Skip to content
Reach-book.com

How to find someone's email address, and know it will arrive

Most business email addresses follow a pattern you can work out, but a guess that bounces costs you sender reputation. This guide covers where to look, how to work out the pattern, how verification works and what to do when a server will not confirm the address.

Updated · 4 min read · Written by the Reach-book.com team

Start with the right person

An email address is only useful if it belongs to someone who can say yes. Before you search, write down the role you need (head of operations, founder, IT manager) and the company. If you are not sure who decides, read how to find the decision maker at a company first; it saves lookups on people who will forward you elsewhere.

Six places to find a business email

  1. The company website. Check the team, about, contact, press and imprint pages. German, Austrian and Swiss sites must publish an imprint with a contact address, and small companies often list the founder's own address there.
  2. Published content. Conference speaker pages, podcast show notes, press releases, author bios and PDF reports often include a direct address.
  3. The person's own channels. A personal website, newsletter footer or social profile may list a work email or a booking link.
  4. The company's email pattern. Find any one address at the company, work out the pattern, and apply it to the person you need (next section).
  5. An email finder. Tools such as Hunter, Apollo and Reach-book.com search public sources and known patterns, then verify the result for you.
  6. Ask. A short message to a general inbox or a colleague ("who handles supplier onboarding?") often gets a name and an address, and an introduction.

Work out the company's email pattern

Most companies use one format for everyone. Hunter analysed more than 12 million addresses and found that "49.9% of the companies use the {first}@example.com email pattern". The other common formats are:

Pattern Example for Anna Berg at example.com
{first} [email protected]
{first}.{last} [email protected]
{f}{last} [email protected]
{first}{last} [email protected]
{first}{l} [email protected]
{last} [email protected]

Find two real addresses at the same company and the pattern is usually clear. Watch for exceptions: founders often keep a short first-name address, and larger companies add a number when two people share a name.

A pattern gives you a candidate, not an address. Check it before you send.

How email verification works

A verifier runs a series of checks, stopping as soon as one fails:

  1. Syntax: the address is well formed.
  2. Disposable and webmail detection: throwaway domains are rejected, and free webmail is flagged as personal.
  3. Domain and MX records: the domain exists and publishes mail servers.
  4. SMTP connection: the verifier connects to the company's mail server.
  5. Mailbox test: it starts a delivery to the address and reads the server's answer without sending a message.
  6. Catch-all check: it tests a random address at the same domain to see whether the server accepts everything.

The result is usually one of four statuses:

  • Valid: the server confirmed the mailbox.
  • Invalid: the server rejected it. Do not send.
  • Accept-all (catch-all): the server accepts any address, so the mailbox cannot be confirmed.
  • Unknown: the server did not answer clearly, often because of rate limits or greylisting.

Why some addresses can never be confirmed

The SMTP standard lets mail servers refuse to say whether a mailbox exists. RFC 5321 allows servers to disable the VRFY command for security reasons and defines a reply (code 252) for an address that looks fine but cannot be verified. Catch-all servers go further and accept mail for every address at the domain, then bounce or discard it later.

Hunter's own help center says that on these domains "no verification tool, including Hunter, can fully confirm deliverability". Any tool that promises 100% verified emails on every domain is overselling.

What to do with an accept-all result:

  • Prefer an address you found published somewhere over one built from the pattern.
  • Send to accept-all addresses in small numbers, from a mailbox with a good history.
  • Watch bounces in the first days of a campaign and remove anything that bounces at once.

Before you send

Finding an address does not give you permission to email it. In the US, CAN-SPAM covers business email too: the FTC says "The law makes no exception for business-to-business email". You need accurate headers, a subject line that is not deceptive, your postal address and a working opt-out honoured within 10 business days. In the EU and UK the rules depend on whether the recipient is a company or an individual. Our guide is cold email legal under GDPR? covers both.

Keep a suppression list from day one, so anyone who opts out is never emailed again from any campaign.

Doing this in Reach-book.com

In Reach-book.com you search by company, name, role or LinkedIn profile, and each lookup returns the address with its verification status. Company website research is added to the prospect, the AI email writer drafts a first email from it, and the email sends from your own Gmail or Microsoft 365 mailbox once you approve it. Bounces, replies and unsubscribes stop the sequence for that person, and opt-outs are honoured across every campaign in the workspace.

Try Reach-book.com on your own pipeline

Find decision makers, verify their emails and send personal sequences from your own Gmail or Microsoft 365 mailbox. The 7-day trial needs a card and is once per new workspace owner.

Sources

Checked on 4 October 2026. Vendors change plans often, so confirm on their own pages before you buy.

  1. Hunter: how to find someone's email address (email pattern analysis)
  2. Hunter help: checks performed by the Email Verifier
  3. Hunter help: what an accept-all status means
  4. RFC 5321, Simple Mail Transfer Protocol, section 3.5.3
  5. FTC: CAN-SPAM Act compliance guide for business