Lead generation

How to Find a Company's Email Address (Without Guessing Blind)

Seven places a business address is already published, the six patterns almost every company uses, and why an unverified guess is more expensive than no address at all.

There are two ways to end up with a business email address: find one that is published, or work out what it probably is and check. Both are legitimate. Only one of them is safe to do at volume without checking, and it is not the second.

This is where addresses actually live, in the order worth looking, and what to do when none of it works.

Start with the places that publish addresses on purpose

Roughly two thirds of small and mid-sized businesses have an address published somewhere on their own site. People skip straight to guessing because the contact page did not have one, and the contact page is only the first of seven places.

1. The contact page — and its variants

Obvious, and worth being systematic about. The page is not always at /contact: try /contact-us, /get-in-touch, /enquiries, /kontakt, /iletisim, /contacto. On a multi-language site the local-language version sometimes carries an address the English one does not.

Frequently the only place an address appears, and often a different one from the contact form's destination. Check a deep page, not just the homepage — footers sometimes differ by section.

3. The team or about page

This is where named addresses live: sarah@, j.miller@. A named address is worth several generic ones, because it belongs to someone with a job title you can write to specifically.

4. The imprint page

In Germany, Austria and Switzerland, a business website must carry an Impressum with contact details including an email address. The same idea exists elsewhere under other names — company details in the footer under UK company law, mentions légales in France. This is why German lead lists have a far higher published-address rate than British or American ones: the law puts the address on the page.

5. The privacy policy and terms

Data-protection law requires a contact route for data subject requests. That is usually privacy@ or dpo@, which is not a sales inbox — but on a small business it is very often the owner's address, because they wrote the policy from a template and dropped their own address in.

6. Job adverts

Adverts on the company's own careers page or on a board often include an application address, and at businesses under fifty people that is a real human's inbox.

7. PDFs, price lists and brochures

The least-crawled surface on any website and frequently the richest — a downloadable brochure from three years ago with a direct dial and a named address on the back page.

A crawl that only reads the homepage misses five of these seven. That gap is most of the difference between collectors that "find no email" and ones that do, which is the whole job of a website email extractor.

Then check the places outside their site

If the site yields nothing:

  • The Google Maps or Yelp listing. Neither exposes an email field directly, but both link to the website, and the listing sometimes points at a different domain — a booking system or an old site that still has an address on it. Getting from listing to address is covered step by step in finding business emails from Google Maps.
  • Social profiles. Facebook business pages have a dedicated email field that many owners fill in and forget. Instagram business accounts expose a contact button. For anything creator-shaped this is often the only route, and finding creators by niche goes into it properly.
  • Trade association and chamber directories. Member listings usually publish contact details, and membership itself is a qualifying signal.
  • Company registries. Public filings carry a registered office and sometimes a contact address. Slow, but reliable for legal entities.
  • Press releases and news coverage. A press release almost always ends with a named media contact and a direct address.
  • Domain records. Historically whois gave you an address; since GDPR most registrars redact it for private individuals and route through a proxy. Occasionally still useful for older corporate domains.

Working out the pattern

At this point you have a domain and possibly a person's name, and no address. Six patterns cover the overwhelming majority of business email:

Pattern Example, for Sarah Jones at acme.com
first.last@ sarah.jones@acme.com
first@ sarah@acme.com
flast@ sjones@acme.com
firstl@ sarahj@acme.com
first_last@ sarah_jones@acme.com
firstlast@ sarahjones@acme.com

Rough tendencies worth knowing: first.last@ dominates at organisations above roughly fifty people; first@ is the norm for small businesses, because the first person there took the short address and everyone since has copied the shape; flast@ shows up disproportionately in law, finance, healthcare and anywhere the mail system was configured by an IT contractor a decade ago.

One known address gives you the whole company. This is the important bit. If any single address at that domain is published anywhere — a job advert, a press release, a PDF — you know the pattern, and every other name at that company follows it. That single find is worth more than any amount of guessing.

Two traps. Non-Latin names and hyphenated surnames break the pattern rules constantly. And a company that has been acquired often runs two domains at once, where the old one forwards and the new one does not, or the reverse.

