Article content and detailed guides remain in English. The selected language applies to controls and quick instructions.

Back to articles

How to Use Google Dorking to Find Email Addresses

On this page

What Is Google Dorking?

Google dorking (also called Google hacking) uses advanced search operators to filter Google results with precision. Instead of a broad search, you combine operators to narrow results to specific file types, domains, URL patterns or page content.

For email prospecting, this means finding pages that contain email addresses -- contact pages, staff directories, PDF documents, spreadsheets and public filings -- that a normal search would bury under thousands of irrelevant results.

Core Operators for Email Finding

Site operator

Restricts results to a single domain.

site:example.com email

Returns only pages on example.com that contain the word "email." Useful when you know the target company and want to find contact pages, team directories or documents on their site.

Variations:

site:example.com "contact us"
site:example.com "@example.com"
site:example.com inurl:team
site:example.com inurl:about

Intext operator

Finds pages containing specific text in the body.

intext:"@example.com"

Returns pages that display @example.com email addresses in their visible text. More precise than just searching for "example.com" because it targets the actual @ pattern.

Filetype operator

Limits results to specific file formats.

filetype:pdf "@example.com"

Returns PDF files that contain @example.com addresses. Common in annual reports, conference proceedings, government filings and academic papers.

Useful file types:

Operator Finds Common sources
filetype:pdf PDF documents Reports, filings, papers, presentations
filetype:xlsx Excel spreadsheets Attendee lists, directories, budgets
filetype:csv CSV files Exported lists, data dumps
filetype:doc OR filetype:docx Word documents Meeting notes, proposals, directories
filetype:xls Legacy Excel files Older directories and lists

Intitle operator

Finds pages with specific words in the title tag.

intitle:"staff directory" site:example.com

Returns pages titled "staff directory" on the target domain. Staff directories, team pages and contact directories often contain email addresses.

Useful title searches:

intitle:"email directory"
intitle:"contact list"
intitle:"our team"
intitle:"faculty directory"
intitle:"staff list"
intitle:"board of directors"

Inurl operator

Finds pages with specific words in the URL path.

inurl:contact site:example.com
inurl:directory site:example.com
inurl:team site:example.com
inurl:staff site:example.com
inurl:people site:example.com

Many organisations use predictable URL patterns for their contact and team pages.

Query Templates by Use Case

Find emails at a specific company

site:example.com "@example.com"
site:example.com inurl:team OR inurl:about OR inurl:contact
site:example.com intitle:"our team" OR intitle:"leadership"

Find emails in a specific industry

"@" "director of marketing" "software company"
intitle:"staff directory" "healthcare"
intitle:"our team" "marketing agency" "@"

Find emails in specific document types

filetype:pdf "attendee list" "@" "conference"
filetype:xlsx "contact" "@"
filetype:csv "email" "name"

Find emails on government or education sites

site:.gov "@" intitle:"staff directory"
site:.edu "@" intitle:"faculty"
site:.edu "department" "@" filetype:pdf
site:.gov "contact" inurl:directory

Find emails in specific regions

site:.co.uk "@" intitle:"team"
site:.de "@" intitle:"kontakt"
site:.com.au "@" intitle:"our team"

Combining Operators

Operators can be combined for precision. The more operators you chain, the fewer (but more relevant) results you get.

Find marketing directors at UK tech companies:

"marketing director" "@" site:.co.uk "technology"

Find board members in annual reports:

filetype:pdf "board of directors" "@" "annual report"

Find speakers at a specific conference:

filetype:pdf "speaker" "@" "summit 2025"

Find contact pages that list email addresses by department:

site:example.com inurl:contact "@example.com" "sales" OR "support" OR "press"

Exclusion operators

Use the minus sign to exclude irrelevant results:

site:example.com "@example.com" -site:blog.example.com
"marketing director" "@" -gmail.com -yahoo.com -hotmail.com
filetype:pdf "@" "conference" -"call for papers"

Excluding free email providers (gmail.com, yahoo.com, hotmail.com) helps focus on business email addresses.

Processing Results

Google dorking surfaces web pages and documents, not clean email lists. Processing the results into a usable list requires extraction.

From web pages

  1. Open each relevant result in your browser.
  2. Select and copy the page content (or specific sections containing emails).
  3. Go to Email Extractor.
  4. Select "Text and files."
  5. Paste the copied text.
  6. Click "Extract emails."

The tool identifies email addresses in the pasted text and deduplicates them automatically.

From documents

When Google dorking returns PDF, Excel or Word files:

  1. Download the files.
  2. Go to Email Extractor.
  3. Select "Text and files."
  4. Upload the downloaded files (up to 25 MB per file, 100 MB per batch).
  5. Click "Extract emails."

Email Extractor supports PDF, XLSX, XLSM, XLSB, XLS, DOCX and other formats directly. For scanned PDFs (image-only), run OCR separately first, as Email Extractor does not include built-in OCR.

From multiple pages

For results spanning many pages, the Email Extractor browser extension (available for Chrome and Edge) can extract emails from up to 25 same-site pages in a single operation.

Operator Reference

Operator Syntax Purpose
site: site:example.com Restrict to one domain
intext: intext:"@example.com" Text must appear in page body
intitle: intitle:"staff directory" Text must appear in page title
inurl: inurl:contact Text must appear in URL
filetype: filetype:pdf Restrict to specific file format
OR term1 OR term2 Either term matches
" " "exact phrase" Exact phrase match
- -site:blog.example.com Exclude term or site
* "director of * marketing" Wildcard (any word)
.. 2020..2025 Number range

Limitations

Google's anti-automation measures. Google limits how many searches you can run in a short period. Running dozens of dork queries in rapid succession may trigger a CAPTCHA or temporary block. Space your searches out and use a normal browser.

Indexed content only. Google only indexes publicly accessible pages. Content behind logins, paywalls or robots.txt blocks will not appear in results.

Stale results. Google's cache may be weeks or months old. An email address found in search results may have been removed from the source page since Google last crawled it.

No verification. Finding an email address on a web page does not confirm it is currently active or deliverable. Verify addresses before sending outreach.

Incomplete coverage. Not every page with email addresses ranks in Google. Some pages are not indexed, others are buried beyond the first few pages of results.

Compliance Considerations

Email addresses found through Google dorking are publicly accessible, but that does not automatically grant permission to send marketing email.

CAN-SPAM (US). Does not require prior consent for commercial email, but requires accurate headers, a physical address, an unsubscribe mechanism and honest subject lines.

GDPR (EU/UK). Requires a lawful basis for processing personal data. "Legitimate interest" may apply for B2B outreach in some contexts, but you must be able to demonstrate the interest, provide an easy opt-out and respond to data subject requests.

CASL (Canada). Requires express or implied consent before sending commercial electronic messages. Publicly available email addresses where the publication is related to the person's business role can qualify as implied consent under specific conditions.

Consult legal counsel for your specific situation. Do not assume that "publicly available" means "available for any purpose."

Extract emails

Explore tools

Verify emails

Check address validity before using your list.

ZeroBounce

Email Verification

Verifies email lists and provides tools for monitoring deliverability.

Useful when list cleaning and sender health belong in one workflow.

Explore ZeroBounce (opens in a new tab)