How to Find a Company's Email Address: 8 Methods That Work
Eight ways to find a company's email address, from contact and legal pages to email patterns and finders, plus which addresses to use for B2B outreach.
By the Glintscout team10 min read
On this page
- Before you start: confirm the domain
- Method 1: Check the contact, footer, about and team pages
- Method 2: Read the legal pages
- Method 3: Search the domain with Google
- Method 4: Use the contact form, and get the address from the reply
- Method 5: Check social profiles and listings
- Method 6: Work out the email pattern
- Method 7: Check the domain's registration data (and why it rarely helps)
- Method 8: Use an email finder, then verify
- Which email address to use for B2B outreach
- Common mistakes
- FAQ
The fastest way to find a company's email address is its own website: the contact page, the footer, the about or team page and the legal pages hold most published addresses. If nothing is published there, check the company's social profiles, work out the email pattern its domain uses, and verify any address you find or guess before you send to it.
Which address you should use depends on the company. At a small business, the general inbox usually reaches the owner; at a larger one, a named person who owns the problem you solve is the better target. Both are covered after the eight methods.
Before you start: confirm the domain
Every method below works on the company's own domain, so get that right first. Take it from the company's website, not from a directory listing, and watch for businesses whose "website" is a Facebook page or a booking platform: an address you find there belongs to the platform.
Two quick checks save wasted effort:
- Does the domain take email? Any DNS lookup tool shows a domain's MX records, the entries that say which server receives its mail. A domain without them rarely receives email, and a "null MX" record, defined in RFC 7505, says outright that it accepts none.
- Is it the current domain? Companies rebrand and merge. If the website redirects to another domain, use the one it lands on.
Method 1: Check the contact, footer, about and team pages
Most companies that want to be emailed publish an address on at least one of these pages. Look at:
- the contact page, including the text around any map or form
- the footer, which appears on every page
- the about, team or staff page, where small companies often list each person's address
- the link behind an "Email us" button or envelope icon, which may be a
mailto:link to an address that isn't printed anywhere
Some sites hide addresses from bots. You may see "name [at] company [dot] com" (rewrite it), an address shown as an image (type it out carefully), or, in copied or scraped text, the placeholder [email protected], which Cloudflare's email obfuscation puts in the page source. Open the page in a normal browser and the real address appears.
Method 2: Read the legal pages
Imprint, legal notice, privacy policy and terms pages are easy to overlook, and they often contain an email address because the law asks for one. In the EU, Article 5 of the E-Commerce Directive requires providers of online services to publish their contact details, "including his electronic mail address". The UK kept the same rule in regulation 6 of the Electronic Commerce Regulations 2002, and Germany's version is the well-known Impressum, now in § 5 DDG.
Privacy policies are the other good source: under Article 13 of the GDPR, a company that collects personal data must tell people who the data controller is and how to contact it, and that contact is usually an email address.
Addresses on legal pages are sometimes dedicated mailboxes such as privacy@ or legal@. Those exist for their stated purpose. Use them to learn the domain's format or its general address, not to send a pitch.
Method 3: Search the domain with Google
Google's site: operator limits results to one domain (Google's documentation). Combine it with the domain's email ending to surface pages that mention an address:
site:company.example "@company.example"
site:company.example email OR contact
This finds addresses on pages you'd never click through to: PDFs (menus, brochures, price lists, application forms), old blog posts and job ads. Adding filetype:pdf narrows the search to PDFs. Drop the site: part and search for "@company.example" alone to find the company's addresses on other websites, such as press releases, event pages and association member lists.
If you need emails for a whole list of businesses rather than one company, doing this by hand stops making sense quickly.
Method 4: Use the contact form, and get the address from the reply
If a company offers only a contact form, use it. A short, specific message through a form is a legitimate way in, and it often reaches the same person the general inbox would. When they reply, you have a working address and a conversation.
Keep it human: one company, one message, written for them. Mass-submitting forms with a script is spam by another route, and most forms are protected against it anyway.
Method 5: Check social profiles and listings
- Facebook pages of small businesses often show an email address in the page's intro or about section.
- Instagram business profiles can have an email button, visible mainly in the app.
- LinkedIn company pages rarely show an address, but they list employees, whose names you need for method 6.
- YouTube channels sometimes offer an email for business inquiries on the channel's about panel.
- Map listings won't help: a Google Business Profile has fields for a phone number and a website but no public email field, and many directory listings are the same.
Use addresses the business publishes as its contact. An owner's personal address found on a personal profile is not an invitation to pitch.
Method 6: Work out the email pattern
Companies with more than a handful of people usually give everyone an address in the same format. Find one real address of a named person at the domain (in a press release, a PDF, a staff page or a blog post's author box) and apply the same format to the person you want to reach.
| Pattern | Example for Jane Doe |
|---|---|
| first | [email protected] |
| first.last | [email protected] |
| firstlast | [email protected] |
| flast | [email protected] |
| f.last | [email protected] |
| first_last | [email protected] |
| last | [email protected] |
| firstl | [email protected] |
Real names break patterns. Watch for nicknames (Bob for Robert), hyphenated and double surnames (common in Spain and Latin America), particles such as "van der", and accents, which are usually dropped (José becomes jose). When two employees share a name, the second one often gets a variant.
