You've found the right prospect, read their LinkedIn profile, checked the company's latest announcements, and drafted a message that fits their role. Then you reach the practical obstacle: the person's email address isn't visible anywhere obvious.
Learning how to get the email address of a person isn't only about locating a string that looks plausible. A useful workflow must identify the right business address, verify that it can receive mail, respect privacy rules, and determine whether the contact is worth messaging at all. The methods below move from manual research to scalable discovery, then from verification to compliant, relevant outreach.
Why Finding the Right Email Still Matters in 2026
A sales representative can spend considerable time researching a target account and still be blocked by one missing detail, a direct email address. LinkedIn may show the prospect's title and company, while the company website confirms the department, but neither necessarily provides a usable route to the individual. A generic contact form may disappear into a queue, and a social message can be overlooked among other notifications.
Email remains embedded in professional communication at extraordinary scale. The Radicati Group projects that worldwide email users will exceed 4.7 billion by the end of 2026, while business and consumer traffic is forecast to pass 392 billion messages per day in that same year. Those figures are projections from the Radicati Group email statistics report, not a guarantee that every prospect prefers unsolicited email. They do explain why a valid professional address remains a practical identifier across sales, recruiting, partnerships, and B2B operations.
The scale creates an important trade-off. A target person is likely to have an active inbox, but a guessed address can also create unnecessary bounces when multiplied across a list. Finding an address and proving that it's usable are separate jobs.
Practical rule: Treat email discovery as a workflow, not a lookup trick. The address should be relevant, verifiable, documented, and appropriate for the message you plan to send.
Start with public business information, use naming patterns only as hypotheses, and apply an independent verification step before importing contacts into a CRM or sequence. The strongest process also asks a harder question: even if the address is valid, does this person have a reason to respond?
Manual Methods for Finding Any Email Address
Manual research still works when you know where to look and how to narrow the search. Begin with the person's full name, employer, role, and company domain. A domain is more useful than a company name alone because it removes similarly named businesses from the results.
Search the company's public footprint
Use Google operators to search pages that may contain published business addresses:
site:company.com "Jane Smith"site:company.com intext:"@" "Jane Smith"site:company.com "Jane Smith" emailsite:company.com filetype:pdf "Jane Smith"site:company.com "Jane Smith" contact
The site: operator restricts results to the company domain. The intext:"@" variation looks for pages containing the email symbol, while filetype:pdf can surface conference documents, reports, media kits, or public filings. Search the person's name in quotation marks when common names produce unrelated results.
Company websites deserve a methodical review. Check the About, Contact, Leadership, Press, and author pages. Blog bylines can reveal how the organization formats employee addresses, even when the specific prospect's address isn't published. Public directories and event pages may also contain business contact details, but availability doesn't automatically establish permission for every type of outreach.

Infer patterns, then label the result as unconfirmed
Suppose a public address shows a format such as firstname.lastname@company.com. That pattern can help you form a possible address for another employee, but it doesn't prove the mailbox exists. Companies may use different formats for subsidiaries, acquired teams, contractors, or senior executives.
Look for several known addresses from the same domain before relying on a pattern. Compare names with initials, shortened first names, hyphens, and middle names. If the evidence is mixed, keep the contact in a low-confidence queue rather than treating the guess as ready for sending.
LinkedIn can help confirm identity, role, and employer. Review the profile's Contact Info area, featured material, posts, and links to personal websites. Don't scrape private information or assume that a visible profile grants permission for unrelated marketing.
For a practical reference on combining public research with verification, see this guide to finding valid email addresses for outreach. If you need a deeper walkthrough focused specifically on name-based research, use the guide to finding email addresses by name.
Scaling Discovery with EmailScout Chrome Extension
Manual searches are useful for a handful of contacts, but they become repetitive when you're building an account list. A browser extension can reduce copying and switching between tabs, provided you still review the source and verify the result afterward.
EmailScout's Chrome workflow is built around pages you're already visiting. Install the extension from the Chrome Web Store, sign in if required by your plan, and open a company website, search result, directory page, or public professional profile. The extension can display email addresses associated with the domain or page and lets you save results for later list cleaning.