Why an unverified guess is expensive

A guess is not free. It has a specific price, and it is not paid by the guess that fails — it is paid by every future email you send.

Send to an address that does not exist and the receiving server rejects it. That rejection is recorded against your sending domain and IP. Once your hard bounce rate goes over roughly 2–3%, providers start treating everything you send as suspect, including the messages to addresses that are perfectly fine. Get high enough and you are not in the spam folder, you are rejected at the door.

Which means the arithmetic on guessing is worse than it looks. Six candidate patterns sent blind to a hundred companies is six hundred sends, of which at most a hundred can land — a bounce rate around 83%, and a dead domain within a day.

Verification is what makes the pattern approach viable at all: generate the candidates, check them without sending, keep the one that resolves. What a real check does — syntax, MX lookup, SMTP probe — and why some results honestly come back as "risky" rather than yes or no, is in email verification, explained properly.

Generic addresses: the honest position

info@, hello@, contact@, enquiries@. Outreach advice treats these as worthless. That is true at one end of the market and wrong at the other.

Business size Who reads info@ Worth sending to?
1–10 people The owner, usually on their phone Yes — frequently the best address available
10–50 An office manager or receptionist Sometimes — forwarded if the subject is specific
50–500 A shared queue, often triaged by rules Rarely
500+ A ticketing system No

Two caveats. Some verification services flag role addresses as risky by policy rather than because they do not exist — that is a filtering decision, not a technical result. And some email platforms exclude role addresses automatically, which for a list of sole traders and small clinics can silently remove most of your list.

If your market is small local businesses, info@ is not a fallback. It is the address, and pretending otherwise means throwing away a working channel.

When there is genuinely no email

It happens, most often in hospitality, retail and trades where the business runs on phone calls and a Facebook page. The options, in order of what actually works:

  1. The contact form. Unglamorous and it does reach someone. It costs you the ability to follow up, so make the single message count.
  2. The phone. For local businesses this often has a much higher answer rate than email ever will — and one call gets you the address for everything afterwards.
  3. The social DM, if the platform is where the business actually operates.
  4. Skip it. A prospect with no reachable contact is not a prospect this week. Spending twenty minutes on one row is a worse use of the time than adding thirty new rows.

Doing this at scale without breaking anything

For a list of a few hundred the pipeline is always the same shape:

  1. Collect the businesses and their domains from a source with good coverage for that market.
  2. Crawl each domain across all seven surfaces above, not just the homepage.
  3. For domains with nothing, generate pattern candidates only where you have a real person's name.
  4. Verify everything, from both routes. Published addresses go stale too — a page from 2019 lists someone who left in 2021.
  5. Drop hard failures. Decide on catch-all domains deliberately, knowing they are unverifiable by design.
  6. Segment before sending: named addresses get one message, generic addresses get another.

Step six is the one people skip. A named address and a shared inbox deserve different opening lines, and treating them identically wastes the better of the two — the templates guide has a version of each.

FAQ

How do I find the email address of a specific person at a company?

Find any one published address at that domain to learn the pattern, apply the pattern to their name, then verify before sending. If no address at the domain is published anywhere, generate candidates for the common patterns and verify them — never send to unverified guesses.

In the UK and most of the EU, a corporate address published on a company's own website can be used for a relevant B2B approach under legitimate interest, provided you identify yourself, explain why you are writing and honour opt-outs immediately. Sole traders and individuals are treated more strictly in several jurisdictions. The distinctions are set out in is scraping Google Maps legal.

Should I email info@ or try to find a named address?

Depends on size. Under about ten people, info@ usually reaches the decision maker directly. Above fifty it reaches a queue. When both are available, use the named address and keep the generic one as a fallback for a later attempt.

Why do email finder tools return different results for the same company?

Because they are doing different things. Some crawl the live site, some replay a cached index from months ago, and some return an unverified pattern guess dressed up as a find. A result is only worth as much as the check behind it — which is why the useful question about any of these tools is what "verified" means to them.

What bounce rate is too high?

Hard bounces above roughly 2–3% of a send is where providers start applying pressure, and sustained rates above 5% cause real reputation damage. A verified list should come in well under 2%.

Keep reading