01

How to Find Someone's Email on LinkedIn, Step by Step

A professional profile almost never shows you an email address. What it does show you is the two facts you need to derive one: the person's name and their current employer. Here is how to turn those into a verified work address, and why the shortcuts in this category are worse than they look. Last updated 17 September 2026.

02

What a profile actually gives you

Start by being precise about what is on the page, because the methods follow from it.

  • The person's name, usually in the form they use professionally.
  • Their current employer and their role there.
  • Their location, which occasionally tells you which regional domain a large company puts them on.
  • Sometimes a personal site, a newsletter or a link in the summary, which can carry a contact address.

What is almost never there is a work address. On the rare occasion a contact address is published, it tends to be a personal mailbox the person keeps for recruiters, not the mailbox they answer colleagues in.

Step 1: turn the employer into a mail domain

The employer name on the profile is not a domain, and the company's website domain is not always the domain it receives mail on. Large companies frequently run mail on a different domain from their marketing site, and companies that have been acquired often keep mail on the old one for years.

The reliable way is to follow the mail records. A domain's MX records say which servers receive its mail, and they point at the domain that actually matters. An email domain search does this and returns the published addresses on the right domain in the same step.

Step 2: get the company's naming pattern

One confirmed address on the domain tells you how the company builds all of them. If a colleague of your target is published as first.last at the domain, your target is almost certainly first.last too.

Where no address is published anywhere, you are down to ranking the common patterns by how often companies use them, and that ranking is a hypothesis rather than an answer. It becomes an answer in step three.

Step 3: resolve the name and verify the mailbox

Apply the pattern to the name from the profile, then check the result against the receiving mail server. That check is what separates this from guessing, and it is the entire reason the method is safe to run at volume.

Watch for the name cases that break naive derivation:

  • Compound and hyphenated surnames, where the company may keep the hyphen, drop it or use only one part.
  • Accented characters, which mail systems flatten, but not always in the same way.
  • A shortened first name on the profile against the legal name in the company directory.
  • Middle initials that appear on the profile and never in the mailbox.
  • Two people with the same name at one employer, where one of them carries a number or an initial.

A finder generates the variants these produce and checks each one, instead of returning the first template that fits. That is what the LinkedIn email finder page describes.

Step 4: decide what to do with a catch-all result

If the company's mail server accepts every possible address on the domain, no external check can confirm one mailbox. The honest answer is catch-all, not confirmed.

Those rows are not worthless, they are just not safe for a cold sequence at volume. Send to them from a warmed domain in small numbers, or keep them out of the campaign until something else confirms the address. What you should not do is let a tool tell you they are verified.

What not to do

This is the part that matters most, because the popular shortcuts in this category carry a cost that is not obvious at the time.

  • Do not run an automated session against the network with your own logged in account. Automated access is against the terms of every professional network, and the account at risk is yours.
  • Do not install a browser extension that reads your logged in session to harvest profiles in bulk. Same risk, plus you are handing a third party a live view of your account.
  • Do not export whatever address the profile shows and treat it as a work address. It is usually a personal mailbox, and writing to a personal mailbox about a business matter reads worse than most senders expect.
  • Do not send to a derived address without checking it. One guess is one bounce, and bounces are scored against your sending domain, not against the guess.

Working from the name and the employer, outside the network, avoids all of that. Nothing in the method needs access to the platform, which is the point.

Doing it for a whole sourcing list

Recruiters and sales teams do this in bursts: fifty profiles for one open role, then nothing on that role for a month. The workflow is the same as for one person, in a file.

  1. Collect the names and employers you gathered, one row each.

  2. Resolve the employers to mail domains.

  3. Run the finder across the file and verify every candidate.

  4. Export the deliverable rows and handle the catch-all rows separately.

The economics matter here. On a hard role, most of those fifty will not resolve, so a tool that charges per attempt charges you most on your worst days. Only counting verified results turns a low hit rate into a cheap day instead of an expensive one.