Explainer

How Do Email Finders Work?

Three methods sit behind every email finder. Here is what each one does, where each one fails, and how to read the result.

Get your free API key →Free to start. No credit card. 1,000 records to spend whenever you like.

An email finder takes a name and a company and returns the most likely working address, by guessing a pattern, testing it, or reading it from a database. Most tools mix the three. The difference is where the address comes from and how much you can trust it.

Key takeaways

  • A finder returns one address. A verifier tells you whether an address you already hold will deliver.
  • The three methods are pattern guessing, mail-server testing and database lookup. Each fails in a different way.
  • Catch-all domains accept any address, so a server test cannot prove a mailbox exists there.
  • Read the status that comes with the address. A bare address with no status is a guess.

What it is

An email finder is a tool that turns a person's name and company domain into a business email address, using patterns, live mail-server checks or stored records.

It sits at the start of outbound. You know who you want to reach. The finder supplies the address, and a status that says how sure it is.

How it works

  1. Input. You give a name and a domain, or a LinkedIn URL, or an ID from a search.
  2. Candidates. The tool builds possible addresses from known patterns, or pulls stored addresses for that person.
  3. Testing. For guessed candidates, the tool opens a connection to the domain's mail server and asks whether it would accept each one.
  4. Scoring. The tool labels each result: confirmed, accepted on a catch-all domain, or unknown.
  5. Return. You get the best address and its status, or nothing.

Step 3 relies on SMTP, the protocol mail servers use to hand messages to each other. The server checks the recipient with a RCPT TO command and replies with a code. A 250 means it accepts the address. A 550 means the mailbox does not exist. The reply codes are defined in RFC 5321 (checked September 2026).

Worked example

You want Jane Doe, a VP of Sales at Acme. The domain is acme.com.

The finder builds candidates from common patterns: jane.doe@acme.com, jdoe@acme.com, jane@acme.com. It looks up the MX record for acme.com, which names the server that receives Acme's mail. It then asks that server about each candidate without sending a message.

Say the server answers 550 for the first two and 250 for jane@acme.com. The finder returns jane@acme.com as the address.

Now change one fact. Acme runs a catch-all server that answers 250 to everything. All three candidates pass, and the test proves nothing. A careful tool returns the most likely pattern and marks it catch-all, not confirmed.

The three methods fail in different ways.

Pattern guessing builds addresses from a name and a domain. It is cheap and fast. It fails when a company uses odd formats, nicknames or aliases.

Mail-server testing checks each guess against the live server. It catches wrong guesses on normal domains. It cannot see inside catch-all domains.

Database lookup returns an address that was collected and checked earlier. There is no guessing at request time. Its accuracy depends on how recently the record was checked and where the address came from.

The status matters more than the address. Four labels cover most results.

  • Verified. The address was tested and the mailbox answered as real.
  • Catch-all, confirmed. The domain accepts everything, but the mailbox was confirmed another way.
  • Catch-all. The domain accepts everything and nothing more is known. Send with care.
  • Unknown or untested. Nobody has checked it. Treat it as a guess.

LeadOcean's own list has 13 status values, from verified to spam_trap. The field is email_status.

Email finder vs email verifier

People use the two terms as if they meant the same thing. They are different jobs.

Email finderEmail verifier
Starts fromA name and a domainAn address you already have
ReturnsAn address and a statusA status for that address
Main riskReturns a wrong guessCannot judge catch-all domains
Use it whenYou have a person but no addressYou have a list and want to cut bounces
MethodPatterns, tests or lookupMail-server tests and syntax checks

Many finders run a verifier inside. The status you receive is the verifier's output. A finder that returns no status gives you no way to tell a confirmed address from a guess.

When it matters

Cold outbound at volume

Bounces hurt sender reputation. Sending to unconfirmed guesses raises your bounce rate. Filter to confirmed statuses first, and treat catch-all addresses as a separate, riskier batch.

Catch-all domains

A catch-all domain accepts mail for any local part, so a server test says yes to anything. Expect a share of any list to land here, and send it in smaller, watched batches.

Job changes

An address that was valid last year may now point at a former employer. A good finder returns an address at the person's current company domain only. Check the date the record was last verified before you trust an old one.

Privacy and consent rules

Finding a business address does not settle whether you may email it. Rules such as the GDPR (Regulation (EU) 2016/679 on EUR-Lex, checked September 2026) and CAN-SPAM (FTC compliance guide, checked September 2026) set separate conditions for contacting people. Read the primary texts and ask a lawyer. This is not legal advice.

How LeadOcean handles it

LeadOcean uses database lookup. Some stored addresses carry the status derived, which means built from the company's address pattern and never tested, so the status tells you when an address is a guess. Each person record carries an email_status and an email_type (work or personal). You can size a list by status for free before you spend a record.

Search takes the emailStatus filter. Add count=true with limit=1 and the call returns only the total, which is free. The total is capped at 100,000.

For one person, GET /v2/people/email/work returns a single work address or data: null. It returns addresses at the person's current employer's domain whose status is verified, catch_all_valid or catch_all. A former employer's address is never returned. A miss costs one record.

bash
: Step 1, size a list by email status (free with count=true and limit=1)
curl -G "https://api.leadocean.io/v1/people/search" \
  -H "x-api-key: $LEADOCEAN_API_KEY" \
  --data-urlencode "domain=acme.com" \
  --data-urlencode "emailStatus=verified,catch_all_valid" \
  --data-urlencode "count=true" \
  --data-urlencode "limit=1"

: Step 2, get one work email for a person (costs one record)
curl -G "https://api.leadocean.io/v2/people/email/work" \
  -H "x-api-key: $LEADOCEAN_API_KEY" \
  --data-urlencode "person_id=PERSON_ID"

The default in LeadOcean counts is mailable people: verified, catch_all_valid and catch_all. LeadOcean does not refund bounced emails, so read email_status before you send. Each record also carries its own fetched_at date, and the dataset is refreshed monthly. Free covers 1,000 records one-off with no card. Pro is $499 a month.

Related reading: what an email finder is, the best email finder tools and the UK shortlist.

FAQ

How accurate are email finders?

It depends on the method and the domain. Normal domains can be tested and give clear answers. Catch-all domains cannot, so the best a finder can do there is a likelihood. Ask any vendor for the status behind each address, not a single accuracy percentage.

Can an email finder guarantee delivery?

No. A confirmed status means the server accepted the address at test time. Mailboxes fill up, people leave and servers change. Delivery also depends on your sending domain and content.

Is it legal to use an email finder?

Finding an address and emailing it are two separate steps. The rules depend on your country, the recipient and your message. Read the law text, such as GDPR or CAN-SPAM, and take advice from a lawyer. This is not legal advice.

What is the difference between a finder and a verifier?

A finder produces an address from a name and a domain. A verifier checks an address you already have. Many finders include verification, so look for the status in the response.

Does LeadOcean guess email addresses?

LeadOcean answers from stored person records, and each address comes with a status. An address built from a pattern and never tested is labelled derived, so you can filter it out. Search with count=true to size a list for free, then read email_status before you send.

Find verified work emails with one API call

Free to start. No credit card. 1,000 records to spend whenever you like.

Get your free API key →