why a wrong guess costs more than a credit
If you verify first, a wrong guess costs one credit. If you skip verification and send, the price changes shape. Mail to an address that does not exist comes back as a hard bounce, and mailbox providers read hard bounces as a signal about the sender, not the address. Enough of them and your sender reputation drops for every recipient, including the ones who asked to hear from you.
Guessed addresses carry a second risk. Abandoned mailboxes are sometimes recycled into spam traps, and hitting one costs far more than a bounce — the same reason buying an email list tends to end badly. If your numbers are already climbing, see why emails bounce and bounce rate.
A workflow that does not waste attempts
- Search first. Run the operators above. A published address needs no guessing and no credits.
- Generate candidates, do not fire them off. Write out the six shapes. Our email finder does this from a name and a domain, and searching costs nothing — you only spend a credit when you ask us to confirm one.
- Verify one at a time, highest confidence first. Stop at the first deliverable result. Checking all six when the second one was right is four credits you did not need to spend.
- Stop at a catch-all. If the first result comes back risky rather than valid, extra attempts will not resolve it. Reach the person another way.
- Re-check before a campaign, not just at capture. Addresses decay. Our guide to cleaning an email list covers the cadence.
If you do this often, the same checks run through our verification API, and you can run them from Claude or ChatGPT without leaving the conversation you are already having.
Is any of this legal?
Finding an address and being allowed to write to it are separate questions, and the answer depends on where your recipient sits. This is not legal advice.
Under the GDPR, a named person’s work address is personal data, so you need a lawful basis under Article 6(1) before you process it. Consent is one. The other one businesses lean on is legitimate interests, which the Regulation defines as processing that is “necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data”. That exception is a balancing test you have to actually perform, not a box to tick. Our GDPR and email marketing guide goes through it properly.
In the United States, CAN-SPAM works the other way round: it does not require prior consent for most commercial email. What it does require is that header information is not materially false or misleading, that the message is clearly identified as an advertisement, that it carries a valid physical postal address, and that it offers a working opt-out mechanism which you honour within 10 business days of the request.
What finding an address does not give you
A confirmed address tells you a mailbox exists and accepts mail. It does not tell you the person wants to hear from you, and no verification service — ours included — can tell you that. Deliverability gets your message to the inbox; whether it belongs there is your call, and complaints will find you faster than bounces do.
The same plainness applies to our own tool. The email finder returns candidates built from the name, the domain and published sources; until one is verified it remains a well-informed guess, which is why searching is free and only confirmation costs anything. Our pricing guide compares what that costs against the alternatives, and the current rates are on the pricing page.
At any real scale, the cheaper game is a list people joined deliberately — see building an email list and improving deliverability. Such a list barely needs guessing, though it brings its own problem in disposable addresses, which verification catches at the door.
Frequently asked questions
Is it legal to find someone’s business email address?
Finding a published address is generally not the problem; what you do next is. Under the GDPR a named person’s work address is personal data and you need a lawful basis under Article 6(1), such as consent or legitimate interests, and legitimate interests requires a balancing test against that person’s rights. In the United States, CAN-SPAM does not require prior consent for most commercial email, but it does require accurate headers, clear identification as an advertisement, a valid physical postal address and a working opt-out honoured within 10 business days. This is not legal advice.
Can I find an email address without any tool?
Often, yes. Search the company domain with an operator such as site:acme.com "@acme.com", check
team and press pages, and look in PDFs and public commit history. Published addresses cost nothing and carry
no risk of bouncing. Pattern guessing is the fallback for when none of that turns anything up.
Why does an address come back as risky instead of valid or invalid?
Usually because the domain is catch-all: it accepts mail for every address, so the server cannot confirm that one particular mailbox exists. In our data, 46.7% of the guessing sessions that never found a deliverable address hit at least one risky result. On a catch-all domain, more guesses will not resolve the question.
How many guesses should I make before giving up?
In our data, sessions averaged 3.5 attempts and 60.9% of them never produced a deliverable address. Verify candidates one at a time from the most likely shape and stop at the first deliverable result — or stop at the first risky one, because that points to a catch-all domain that further attempts cannot resolve.
Does a verified address mean it is safe to send?
It means the mailbox exists and accepts mail. It does not mean the person wants your message, and it does not create a lawful basis for sending it. Verification protects your sender reputation from bounces; it does not protect you from complaints.