How to Find Business Email Addresses That Actually Work

Finding a decision maker’s work address is part sourcing, part pattern matching and part verification. Here is the order to do it in, and where each method breaks down.

Start with the addresses you already have

Before you buy a tool to help you find business email addresses, mine the systems you already own. Inbound form fills, webinar registrations, support tickets, invoices, calendar invites and dormant CRM records usually hold more genuine work addresses than a first sourcing run will produce, and they cost nothing.

Two habits make this worth doing properly. First, export rather than eyeball: pull every contact object out of the CRM, the helpdesk and the billing system into one sheet, with source, date and consent status attached to each row. Second, deduplicate on the address itself, not on the person’s name — the same human shows up as Rob, Robert and R. Chen across three systems, and name matching will merge two different people while missing one.

Then judge the age. An address collected four years ago is closer to a guess than a fact, because people change jobs. Anything older than roughly eighteen months should be treated as unverified until you re-check it. Anything at a company that has since been acquired should be assumed broken until proven otherwise.

This pass usually recovers a useful block of contacts and, more importantly, shows you which target segments you have no coverage in at all. That gap is what sourcing budget is for.

Where to find business email addresses on the open web

Published sources are still the backbone of manual sourcing. They are slow per contact, but the hit rate is high, because you are reading an address rather than inferring one.

  • The company’s own site. Team, press, contact and legal pages. In German-speaking markets the Impressum is legally required and usually names a real person with a real address.
  • Registries and filings. Company registers, trademark filings and domain records often carry an administrative or legal contact.
  • Conference and event pages. Speaker bios, sponsor listings and press kits frequently publish a direct address for partnership or media enquiries.
  • Documents on their own domain. Whitepapers, price sheets, tenders and job adverts are indexed; a site-restricted search for the at sign plus the domain surfaces many of them.
  • Their own outbound. Newsletters, podcast show notes and support ticket signatures give you a live address and, just as usefully, the company’s naming pattern.

Two rules govern all of it. Read a site’s terms before you automate anything against it, and where automated collection is forbidden, collect by hand or skip the source. Prefer places where the person published the address themselves for business contact — a press page and a leaked forum thread are not the same kind of source, and the difference will matter to your reply rate as well as to your counsel.

Email patterns and how far you can trust them

Most companies apply a single pattern to everyone. Once you know the pattern for a domain, every other contact there becomes a candidate address rather than a fresh research task.

PatternExample for Anna WeberWhere you tend to see it
first.last[email protected]The most common by a wide margin, especially in Europe
first[email protected]Small teams and early startups, until two names collide
flast[email protected]Mid-market and older Exchange estates
firstl[email protected]Less common, often a collision fallback
first_last[email protected]Rare, but persistent where it exists

Derive the pattern from at least two known-good addresses at the domain, never from one. Watch for the mail domain differing from the marketing domain, which is normal in groups and after acquisitions. And be clear about what a pattern cannot tell you: whether the person still works there, whether the box is a shared alias, and whether the address is a spam trap. A pattern produces a hypothesis. Verification decides.

Verification: what a checker can and cannot prove

Verification is the step that decides whether your bounce rate is around one percent or well into double digits. A checker works in layers, each answering a narrower question.

  • Syntax. Is this a legal address at all? Catches typos, pasted whitespace and truncated exports.
  • Domain and MX. Does the domain resolve, and does it accept mail? A domain with no MX record cannot receive anything, whatever the address looks like.
  • Disposable and role detection. Flags throwaway providers and shared boxes such as info@, sales@ and support@. Role addresses are not invalid, but they behave differently and belong in their own segment.
  • Mailbox probe. An SMTP conversation that stops short of sending and asks the server whether the recipient exists.

The last layer is where certainty runs out. A catch-all domain accepts every address at the gateway and discards unknown ones later, so the probe reports acceptance for a mailbox that does not exist. Some providers answer that way deliberately, precisely to defeat this check. Treat catch-all results as unknown rather than valid: park them, or send to them at low volume from a separate domain, so a bad batch cannot damage the reputation of the domain you rely on.

Enrichment: from a bare domain to a named contact

Sourcing and enrichment run in opposite directions. Sourcing starts from a person and finds their address. Enrichment starts from a company — often nothing but a domain on a target list — and works down to a named human in the right role.

A workable enrichment pass answers four questions in order. Which company is this actually, as a legal entity, with a size and a country. Who holds the relevant role there today. What is that person’s address. Does the address verify. Stopping after the second question leaves you with a name you cannot reach; skipping the first leaves you emailing a reseller instead of the manufacturer.

Expect partial results and design for them. A realistic pass over a cold domain list returns a named, verified contact for some fraction of rows; the rest come back as role addresses, unknown catch-alls, or nothing. That is normal and not a tooling failure. The mistake is treating a half-filled row as a complete one and sending anyway.

Growmindr runs this pass inside its lead generation workspace, drawing on connected providers and your own CSV imports, then deduplicating against contacts you already hold so the same person is not enriched — or emailed — twice.

