Article content and detailed guides remain in English. The selected language applies to controls and quick instructions.

Back to articles

How to Find Email Addresses from a List of Domains

On this page

The Problem

You have a list of company domains. Maybe from a conference attendee list, a directory, an industry database or your own research. You need email addresses for people at those companies. The domains alone are not enough to start outreach.

Here are practical methods to turn domains into deliverable email addresses.

Method 1: Scrape the Website

Company websites often contain email addresses in plain text, especially on contact pages, about pages, team pages, footer sections and press pages.

Manual approach:

  1. Visit each domain.
  2. Check the contact page, about page, team page and footer.
  3. Copy any email addresses you find.

Automated approach:

  1. Save the relevant pages as HTML files.
  2. Upload them to Email Extractor.
  3. Click "Extract emails."
  4. Download the deduplicated list.

You can also use Email Extractor's webpage extraction feature to process URLs directly.

Advantages: The addresses are published by the company itself, so they are current and intentionally public.

Limitations: Many companies do not list individual email addresses on their website. You may find generic addresses (info@, contact@, sales@) rather than personal ones.

Method 2: Email Pattern + Name Lookup

Most companies use a consistent email format. If you can identify the pattern and a person's name, you can construct their address.

Step 1: Find the pattern.

  • Search for any known email from the domain. Check press releases, job postings, GitHub profiles, author bios, WHOIS records or SEC filings.
  • Tools like Hunter.io offer a domain search that reveals the email pattern.

Step 2: Find the person's name.

  • LinkedIn is the most reliable source for current employee names and titles.
  • Company about/team pages also list staff.
  • Industry directories and conference speaker lists are other sources.

Step 3: Construct the address.

Step 4: Verify the address.

Advantages: Works for any employee at the company once you know the pattern.

Limitations: Patterns can vary within a company (executives may use a different format). Common names may have variants (Mike vs Michael). Verification is essential.

Method 3: B2B Data Providers

Data providers maintain databases of business contact information indexed by domain, company, title and industry.

How it works:

  1. Upload your list of domains.
  2. The provider matches each domain to their database.
  3. Results include contact names, titles and email addresses.

Common providers: Apollo.io, Hunter.io, Snov.io, ZoomInfo, RocketReach, Lusha, Clearbit, Seamless.AI and UpLead.

Advantages: Fast. Can process hundreds or thousands of domains at once. Many providers include verification.

Limitations: Coverage varies. Not every domain will have contacts in the database. Accuracy is imperfect, and data goes stale. Free tiers have limited lookups.

For platform-specific guides:

Method 4: Google and Search Operators

Google indexes a surprising number of email addresses. Using search operators can surface addresses associated with specific domains.

Useful queries:

  • "@company.com" -- finds pages containing email addresses from that domain.
  • site:company.com "email" OR "contact" -- finds contact pages on the company's own site.
  • "company.com" filetype:pdf -- finds PDF documents from the company, which may contain author emails.
  • "@company.com" site:linkedin.com -- finds LinkedIn profiles that display email addresses from that domain.

Processing results:

  1. Copy the search result text.
  2. Paste into Email Extractor.
  3. Extract the email addresses.

For more on search techniques, see Google Search Operators for Email Finding.

Advantages: Free. Can find addresses not available through data providers.

Limitations: Time-consuming for large domain lists. Not all domains have indexed email addresses. Results may include outdated addresses.

Method 5: Public Records and Filings

Government filings, regulatory databases and public records often contain email addresses tied to specific companies.

Sources:

  • SEC filings (for US public companies).
  • Patent databases (inventor contact information).
  • Government contract databases (contractor points of contact).
  • Non-profit filings (IRS Form 990 for US non-profits).
  • Business registration databases (varies by country and state).

Download relevant filings as PDFs or text files and process them through Email Extractor.

Processing at Scale

For a list of 10 domains, manual methods work. For 100 or more, you need a systematic approach.

Batch workflow

  1. Start with a B2B data provider for broad coverage.
  2. For domains with no results, try pattern guessing with name lookups.
  3. For remaining gaps, use website scraping and search operators.
  4. Consolidate all results into a single file.
  5. Run through Email Extractor to deduplicate.
  6. Verify the full list through a verification service.

Prioritise by value

Not all domains on your list are equally important. Prioritise high-value targets for manual research and use automated tools for the rest.

After Finding the Addresses

Verify before sending

Addresses from any source should be verified. See Best Email Verification Services.

Check compliance

If your targets include EU residents, GDPR applies. If Canadian, CASL applies. Understand your obligations before sending. See GDPR Guide and CAN-SPAM Guide.

Segment by source quality

Addresses from company websites are higher quality than pattern guesses. Segment your list by source and adjust your outreach approach accordingly.

Extract emails

Explore tools

Verify emails

Check address validity before using your list.

ZeroBounce

Email Verification

Verifies email lists and provides tools for monitoring deliverability.

Useful when list cleaning and sender health belong in one workflow.

Explore ZeroBounce (opens in a new tab)