Reverse Email Lookup — Email to Name, LinkedIn & Company avatar

Reverse Email Lookup — Email to Name, LinkedIn & Company

Pricing

from $3.00 / 1,000 enriched contacts

Go to Apify Store
Reverse Email Lookup — Email to Name, LinkedIn & Company

Reverse Email Lookup — Email to Name, LinkedIn & Company

Find the person and company behind any email using free public OSINT sources. Name, LinkedIn URL, job title, company domain, location, confidence score and per-field provenance. BYOK waterfall + MCP. Pay only for matches; misses free.

Pricing

from $3.00 / 1,000 enriched contacts

Rating

0.0

(0)

Developer

Creator Fusion

Creator Fusion

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

6 days ago

Last modified

Categories

Share

Reverse Email Lookup — Email to Name, LinkedIn, Company & OSINT Intel

What does Reverse Email Lookup do?

Give it a list of email addresses and it returns, for each one, the person behind it (name, headline, LinkedIn URL, location, photo, social profiles) and the company behind the domain (name, description, logo, socials, tech stack, domain age, GitHub org, news, SEC status), plus email-intelligence signals (mail provider, SPF/DMARC, house email format, optional breach count). It uses free, public OSINT sources only — no login, no cookies, no paid data provider, no API key required. You pay only for rows where a person was found; misses are free.

It is a Reverse Contact / Clay / Apollo alternative for people who want transparent, source-attributed enrichment at a fraction of the price.

What you get per email

FieldExample
fullName, firstName, lastNameDavid Heinemeier Hansson
headline / jobTitleCTO at 37signals
company, companyDomain, companyWebsiteLinux Foundation, linux-foundation.org
linkedinUrlhttps://www.linkedin.com/in/…
location, photoUrl, twitterUrl, githubUrl, personalWebsitePortland, OR
emailProvider, isFreeProvider, isDisposable, isRoleAddressGoogle Workspace / false / false / false
confidenceScore (0–100), confidenceLevel, matchType, confidenceReasons[]75 · high · exact · gravatar-profile, github-corroborated
notFoundReason on missesrole-mailbox, disposable-email, domain-does-not-resolve, no-public-footprint
checkedAt, sourcesHit[]freshness timestamp + which sources answered

Every row is flat and CSV-ready. Nested objects carry the detail:

  • person — Gravatar profile, GitHub profile, Keybase proofs, verified social accounts, LinkedIn candidates with scores, pages on the web that cite the email.
  • companyProfile — name, legal name, description, logo, socials (LinkedIn/X/Facebook/Instagram/YouTube/GitHub/Crunchbase), phones, public emails, address (JSON-LD), tech stack, domain registration date & age, registrar, nameservers, certificate-transparency subdomain count and interesting hosts (vpn., sso., dev., jira., …).
  • emailIntel — MX/SPF/DMARC, mail provider, optional aggregate breach signal (count, names, latest date — never raw records) and EmailRep reputation.
  • sourceLog — per-source hit / latency / HTTP status, so you can see exactly where each fact came from.

Sources (all free)

SourceWhat it contributesTrust
Gravatardisplay name, photo, location, bio, verified social linksHigh — profile is bound to the exact email hash and Gravatar verifies ownership
Keybasecryptographically-proven Twitter/GitHub/Reddit/domain identitiesHigh
GitHubprofile by public email (+ commit-author search with token)Medium — the public email on GitHub is self-declared; weighted up when another source agrees on the name
Web search (Bing → DuckDuckGo fallback)pages citing the email, name harvesting, LinkedIn discovery by name + companyMedium; scored per candidate
Company websitename, description, logo, socials, phones, JSON-LD org data, tech fingerprintHigh for company facts
DNSMX / SPF / DMARC, mail provider fingerprint, SaaS footprint from TXT verification recordsHigh
RDAPdomain registration date, registrar, nameserversHigh
crt.shcertificate-transparency subdomain footprintHigh (service is slow / flaky; retried)
Company-site email crawl (/about, /team, /contact, /leadership…)is this exact email published by the company itself? house email format (first.last, f.last…) and whether the input fits itVery high when cited; format check is a soft signal
Wayback Machine CDXfirst archived date, site changes in last 90 daysHigh
Hacker News (Algolia)posts citing the email or name; HN user whose profile cites the email/domainMedium–high
GitHub organisationorg matched to the domain: repos, languages, stars, last pushHigh
Google News RSScompany mentions, last-30-day count, latest headlinesMedium
SEC EDGARpublic-company detection: CIK, SIC, state, recent filingsHigh
Have I Been Pwned (optional key)aggregate breach count, breach names, latest dateHigh
EmailRep.io (optional key)reputation, first-seen, profiles seenMedium

Domain-scoped lookups (DNS, RDAP, crt.sh, website) are cached per company inside a run, so 500 people at the same company cost one set of company lookups.

How to use it

  1. Paste your emails into the Emails field (one per line) or pass emails[] via API.
  2. Optionally untick sources you don't need and set Max emails as a cost cap.
  3. Click Start. Results land in the dataset as flat rows — export as CSV, JSON or Excel, or pipe to Zapier/Make/Sheets.

