An email finder is a tool that returns a person's business email address. You give it a name and company, a LinkedIn profile or a stored ID. It replaces guessing first.last@company.com and hoping.
Key takeaways
- A finder returns an address. A verifier checks an address you already hold. Good finders do both and tell you which they did.
- The address is only useful with its status: verified, catch all or unknown. A bare address is a guess.
- Finders work by pattern guessing, live mail-server tests or database lookup. Each fails in a different way.
- On LeadOcean the lookup is
GET /v2/people/email/work, and the status filter isemailStatus.
What it is
An email finder is software that returns the likeliest working email address for a named person at a named company, with a signal of how sure it is.
Outbound starts with a list of people. A list of names is not a list of addresses. The finder closes that gap.
Most tools work in one of two shapes. A web form takes one name and one domain and returns one address. An API does the same call in code, so a script or an AI agent can run it thousands of times.
The result is usually one address plus a label. The label matters more than the address. It tells you whether to send, hold or skip.
How it works
A finder takes an input, builds or retrieves candidate addresses, checks them, and returns the best one with a status.
- Input. You supply a name and a company domain, a LinkedIn URL, or an ID from an earlier search.
- Candidates. The tool either builds addresses from common patterns (
jane.doe@,jdoe@,jane@) or pulls addresses it already stores for that person. - Check. For built candidates, the tool asks the company's mail server whether it would accept each one, without sending a message. Stored addresses carry the result of an earlier check.
- Score. Each address gets a status such as verified, accepted by a catch all server, or unknown.
- Return. You get the best address and its status, or nothing.
Step 3 uses SMTP. The server answers the RCPT TO command with a 250 (accepted) or a 550 (no such mailbox), as defined in RFC 5321, checked September 2026.
Worked example, with placeholders. You want Jane Doe, VP of Sales at Acme (acme.com). The finder builds three candidates and tests each.
RCPT TO:<jane.doe@acme.com> -> 550 no such mailbox
RCPT TO:<jdoe@acme.com> -> 550 no such mailbox
RCPT TO:<jane@acme.com> -> 250 OKThe finder returns jane@acme.com as verified. If Acme ran a catch all server, all three lines would say 250 and the test would prove nothing. A careful finder then returns the likeliest pattern marked catch all, not verified.
Email finder vs email verifier
A finder discovers an address. A verifier judges one you already have. People mix them up because most products sell both under one name.
| Email finder | Email verifier | |
|---|---|---|
| You give it | A name and company, a LinkedIn URL or an ID | An address |
| It returns | An address and a status | A status for that address |
| Typical use | Building a list from names | Cleaning an existing list before a send |
| Failure mode | Returns nothing, or a guess on a catch all domain | Marks a catch all address as unprovable |
| Where it sits | Before the send list exists | Right before the send |
Run a verifier after a finder only when the finder gives no status. If every address already carries one, a second check on the same domain rarely changes the answer.
When it matters
Building a list from a named target
You have 200 accounts and a title in mind, such as VP of Sales. A finder gives you the address for each person. Size the list first, then spend records only on the people you will actually contact. This is the classic use, and the one where status labels decide your bounce rate.
Filling the gap in a CRM
Your CRM holds names and companies but half the contacts have no email. A finder fills the blanks. Check that it returns the current employer's address, not a former one, or you will mail people who left.
Feeding an AI agent
An agent that researches accounts needs a callable way to turn a person into an address. An API or an MCP tool does that inside the agent loop. The agent should read the status and skip anything that is not sendable.
Protecting your sending domain
Bounces cost reputation faster than they cost leads. A finder that returns unconfirmed guesses without a label puts that cost on you. Prefer one that tells you what it did not confirm. Split catch all addresses into their own smaller send, and stop if bounces climb.
How LeadOcean handles it
LeadOcean finds emails by database lookup, not by guessing patterns. There is no name plus domain lookup. You search by domain first, then look up the person you want by ID or LinkedIn URL (LeadOcean OpenAPI, checked September 2026).
GET /v2/people/email/work returns one current work address, or data: null. It only returns addresses at the person's current employer that are verified, catch_all_valid or catch_all. A null means none that qualify, not that the person has no email. The call costs one record, including a miss.
Asking whether a deliverable address exists is free. A people search row publishes has_email, email_status and email_type as flags, and sizing a search spends nothing. Send count=true as a query parameter with limit=1.
The first call sizes the audience and spends no records. The second looks up one person and costs one record.
curl -X POST "https://api.leadocean.io/v1/people/search?count=true&limit=1" \
-H "x-api-key: $LEADOCEAN_API_KEY" \
-H "Content-Type: application/json" \
-d '{"jobLevel": ["VP"], "jobFunction": ["Sales & Business Development"], "country": ["GB"], "emailStatus": ["verified"]}'
curl "https://api.leadocean.io/v2/people/email/work?linkedin_url=https://www.linkedin.com/in/jane-doe-example" \
-H "x-api-key: $LEADOCEAN_API_KEY"On 2026-10-01, leadocean_count_leads returned 3,146 mailable people. The filters were jobLevel VP, jobFunction Sales & Business Development and country GB, with the default email filter (verified, catch_all_valid and catch_all). Adding emailStatus set to verified alone returned 751 on the same day. The same filters work in the MCP server. They also work on the Exports page of the app (app.leadocean.io), which shows the record price before you start.
LeadOcean does not refund bounced emails, so read email_status before you send. Pricing is two plans: Free (1,000 records, one-off, no card) and Pro at $499 a month. See pricing. To compare tools, see best email finder tools and best email finder tools for the UK. The free email finder lets you try a lookup.
FAQ
What does an email finder do?
It returns a business email address for a person you name, with a status that says how sure it is. You supply a name and company, a LinkedIn URL or an ID. It saves you from guessing address patterns.
Is an email finder the same as an email verifier?
No. A finder discovers an address. A verifier checks one you already hold. Many products do both, so read the status on the result to see what was actually confirmed. For the mechanics see how email finders work.
How accurate is an email finder?
No single number holds across tools, and we have not run an accuracy test, so this page gives none. Accuracy depends on the method and on how many target domains are catch all. Read the status, and send unconfirmed addresses in a smaller, separate batch.
Can an email finder find a personal email?
Some can. LeadOcean has a separate endpoint, GET /v2/people/email/personal, for personal addresses. Business outreach should start with the work address. Check the rules that apply to you before emailing anyone. This page is not legal advice.
Do I need a LinkedIn URL to find an email?
Not always, but it is the cleanest input. On LeadOcean you can also use a person_id from a search row. Search by domain first, then look up the person by ID.
Find the right emails before you send. Start free.
Free to start. No credit card. 1,000 records to spend whenever you like.
Get your free API key →