A company email finder takes a company domain and returns the address format that company uses, such as first.last@domain, plus any addresses already known on that domain. With the format and a person's name you can generate their address and confirm it with a verifier. Most companies above 50 people use a single format; the exceptions, and the 2.3% of non-freemail (business and ISP) domains that are catch-all, are where the method needs a live check.
For a person called Maria Lopez Garcia at example.com, these are the candidates in rough order of frequency among business domains. Generate the top three and verify; the first valid result is usually the right one.
| Format | Example | Common at | Note |
|---|---|---|---|
| first.last | maria.lopez@ | Most companies over 50 people, most of Europe | Default guess |
| first | maria@ | Startups, agencies, firms under 30 people | Collides fast as the company grows |
| flast | mlopez@ | US enterprises, finance, law | Often the legacy format at older companies |
| firstlast | marialopez@ | Mid-sized US companies | Check length limits on long names |
| first_last | maria_lopez@ | Some tech companies | Rare but stable where used |
| last.first | lopez.maria@ | German and Japanese companies occasionally | Verify before assuming |
| f.last | m.lopez@ | Government, education | Common on .gov and .edu |
| Double surname handling | maria.lopez-garcia@ or maria.lopez@ | Spain, Latin America, Portugal | Both forms exist; try the hyphenated first |
The company website contact page, press releases, conference speaker lists, GitHub commits, PDF reports, and job postings all leak real addresses. Two is enough to see the format; three confirms it.
Before generating anything, run a random string at the domain through a verifier. If it comes back valid, the domain is catch-all and no guess can be confirmed from outside; see catch-all email checker. In the corpus, 2.3% of non-freemail (business and ISP) domains are catch-all, rising to 12.4% on .org.
Apply the observed format to the target name. Handle accents by stripping them (José becomes jose), hyphens by trying both the hyphenated and the dropped form, and middle names by ignoring them first.
Run the three most likely through the free email verifier. One valid result and the rest invalid is the normal pattern. Two valid results on a non-catch-all domain usually means an alias.
Keep a sheet of domain to format. The next person at the same company costs one check instead of three.
Every company has role addresses: info@, sales@, hello@, press@, careers@. They are easy to find and usually the wrong target for a personalised outreach, but not always.
Press enquiries to press@, partnership proposals to partnerships@, vendor onboarding to procurement@ at larger companies. These mailboxes are staffed and routed. A clear subject line gets read.
Cold sales outreach to info@ or sales@ lands with a receptionist or a competitor's SDR. Reply rates are a fraction of a named contact's. BounceZero flags role addresses so you can keep them out of sequences; the reasons are in what is a role-based email.
A company whose website lists maria.lopez@ next to info@ has told you its personal format for free. Scan the contact and team pages before anything else.
Many role mailboxes forward to several people and some are spam-trap-like. A high share of role addresses in a cold list correlates with complaint rates. Keep them under 5% of any cold send.
The manual method costs minutes per company and works for a dozen targets. Above that, a finder with a domain search, such as Hunter's domain search or Snov's, returns the format and every known address on the domain in one query, and an extension on LinkedIn covers named people. The comparison of find rates and accuracy is in the email finder guide.
Whichever route, the finder tells you the probable address and the verifier tells you whether it exists today. Finders report 65 to 85% accuracy; the 10 to 25% gap is the verification step. For LinkedIn-sourced lists the specific workflow is in the LinkedIn email finder guide.
Confirmed-valid and unknown rates for business addresses by domain type from the BounceZero corpus, April to October 2026. A high unknown share means the company's gateway blocks probes; for those, the generated address is best confirmed by a reply, not a verifier.
| Domain type | Addresses in corpus | Invalid | Catch-all | Unknown |
|---|---|---|---|---|
| .com business | 2,158,955 | 16.4% | 4.4% | 14.7% |
| .org | 56,401 | 24.6% | 12.4% | 25.0% |
| .edu | 17,961 | 32.8% | 8.3% | 18.5% |
| .uk | 21,194 | 17.0% | 3.7% | 10.6% |
| .de | 2,095,440 | 13.9% | 0.0% | 41.2% |
| .fr | 119,582 | 12.1% | 0.5% | 9.3% |
.de unknowns are driven by t-online.de, which returned unknown for 41% of its 2.09 million addresses; corporate .de domains behave closer to .uk.
A generated address that verifies as valid on a non-catch-all domain is as reliable as any finder result. A generated address on a catch-all domain is a guess no matter which tool produced it. The catch-all check comes first.
Eight methods ranked by accuracy
Mechanisms and tools compared
Test a domain before you guess
Why info@ is flagged
100 checks a month
The domain-search finder
Find two or three real addresses on the domain from the website, press releases, PDFs, GitHub or conference pages. The shared shape, such as first.last or flast, is the format. Confirm by generating one more known person's address in that format and verifying it.
Yes, for a handful of contacts. Find the format manually, generate the candidate, and verify it with the free tier of a verifier, which gives 100 checks a month. Finder tools also offer free tiers of 25 to 50 finds a month for testing.
Then the server accepts any address and no outside check can confirm a guess. Verify the domain first; if it is catch-all, treat generated addresses as unconfirmed, send at low volume from a secondary domain, and prefer a reply or a LinkedIn contact as confirmation.
For sales outreach, a named person. Role addresses like info@ and sales@ go to a shared inbox and reply rates are far lower. For press, partnerships and procurement at larger companies, the role address is often the staffed route and the right choice.
On a non-catch-all domain with a single format, the generated address verifies valid in most cases and the verifier catches the exceptions. Accuracy drops at small companies with mixed formats and at companies with many people sharing a name. Verification at the end is what turns the method from a guess into a result.
Generate the candidate, run it through the free verifier, send only what came back valid. 100 checks a month, no card.
Ayoub built BounceZero's 5-stage validation pipeline, its dedicated BGP-announced IP infrastructure, and the Patroni HA PostgreSQL cluster behind every verification. Previously built high-volume email delivery infrastructure. Trained at 1337 Benguerir (École 42 network, 2019). Open-source: bgp_analyzer.
Where leads come from, how finders work, and what a verified lead is - with 2026 corpus data
7.93M addresses: invalid, catch-all and unknown rates by provider and country
Verify an email list in bulk
Free email lookup in 2026
Clay data enrichment explained
Apollo lead generation guide 2026
8 channels that build pipeline, by budget
Continue through related topics