A pattern gives you a guess, not an address. Verify it before you send (method 8), and never send to several guesses to "see which one works": every wrong guess is a bounce.
Method 7: Check the domain's registration data (and why it rarely helps)
It used to be common to look up who registered a domain and email them. That route has mostly closed. After the GDPR took effect in 2018, registrars began redacting registrant contact details, and on 28 January 2025 the Registration Data Access Protocol (RDAP) replaced WHOIS as the definitive source for generic top-level domains such as .com. A public lookup with ICANN's lookup tool typically shows the registrar, the key dates and the name servers, while the registrant's contact details are redacted or replaced by a web form or a privacy service.
Even when an address is visible, it often belongs to the web developer, an IT provider or the privacy service, not to anyone who makes buying decisions. Use registration data to confirm that a domain is active, not to find a contact.
Method 8: Use an email finder, then verify
Email finders automate methods 1, 3 and 6: they look for addresses published on the web and predict addresses from patterns. Two things to know before you trust one:
- Found is not the same as predicted. An address the tool saw published is a fact about the past; one it predicted from a pattern is a guess. Either can be wrong today.
- Verification is a separate step. A verification check asks the company's mail server whether it accepts the address, without sending an email. The verdict is valid, invalid, catch-all or unknown, and only valid addresses are safe to send to. A catch-all server accepts every address, so it can't confirm any single one; catch-all emails explained covers what to do with those, and how to verify an email address without sending an email explains the whole check.
For a list of companies rather than one, the same logic runs in bulk: each company's domain goes in, the addresses found on that domain come out, and only those verified as valid move on to your outreach tool. That's how the email step works in Glintscout: it looks for addresses on each company's own domain, verifies every one, and exports only the valid ones, whether the companies came from a Google Maps search or another source. If you're building the list itself, the guide to building a B2B lead list by city and niche covers the steps before this one.
Which email address to use for B2B outreach
Finding an address isn't the goal. Reaching the person who can say yes is. Here's how the common addresses compare:
| Address | Who usually reads it | Use it for a sales email? |
|---|---|---|
| info@, office@, hello@, contact@ | The owner or office manager at small firms; a shared inbox at larger ones | Yes at small businesses; at larger ones it gets routed, slowly |
| A named person (jane@) | That person | Best when they own the problem you solve |
| sales@ | The sales team | Only if you're buying or proposing a partnership |
| support@, help@ | A ticket queue | No: your pitch becomes a support ticket |
| careers@, jobs@ | Recruiting | Only if you sell recruiting services |
| billing@, accounts@ | Finance | Only if you sell to finance |
| privacy@, legal@, dpo@ | Data protection or legal | No |
| postmaster@, abuse@, webmaster@, noreply@ | Technical roles, or nobody | Never |
Most of these names are conventions, and some are standards: RFC 2142 defines postmaster@, abuse@, webmaster@ and similar mailboxes for specific operational jobs, which is exactly why a sales pitch doesn't belong there.
Two more rules:
- One address per company for a first email. Writing to three people at a ten-person company in the same week reads as a campaign, not a conversation.
- Named addresses are personal data. Under the GDPR, [email protected] relates to an identifiable person; [email protected] usually doesn't. Countries also differ on whether you may email a business at all without consent, so check is cold email legal? before you send.
Common mistakes
- Taking an address from a directory or social page that belongs to the platform.
- Sending to a guessed address without verifying it.
- Treating a catch-all "accept" as proof that the mailbox exists.
- Pitching support@ and getting a ticket number back.
- Using an address you found a year ago without checking it again.
FAQ
Can I find a company's email address for free?
Yes. Methods 1 to 7 cost nothing but time. What's hard to do for free, at any volume, is verification: checking each address against its mail server before you send.
How do I find the email address of a specific person at a company?
Find the person's name (team page, LinkedIn, press releases), find one real address at the same domain to learn the pattern, apply it, and verify the result. If the domain is catch-all, verification can't confirm your guess, so the address the company publishes is the safer choice.
What if a company has no email address anywhere?
Use the contact form, call, or send a letter. Don't guess on a domain that won't confirm addresses: a bounce hurts your sender reputation, and the contact form reaches the same people.
Why did an address I found on the company's own website bounce?
Websites keep addresses long after the mailbox closes: the person left, the company changed email provider, or the page has a typo. That's why every address, even a published one, should be verified shortly before you send.
Is it legal to email an address I found on a company website?
It depends on the recipient's country and on whether the address is a company's or a person's. Publishing an address doesn't by itself mean consent to marketing everywhere; the rules by country are in is cold email legal? This is general information, not legal advice.
Keep reading
All articlesLead generation
How to Build a B2B Lead List by City and Niche (Step by Step)
Build a B2B lead list by city and niche: turn your niche into keywords, pick cities and a source, find emails on each company's site and verify them.
13 min read
Lead generation
How to Extract Leads from Google Maps (With Verified Emails)
Turn Google Maps into a B2B lead list: search by keyword and city, drop directory and social links, find emails on each business's site and verify them.
9 min read
Lead generation
How to Find Companies Running Google Ads (and What to Pitch Them)
Find the companies running Google Ads in any city: search by keyword and location, check the Ads Transparency Center, then pitch what you saw.
9 min read