The legal and ethical side: questions for your own counsel

What follows is a list of questions to raise, not legal advice. The rules differ by your country, the recipient’s country, and whether the recipient is a business or a consumer. Have your own counsel sign off before the first send.

Under the GDPR and similar regimes

A work address that identifies a person is personal data, including in a business context. Cold B2B outreach in the EU is commonly run on the legitimate interest basis, which expects you to have documented a balancing test: what your interest is, why the processing is necessary for it, and why it does not override the person’s rights and expectations. Transparency obligations sit alongside it — people are entitled to learn where their data came from — as do access, objection and erasure rights. Several member states add stricter national rules for electronic marketing, so the answer is not uniform across the EU.

Under CAN-SPAM and comparable rules

The US regime is opt-out rather than opt-in for commercial email, but it still requires accurate headers and subject lines, a valid physical postal address, a clear unsubscribe mechanism, and prompt processing of opt-outs.

In practice: keep a source note on every contact, suppress opt-outs globally rather than per campaign, respect a site’s terms rather than harvesting against them, and never disguise who you are or why you are writing.

A repeatable workflow

Ad-hoc sourcing produces lists nobody trusts. Fix the order of operations once, then run it identically every time.

  1. Define the account list first. Companies, not people. Filter on the criteria that genuinely predict fit, then decide which roles you need at each account.
  2. Deduplicate against what you own before spending anything, including against contacts already sitting in an active sequence.
  3. Source in tiers. Owned data, then published sources, then provider lookups, then pattern inference. Stop at the first tier that answers.
  4. Verify everything, including addresses a provider already marked as valid.
  5. Split by confidence. Verified, catch-all, role and unknown become separate segments with separate send volumes.
  6. Record provenance. Source, date, method and consent status on every row.
  7. Re-verify before each campaign, not once at import.

Provenance is the field people skip and later regret. Lists decay continuously as people change roles, and much faster after a restructuring, so the date matters as much as the address. And when someone asks where you got their address — which, under the GDPR, they are entitled to do — the answer has to be a record, not a recollection.

How to tell whether the list is any good

Judge a sourcing method by what happens after you send, not by how many rows it produced. Four numbers cover most of it.

  • Hard bounce rate. The direct measure of list quality. If it climbs past the low single digits, stop and re-verify rather than pushing through — mailbox providers read sustained bouncing as evidence that you are guessing.
  • Coverage. The share of target accounts for which you obtained a named, verified contact. Weak coverage on a good account list is a sourcing problem, not a copywriting problem.
  • Role-address share. A list made mostly of info@ and contact@ will underperform regardless of how well the email is written.
  • Reply rate by source. Tag every contact with its origin and compare. Provider lookups, pattern inference and hand-collected addresses rarely perform alike, and the cheapest source is not automatically the worst.

Track all four per source and per segment rather than as one blended figure. A comfortable blended bounce rate can hide a pattern-inferred segment bouncing badly while your owned data bounces at nothing — and it is the bad segment that is quietly damaging the domain you send everything else from.

FAQ

How can I find someone’s business email address for free?

Start with sources that publish addresses openly: the company site’s team, press, contact and legal pages, its Impressum in German-speaking markets, conference speaker bios, and documents hosted on its own domain. Then check your own CRM and helpdesk, which often already hold the contact. Free methods take longer per contact but produce read addresses rather than guessed ones, so the bounce rate is far lower.

Is it legal to send cold email to business addresses I found online?

It depends on your country, the recipient’s country, and your industry, so confirm the specifics with your own counsel. In broad terms, EU senders usually rely on a documented legitimate interest basis and must honour transparency, objection and erasure rights, while US senders under CAN-SPAM need accurate headers, a postal address and a working unsubscribe. Finding an address publicly is not by itself permission to email it.

What is a catch-all domain and why does it matter?

A catch-all domain accepts mail addressed to any mailbox at the domain, then discards or forwards the ones that do not exist. Verification tools cannot distinguish a real mailbox from an invented one there, so an address that looks valid may still bounce or vanish. Treat catch-all results as unknown, keep them in a separate segment, and send to them at reduced volume.

How reliable is guessing an email address from a name pattern?

Reliable enough to be worth trying, never reliable enough to send without verifying. Pattern inference works because most companies use one format for everyone, so two confirmed addresses at a domain usually reveal it. It cannot tell you whether the person still works there, whether the box is an alias, or whether the address is a spam trap. Always verify before the address enters a campaign.

Should I email role addresses like info@ or sales@?

Sometimes, but keep them separate. Role addresses reach a shared inbox where several people triage mail, so personalised outreach reads oddly and reply rates differ from named contacts. They are reasonable for partnership or supplier enquiries at small companies. Segment them, write differently for them, and measure them on their own so they do not distort your overall campaign figures.

How often should I re-verify an email list?

Re-verify immediately before each campaign rather than once at import. Contact data decays constantly as people change roles, companies restructure and domains move, and a list that verified cleanly two months ago will not verify cleanly today. Re-verification is cheap relative to the cost of a bounce spike, which damages the sending reputation of the domain your other campaigns depend on.