Configure collection before browsing
The useful setting for passive research is AutoSave. Enable it when you want addresses discovered during normal browsing to be collected without manually saving each result. Use it selectively during a defined research session, then export the list and remove duplicates, generic inboxes, irrelevant domains, and contacts outside your target market.
URL Explorer handles a different job. Give it a list of public URLs, and it can scan those pages to extract available email addresses in bulk. This is helpful when a target account has multiple offices, team pages, author archives, or resource pages. It's also a reason to keep source URLs in your working sheet, since the page context helps you judge whether an address is a relevant business contact or an incidental mention.
For broader discovery, adjust a Google results URL so the parameter that displays ten results, num=10, becomes num=100. This changes the number of visible results in a page, which can give the extension more public pages to inspect during one session. It doesn't make every result relevant or every address valid, so use filters rather than collecting indiscriminately.
A focused query might combine a profession, location, and domain:
"account executive" "Toronto" "@company.com""head of partnerships" "Berlin" "@company.com"site:company.com "marketing" "@company.com""Jane Smith" "company.com"
The @gmail.com filter may help locate publicly listed independent professionals, but it requires extra care. For B2B prospecting, a company-domain address generally gives clearer business context than a personal mailbox. Save the person's name, role, company, source page, discovery method, and confidence status alongside the address.
A short product walkthrough can help you understand the EmailScout Chrome extension workflow. Use the video after you've reviewed the setup and collection logic, so the interface fits into a process rather than replacing one.
The extension can accelerate discovery, but it shouldn't be treated as a compliance or deliverability decision-maker. Keep discovery, validation, and campaign approval as separate stages.
Verifying Emails Before You Hit Send
Pattern-generated emails often look correct but fail delivery checks, while catch-all domains can accept messages for nonexistent or unmonitored mailboxes. Sending those contacts immediately raises bounce risk and can weaken the reputation of your sending domain.
An independent 2026 comparison of email-finding tools reported accuracy ranging from 81.3% to 93.2%, coverage from 72.6% to 88.2%, and bounce rates from 1.2% to 7.2%. The figures in the email finder accuracy benchmark show why discovery output needs a separate deliverability check before it enters a sequence.
Use confidence categories instead of one blended list
Classify every contact before adding it to your CRM:
- Verified: The address passes a deliverability check and matches the intended person and company.
- Risky: The domain is catch-all, the address is inferred from a pattern, or the verifier cannot establish a strong result.
- Rejected: The address is invalid, disposable, unrelated to the target, or tied to a role that no longer fits the account.
A deliverable mailbox can still be a weak prospect. Verification addresses mailbox risk, while role fit, buying authority, timing, and permission require separate fields. Keeping those judgments apart prevents a technically valid address from receiving an inflated quality score.
The email finder benchmark workflow recommends counting a find only after deliverability checks, rather than when a tool generates or matches an address. It also identifies bounce rates below about 2% as the target for protecting sender reputation. Treat that figure as an operating threshold, not a guarantee for every campaign.
Before sending, run the final list through an email validation service, remove duplicates, and quarantine catch-all results. The EmailScout email validation page can support this review stage. Record the validation date and result regardless of which validator you choose.
| Metric | Low End | High End | Operational Target |
|---|---|---|---|
| Accuracy | 81.3% | 93.2% | Confirm individually |
| Coverage | 72.6% | 88.2% | Prioritize relevant contacts |
| Bounce rate | 1.2% | 7.2% | Below about 2% |
Never upload an unreviewed export directly into automated sequencing. A smaller clean list protects deliverability and usually produces better reply economics than a larger file filled with guesses. Review risky records manually, then message only contacts whose address, role, and business relevance support the outreach.
Staying Compliant with Privacy Regulations
Public visibility doesn't equal unrestricted permission. A business email address linked to an identifiable person can still be personal data under GDPR, even when it uses a company domain rather than a private provider.
The GDPR took effect in the European Union on 25 May 2018. Its enforcement history includes multibillion-euro penalties across the EU, demonstrating that organizations can face serious consequences when they handle personal data casually. The practical framework involves lawful basis, purpose limitation, transparency, data minimization, and record-keeping.
Separate collection from lawful use
Collecting a work address from a company leadership page is materially different from scraping a private account or assembling personal contact data unrelated to the person's professional role. Even public business information needs a reason for collection and a documented use case.
For B2B outreach involving EU or UK audiences, legitimate interest may be available in appropriate circumstances, but it isn't a blanket exemption. The sender should assess whether the message is relevant to the person's role, whether the individual could reasonably expect the contact, and whether the sender's interests are balanced against the person's privacy rights.
Maintain a simple record for every contact:
- Source: The page, directory, or business context where the address was found.
- Purpose: The specific professional reason for contacting the person.
- Basis: The lawful basis your organization is relying on.
- Identity: Your company and the sender's identity.
- Control: A clear, functional opt-out process and suppression record.
Compliance principle: A findable address is not automatically a lawfully usable address.
Identify yourself in the message, explain why the contact is relevant, and make opting out straightforward. Don't disguise a sales email as a personal note, continue contacting someone after an objection, or retain data indefinitely without a business reason.
For teams that need a broader checklist, Formbricks offers a comprehensive GDPR guide for 2025. Treat it as general guidance, then confirm requirements with qualified privacy counsel for your jurisdiction and campaign model.

Compliance can slow collection because teams must document sources and review use cases. That friction is useful. It prevents public data from being mistaken for unrestricted data and gives your team a defensible process when a prospect asks how you obtained their address.
Turning Found Emails into Actual Replies
A verified mailbox only gives you permission to attempt a conversation. It doesn't make the message relevant, timely, or valuable.
One industry report places the average cold email reply rate at 4.1% in 2025, meaning 96% of cold emails go unanswered, as reported in the cold email comparison from Hunter. The lesson isn't to abandon email. It's to stop treating list size as the main performance lever.
Before sending, ask three questions:
- Does this person own or influence the problem?
- Does the message connect to something specific about their role or company?
- Can the recipient understand the value without doing research for you?
A verified address for the wrong department is still a poor target. A senior decision-maker with no current need may be less responsive than a closer operator who has publicly discussed the problem. Relevance and personalization matter more than filling a sequence with every address you can find.
Use a small, carefully reviewed campaign first. Check whether replies reveal genuine interest, confusion, wrong-person referrals, or immediate objections. Then refine the audience and message before expanding. Your complete workflow should look like this: discover from a legitimate business context, verify deliverability, document the source and basis, assess role fit, and send a concise message with a clear reason to respond.
EmailScout can help you discover addresses from company websites, search results, profiles, and batches of public URLs, then save the findings for review before validation and outreach. Visit EmailScout to explore the extension and build a cleaner path from email discovery to relevant, compliant conversations.
