Check the company’s own site first, then a data provider with per-record provenance, then pattern inference with verification, and consider simply asking. Whatever the source, verify close to the send: a guessed address that bounces costs more than the contact was worth.
Published by emailcampaign.ai. We sell sending infrastructure, not contact data, so we have no interest in which provider you pick.
The four methods, in order
| Method | Reliability | Effort | Notes |
|---|---|---|---|
| The company's own site | High | Medium | Team pages, press contacts, author bylines, PDF reports and job listings |
| B2B data provider | Medium to high | Low | Pick one that records provenance and a last-verified date |
| Pattern inference | Low until verified | Low | Confirm one known address, apply the pattern, then verify every result |
| Ask | Highest | High | A message to a general address or a colleague, or a direct request |
Reading the company site properly
More addresses are published than people expect, just not on the contact page. Worth checking: author bylines on the blog, press releases, PDF reports and whitepapers where a contact is listed on the last page, job listings that name a hiring manager, conference speaker pages, and support documentation.
This is the highest quality source because the address was published deliberately and is current. It is also slow, which is why it works best for a short, high-value list rather than a large one.
Pattern inference, done safely
Email formats are consistent inside a company. Confirm one address you already know, and you have the pattern for everyone else.
| Pattern | Example for Jane Smith at acme.com |
|---|---|
| firstname.lastname@ | jane.smith@acme.com |
| firstname@ | jane@acme.com |
| flastname@ | jsmith@acme.com |
| firstnamel@ | janes@acme.com |
| lastname.firstname@ | smith.jane@acme.com |
Two cautions. Common first names collide, so larger companies often break their own pattern for duplicates. And a company using a catch-all domain will accept every variation you try, which means verification cannot tell you which one is real. On a catch-all, pattern inference gives you nothing.
Verification is not optional, and does not do what people think
Verification opens an SMTP conversation and stops before sending, checking whether the server accepts the recipient. It is a good test of whether an address is dead.
It cannot tell you a person is behind the address. On an accept-all domain every address you ask about comes back valid, including invented ones. Keep accept-all results in a separate bucket, send to them last and in smaller batches, and watch the bounces between batches rather than after the campaign.
Verification also ages. A file checked three months ago is not a verified file today, because people change jobs continuously.
Why this connects directly to deliverability
Hard bounce rate is the cheapest proxy a mailbox provider has for whether you obtained addresses from people or from a script. Above roughly two percent, the list reads as bought or stale, and that verdict attaches to your sending domain rather than to the campaign.
Guessed and unverified addresses are the most common way teams cross that line. The arithmetic is unforgiving: a pattern that is right eighty percent of the time produces a twenty percent bounce rate, which is far past the point where a domain is damaged.
The method most people skip
Asking. A short note to a general company address, or to someone else at the company, saying who you are looking for and why, works more often than its reputation suggests. It costs a message and returns a correct address with a reason attached, which also makes the outreach itself easier to justify.
For a list of two hundred well chosen prospects, the slow methods are affordable and produce a list that will not bounce. For a list of twenty thousand, no method is reliable enough, which is itself an argument about list size.
Questions, answered straight
- How do I find someone's business email address?
- Start with the company's own site, where team and press pages frequently list addresses. Then a reputable B2B data provider that records where each record came from. Pattern inference is a last resort and must always be verified before sending, because a guessed address that bounces damages your sending domain.
- What is the most common business email format?
- firstname.lastname@company.com and firstname@company.com cover a large share of companies, followed by flastname@ and firstnamel@. Formats are consistent within a company, so confirming one known address usually reveals the pattern for the rest.
- Are email finder tools accurate?
- Accuracy varies widely and the confidence score matters more than the hit rate. A tool returning an address with low confidence is guessing from a pattern, and sending to it is how bounce rates climb. Treat anything below high confidence as unverified.
- Can I just guess the email format?
- You can infer it, but never send to an inferred address without verifying it first. Guessed addresses are the single most common cause of the two percent hard bounce threshold being crossed, and that threshold is where providers start treating your list as bought or stale.
- Is finding someone's work email legal?
- Collecting a business contact is generally permissible, but what you then do with it is governed by the rules where the recipient is. Keep a record of where each address came from, because under some regimes you have to be able to say.
Published 20 September 2026. Updated 20 September 2026. Written by the team that runs the infrastructure; numbers come from the platform's own provisioning and sending, and from the providers' published documentation at the time of writing.