Guides / Find any email address
How to Find Anyone's Work Email Address (Without Paying for Anything)
You have the person picked out. A founder at a startup doing work you actually care about, a research lead, someone running the exact team you want to intern with. Maybe you even have a draft written. And you're stuck on the most annoying step in the entire process: you don't have their email address.
I know this step well. As a sophomore at Penn with zero connections, I sent 45 cold emails to companies I had no relationship with, asking for internship work. 44 of them delivered. I got 8 replies from founders and execs within 48 hours. None of that happens if you can't find the right address, so before I sent anything, I got good at finding addresses. This post is the core of how I do it, for free, with enough detail that you can go do it right now.
Start with the patterns almost every company uses
Corporate email addresses are not random. The vast majority of companies pick one format and apply it to everyone. If you know someone's full name and the company domain, you can usually generate the correct address in under a minute. The common patterns, roughly in order of how often I see them:
- first@company.com (jane@company.com). This is the default at most startups under about 50 people. Founders especially. If you're emailing a founder at a small company, guess this one first.
- first.last@company.com (jane.park@company.com). The standard at mid-size and larger companies, and at most companies that started on Google Workspace with more than a handful of employees.
- flast@company.com (jpark@company.com). First initial plus last name. Common at older companies, banks, and anywhere with an IT department that set conventions years ago.
- firstlast@company.com (janepark@company.com). Less common but worth having on your list.
- last@company.com or first_last@company.com. Rare. Try these only after the others fail verification.
Two things trip people up here. First, get the domain right. The company might market itself at company.io but run email on company.com, or the reverse. Check where the email links on their own site point (more on that below). Second, watch for shortened first names. A founder who goes by Alex everywhere might be alexander@ on email, or the other way around. Generate both versions.
So for any target, you should walk away from this step with a short list: three to six candidate addresses built from the patterns above. Do not send to any of them yet. That matters more than people think, and I'll explain why in a second.
Check the company's own website before anything else
Before you guess, look. Companies leak their email format constantly, and one confirmed address tells you the format for everyone at the company.
- The contact and about pages. Obvious, but people skip it. Even a generic hello@company.com confirms the domain they actually use for mail.
- The blog. Startup blog posts often end with "questions? reach me at sam@company.com." Founders write these themselves and sign them with real addresses.
- Press pages and press releases. This is the best one. Press releases almost always include a media contact with a full name and a full email address. That's your pattern, confirmed. If the media contact is maria.lopez@company.com, your target founder is very likely firstname.lastname@ too.
- Job postings. Smaller companies often say "send your resume to careers@company.com" or, better, to a named person.
- PDFs and docs on their site. Whitepapers, investor decks, and event one-pagers frequently have an author's email in the footer. A site search on Google like site:company.com "@company.com" surfaces these fast.
- GitHub, personal sites, and conference talks. Engineers and researchers put work emails in commit histories, paper headers, and speaker bios all the time.
When I was building my own list, this step alone solved a lot of my targets. One confirmed address anywhere on the domain and I stopped guessing entirely.
I put the full version of this process, every step in order with the exact free tools I used for each one, into a free download. If you'd rather follow a checklist than reconstruct it from a blog post, it costs nothing: grab the free email-finding method here.
Never send to an unverified guess
This is the rule that separates people who do this well from people who quietly torch their own results. A guessed address is a hypothesis. You verify it before you send, every single time, and here's why.
When you send to an address that doesn't exist, the email bounces. A bounce isn't neutral. Mail providers track how many of your emails bounce, and a high bounce rate tells them you're either careless or a spammer. Either way, your future emails, including the correctly addressed ones, start landing in spam folders. As a student, your personal Gmail or school address is the only sending reputation you have. One sloppy afternoon of spraying guesses can damage it for weeks, and you'll never know, because spam-foldered emails just look like silence.
The good news: you can verify addresses for free, without sending anything. Free email verifiers work by asking the receiving mail server, in effect, "would you accept mail for this address?" The server answers yes or no without any email actually being delivered. Several tools do this with a free daily allowance, which is plenty when you're checking a handful of candidates per target.
