Three ways to find a work email: guess and verify the company pattern, check their LinkedIn, or use a tool. Ours returns a verified email per person and only charges on a hit.
Three approaches carry the weight. The rest is noise. Here is what each one is and when to reach for it.
Most guides on how to find someone's email address hand you ten browser tricks and hope one sticks. In practice, three methods do the real work: guess the company's email pattern and verify it, pull the address from the person's LinkedIn profile, or run a finder that does both for you. Everything else is a slower version of these.
1. Guess the pattern, then verify. Most companies use one format for everyone, like first.last@company.com, first@company.com, or flast@company.com. Find one known address at the company (a press contact, a support inbox, a colleague you already have), copy its shape, and apply it to your target's name. Then run an SMTP check on the guess before you send, so you are not emailing an address that bounces.
2. Read it off their LinkedIn. A person's LinkedIn profile ties a name to a current employer and a job title. That is enough to derive the work email once you know the company's pattern, and it is the input every serious finder starts from. You are matching a real person at a real company, not throwing a name at a domain and hoping.
3. Use a finder that returns a verified email. A good tool takes a name and company, or a LinkedIn URL, and hands back one work email it has already checked. That is what our LinkedIn person endpoint does, covered next.
Our LinkedIn person endpoint takes a public profile and returns the person's details plus one verified work email. The email comes back only when it passes the check, and you pay only when one is found.
Point it at a public profile URL. It reads the logged-out page, derives the work email, and verifies it against the mail server before returning the row. No verified email, no charge, and no made-up address dropped into the output.
The response as a flat CSV, the way the playground renders it:
Every field on the profile comes back alongside the email, so you get the person and their address in one call.
Related: LinkedIn email finder · LinkedIn people search API · Email scraper
The email-finder market runs on monthly credit plans. Hunter's free plan is 50 searches a month, and those credits reset each month rather than roll over (hunter.io). Apollo has a free tier but bills per seat and its credits expire each billing cycle (apollo.io). Here is where they land against our pricing.
| Hunter.io | Apollo.io | CrustAPI | |
|---|---|---|---|
| Free per month | 50 searches | Free tier, capped credits | 3,000 credits |
| Unused credits | Reset monthly | Expire each cycle | Never expire |
| Charge on a miss | No | Credit rules vary | No, found emails only |
| Access model | Web + API | Per-seat SaaS | One API, no seats |
| Entry price | Starter ~$34/mo billed yearly | Basic ~$49/seat/mo | $1.96 per 1,000, usage-based |
Hunter and Apollo are subscriptions, so you pay every month whether you look up two people or two thousand. Ours is prepaid usage: one credit per found, verified email, and the credits sit in your account until you spend them.
You need a whole domain or a full sales suite: Hunter's Domain Search returns every public email pattern for a company in one shot, and Apollo wraps a CRM, sequences, and a dialer around its contact data. If you want an all-in-one outbound platform or a bulk sweep of one domain, those are the right call. We do one thing: a verified work email for a specific person from their LinkedIn profile.
A page that promises to find "anyone's" email is selling you something. Here is where the methods above stop working, so you know before you start.
Personal addresses. A private Gmail, Yahoo, or Outlook address is tied to no company pattern and no public directory. It is not reliably findable from public data, and we do not claim to return it. If a person has only a personal inbox, no tool can conjure it truthfully.
People with no public footprint. If someone has no LinkedIn profile and their company lists no staff, there is nothing to match a name against. The pattern trick needs a known address to copy, and the LinkedIn method needs a profile to read.
Google Maps listings. A Maps record gives you a business name, phone, website, and full address, but there is no email field anywhere in Maps data, from us or anyone. To reach a person you go through the LinkedIn profile endpoint, not a business listing. See the Maps scraper API for what Maps does return.
One credit equals one found, verified email. A lookup that turns up nothing costs nothing, so you are never billed for a dead search.
Start on the free tier: 3,000 credits every month, no card. Paid packs are prepaid and never expire, from 25,000 for $49 (that is $1.96 per 1,000) up to 250 million for $100,000, where the rate drops to $0.40 per 1,000. Buy once, spend when you need it, and top up when you run low.
Point our LinkedIn person endpoint at a public profile and get one verified work email back, or nothing and no charge if there is no match. Start with 3,000 free credits a month, no card, and only pay when we find an email worth sending to.
Get 3,000 free credits