How to Use Google Dorking to Find Email Addresses
On this page
What Is Google Dorking?
Google dorking (also called Google hacking) uses advanced search operators to filter Google results with precision. Instead of a broad search, you combine operators to narrow results to specific file types, domains, URL patterns or page content.
For email prospecting, this means finding pages that contain email addresses -- contact pages, staff directories, PDF documents, spreadsheets and public filings -- that a normal search would bury under thousands of irrelevant results.
Core Operators for Email Finding
Site operator
Restricts results to a single domain.
site:example.com email
Returns only pages on example.com that contain the word "email." Useful when you know the target company and want to find contact pages, team directories or documents on their site.
Variations:
site:example.com "contact us"
site:example.com "@example.com"
site:example.com inurl:team
site:example.com inurl:about
Intext operator
Finds pages containing specific text in the body.
intext:"@example.com"
Returns pages that display @example.com email addresses in their visible text. More precise than just searching for "example.com" because it targets the actual @ pattern.
Filetype operator
Limits results to specific file formats.
filetype:pdf "@example.com"
Returns PDF files that contain @example.com addresses. Common in annual reports, conference proceedings, government filings and academic papers.
Useful file types:
| Operator | Finds | Common sources |
|---|---|---|
| filetype:pdf | PDF documents | Reports, filings, papers, presentations |
| filetype:xlsx | Excel spreadsheets | Attendee lists, directories, budgets |
| filetype:csv | CSV files | Exported lists, data dumps |
| filetype:doc OR filetype:docx | Word documents | Meeting notes, proposals, directories |
| filetype:xls | Legacy Excel files | Older directories and lists |
Intitle operator
Finds pages with specific words in the title tag.
intitle:"staff directory" site:example.com
Returns pages titled "staff directory" on the target domain. Staff directories, team pages and contact directories often contain email addresses.
Useful title searches:
intitle:"email directory"
intitle:"contact list"
intitle:"our team"
intitle:"faculty directory"
intitle:"staff list"
intitle:"board of directors"
Inurl operator
Finds pages with specific words in the URL path.
inurl:contact site:example.com
inurl:directory site:example.com
inurl:team site:example.com
inurl:staff site:example.com
inurl:people site:example.com
Many organisations use predictable URL patterns for their contact and team pages.
Query Templates by Use Case
Find emails at a specific company
site:example.com "@example.com"
site:example.com inurl:team OR inurl:about OR inurl:contact
site:example.com intitle:"our team" OR intitle:"leadership"
Find emails in a specific industry
"@" "director of marketing" "software company"
intitle:"staff directory" "healthcare"
intitle:"our team" "marketing agency" "@"
Find emails in specific document types
filetype:pdf "attendee list" "@" "conference"
filetype:xlsx "contact" "@"
filetype:csv "email" "name"
Find emails on government or education sites
site:.gov "@" intitle:"staff directory"
site:.edu "@" intitle:"faculty"
site:.edu "department" "@" filetype:pdf
site:.gov "contact" inurl:directory
Find emails in specific regions
site:.co.uk "@" intitle:"team"
site:.de "@" intitle:"kontakt"
site:.com.au "@" intitle:"our team"
Combining Operators
Operators can be combined for precision. The more operators you chain, the fewer (but more relevant) results you get.
Find marketing directors at UK tech companies:
"marketing director" "@" site:.co.uk "technology"
Find board members in annual reports:
filetype:pdf "board of directors" "@" "annual report"
Find speakers at a specific conference:
filetype:pdf "speaker" "@" "summit 2025"
Find contact pages that list email addresses by department:
site:example.com inurl:contact "@example.com" "sales" OR "support" OR "press"
Exclusion operators
Use the minus sign to exclude irrelevant results:
site:example.com "@example.com" -site:blog.example.com
"marketing director" "@" -gmail.com -yahoo.com -hotmail.com
filetype:pdf "@" "conference" -"call for papers"
Excluding free email providers (gmail.com, yahoo.com, hotmail.com) helps focus on business email addresses.
Processing Results
Google dorking surfaces web pages and documents, not clean email lists. Processing the results into a usable list requires extraction.
From web pages
- Open each relevant result in your browser.
- Select and copy the page content (or specific sections containing emails).
- Go to Email Extractor.
- Select "Text and files."
- Paste the copied text.
- Click "Extract emails."
The tool identifies email addresses in the pasted text and deduplicates them automatically.
From documents
When Google dorking returns PDF, Excel or Word files:
- Download the files.
- Go to Email Extractor.
- Select "Text and files."
- Upload the downloaded files (up to 25 MB per file, 100 MB per batch).
- Click "Extract emails."
Email Extractor supports PDF, XLSX, XLSM, XLSB, XLS, DOCX and other formats directly. For scanned PDFs (image-only), run OCR separately first, as Email Extractor does not include built-in OCR.
From multiple pages
For results spanning many pages, the Email Extractor browser extension (available for Chrome and Edge) can extract emails from up to 25 same-site pages in a single operation.
Operator Reference
| Operator | Syntax | Purpose |
|---|---|---|
| site: | site:example.com | Restrict to one domain |
| intext: | intext:"@example.com" | Text must appear in page body |
| intitle: | intitle:"staff directory" | Text must appear in page title |
| inurl: | inurl:contact | Text must appear in URL |
| filetype: | filetype:pdf | Restrict to specific file format |
| OR | term1 OR term2 | Either term matches |
| " " | "exact phrase" | Exact phrase match |
| - | -site:blog.example.com | Exclude term or site |
| * | "director of * marketing" | Wildcard (any word) |
| .. | 2020..2025 | Number range |
Limitations
Google's anti-automation measures. Google limits how many searches you can run in a short period. Running dozens of dork queries in rapid succession may trigger a CAPTCHA or temporary block. Space your searches out and use a normal browser.
Indexed content only. Google only indexes publicly accessible pages. Content behind logins, paywalls or robots.txt blocks will not appear in results.
Stale results. Google's cache may be weeks or months old. An email address found in search results may have been removed from the source page since Google last crawled it.
No verification. Finding an email address on a web page does not confirm it is currently active or deliverable. Verify addresses before sending outreach.
Incomplete coverage. Not every page with email addresses ranks in Google. Some pages are not indexed, others are buried beyond the first few pages of results.
Compliance Considerations
Email addresses found through Google dorking are publicly accessible, but that does not automatically grant permission to send marketing email.
CAN-SPAM (US). Does not require prior consent for commercial email, but requires accurate headers, a physical address, an unsubscribe mechanism and honest subject lines.
GDPR (EU/UK). Requires a lawful basis for processing personal data. "Legitimate interest" may apply for B2B outreach in some contexts, but you must be able to demonstrate the interest, provide an easy opt-out and respond to data subject requests.
CASL (Canada). Requires express or implied consent before sending commercial electronic messages. Publicly available email addresses where the publication is related to the person's business role can qualify as implied consent under specific conditions.
Consult legal counsel for your specific situation. Do not assume that "publicly available" means "available for any purpose."