The workflow looks like this:
- Generate your candidate list from the patterns above.
- Run each candidate through a verifier until one comes back valid.
- Send to that one address only.
One complication worth knowing about: some domains are configured as "catch-all," meaning the server says yes to every address whether it exists or not. Verifiers will usually flag this as "accept-all" or "risky" rather than "valid." When you hit a catch-all domain, verification can't confirm your guess, so lean harder on the website-scraping step to find a confirmed example of the company's format, and go with the most common pattern if you find nothing. A catch-all domain also won't hard-bounce a wrong guess, which softens the downside.
My own numbers reflect this process. Of the 45 emails I sent, 44 delivered. That's 44 delivered out of 45, on addresses I built almost entirely from guessing and verifying. The method is not exotic. It's just doing the boring check every time.
What to do when the company is tiny and has no contact page
Early-stage startups are the best cold email targets, and also the hardest to research. Five people, a one-page website, no blog, no press. Here's the order I work in:
- Default to first@. At companies this small, first@company.com is the single most likely format. Verify it first.
- Find the domain through their launch footprint. Tiny startups announce themselves somewhere: Product Hunt, Hacker News, a funding announcement, a university news post. Those announcements often link the real domain and sometimes quote a founder with contact info.
- Check the founders' personal sites. Founders of small startups usually have personal websites, and personal websites usually have an email. A founder's personal Gmail is a perfectly fine place to send a thoughtful note. Arguably better, since it's a less crowded inbox.
- Look at their open-source and research trail. If it's a technical startup, the founders have GitHub profiles, arXiv papers, or old lab pages, and those frequently carry emails.
- Check the WHOIS record and site metadata. Sometimes the domain registration or the site's legal page has a real mailbox on it.
If all of that fails, you're not out of options. You're just on the wrong channel.
When LinkedIn is the better move
Email is my default because it lands in the one place professionals check with real attention, and because a well-written email doesn't look like the pile of connection requests they ignore weekly. But there are cases where LinkedIn wins:
- The address genuinely can't be found or verified. If you've run the whole process and everything comes back invalid or risky, don't send to a guess. Send a short, specific LinkedIn message instead. A delivered LinkedIn message beats a bounced email every time.
- Your email bounced. This happened to me once during my campaign. One of my 45 emails bounced, so I sent essentially the same message to the same person over LinkedIn. They replied. The message was the asset; the channel was just plumbing.
- The person is visibly active there. Someone posting on LinkedIn twice a week is reading their LinkedIn inbox. Meet people where they actually are.
Keep LinkedIn messages shorter than emails. You don't control formatting there, and walls of text look worse in a chat window. Two or three sentences, one specific reason you're reaching out, one clear ask.
Finding the address is step one, not the whole game
Everything above should get you a verified address for most people you want to reach. It's the same process behind my 44-out-of-45 delivery rate, and you can run it today with free tools and a spreadsheet.
But a delivered email that reads like every other "I'm a passionate student seeking opportunities" message gets archived in seconds. The 8 replies I got from founders and execs came from what the emails said, not just where they landed. Finding the address gets you to the door. The email itself is what gets it opened.
If you want the address-finding process as a clean, ordered checklist with the exact free tools I use at each step, that's the free kit: download it at coldopen.pro, no payment, no catch. If you want to go deeper on addresses specifically, there's a $15 Address-Finder Toolkit available at checkout. And if you want the full picture, And if you want the templates and a 1-on-1 markup of your own draft, that's the Cold Open Core playbook at $29; the $59 Deluxe adds a teardown of every real email I sent, plus an outreach tracker., that's the Cold Open playbook, starting at $29. Everything comes with a 30-day full refund, and you keep the files either way.
The exact method for finding and verifying anyone's work email address, free. The playbook with every template and a 1-on-1 markup of your draft is $29.
Get the free email-finder method