Input

{
"emails": ["jane.doe@acme.com", "dhh@hey.com"],
"sources": ["dns", "rdap", "gravatar", "github", "keybase", "crtsh", "website", "search"],
"maxEmails": 1000,
"maxConcurrency": 3,
"githubToken": "ghp_… (optional, raises GitHub limits + enables commit-author search)",
"hibpApiKey": "… (optional, enables aggregate breach signal)",
"proxyConfiguration": { "useApifyProxy": true }
}

Use Apify residential proxy for best results: search engines honour site: and exact-phrase operators far more reliably from residential IPs than from datacenter ranges.

Sample output

{
"email": "dhh@hey.com",
"success": true,
"matchType": "probable",
"confidenceScore": 55,
"confidenceLevel": "medium",
"notFoundReason": null,
"fullName": "David Heinemeier Hansson",
"firstName": "David",
"lastName": "Hansson",
"headline": "Creator of Ruby on Rails, CTO 37signals",
"company": null,
"companyDomain": null,
"location": null,
"linkedinUrl": "https://www.linkedin.com/in/david-heinemeier-hansson-374b18221",
"emailProvider": "Free webmail",
"isFreeProvider": true,
"isDisposable": false,
"isRoleAddress": false,
"checkedAt": "2026-09-24T09:52:16.071Z",
"sourcesHit": ["search", "hackernews"],
"confidenceReasons": ["email-indexed-on-web", "name-from-web-listing", "linkedin-name-match", "hackernews-footprint"],
"person": { "webMentions": [{ "url": "https://world.hey.com/dhh", "title": "David Heinemeier Hansson" }], "linkedinCandidates": [ "…" ], "hackernews": { "emailMentions": [ "…" ] } },
"companyProfile": null,
"emailIntel": { "domainResolves": null, "acceptsMail": null, "breachCount": null },
"sourceLog": { "gravatar": { "hit": false, "ms": 378, "status": 404 }, "search": { "hit": true, "ms": 613 } }
}

A corporate address additionally fills companyProfile (name, description, logo, socials, phones, tech stack, domain age, GitHub org, news, SEC status) and emailIntel (MX/SPF/DMARC, provider).

How much does it cost?

Pay-per-event. You are charged only for rows where a person was found.

EventPriceNotes
Enriched contact (record-found)$0.004 — $4 per 1,000 matchesCharged when success: true
Actor start$0.00005Apify's standard start event
Misses, role mailboxes, disposable and invalid emailsFreeStill returned as rows with notFoundReason so you can filter

Example: 1,000 cold emails with a 35 % match rate ≈ 350 × $0.004 = $1.40. Set Maximum cost per run in the run options to cap spend; the Actor stops cleanly when the limit is hit.

Compared with the store leaders at $10–150 per 1,000 and Reverse Contact at ~$60 per 1,000 credits, this is 60–97 % cheaper — and you can read exactly which public source every fact came from.

Why use this instead of a paid enrichment API?

  • No vendor lock-in or hidden data. Every field carries provenance in sourceLog; nothing comes from resold LinkedIn dumps.
  • Cheapest first pass. Run your whole list here, then send only the misses to a $10–150/1k provider.
  • Signals the resellers don't give you: confidence score with reasons, house email-format check, breach signal, tech stack, domain age, public-company flag.
  • Agent-ready. Limited permissions, flat JSON rows, works from the Apify MCP server.

Provenance on every field

Each row carries fieldSources — a map from field to the source that supplied it ("linkedinUrl": "search:email-mention", "location": "gravatar", "company": "byok:prospeo") — plus publicSourcesOnly: true|false. That is your audit trail for GDPR Art. 6(1)(f) assessments and DPIAs: you can show, per contact, that the data came from a public source, when it was checked, and that no purchased broker data was involved. No other enrichment vendor exposes this.

Bring your own keys — waterfall the misses

Free public sources run first and are the default. If you add a vendor key, addresses the public sources can't resolve are sent to your vendor account (Prospeo, Reverse Contact or People Data Labs), the result is merged, and every vendor-supplied field is stamped byok:<vendor> in fieldSources. You still pay us only our $0.004 per match; the vendor bills you directly at their rate (Prospeo 1 credit, Reverse Contact 2 credits, PDL 1 credit — all three are free on a miss).

Why this beats running the vendor first: on a typical cold B2B list 30–60 % of addresses have a public footprint, so the waterfall cuts your vendor credit spend by that much, and the rows that never touch a vendor stay fully public-sourced.

Options: byokMode = on-miss (default) / always / off; byokOrder to change vendor precedence; byokMobile to ask Prospeo for the mobile (10 credits, off by default).

Use it from an AI agent (MCP) or as a live API

The Actor runs in Standby mode, so it also answers synchronously:

  • MCP: point any MCP client (Claude Desktop, ChatGPT, Cursor, Apify MCP server) at the Standby URL shown on the Actor's Endpoints tab, path /mcp, with your Apify token as Bearer auth. Tools: enrich_email(email, sources?) and enrich_emails(emails[]). Each call returns a one-line summary plus the full row as structured content.
  • JSON: GET <standby-url>/enrich?email=jane@acme.com or POST <standby-url>/enrich with {"emails":[…]} (max 25 per call). Same row shape as the dataset.

Standby calls are charged the same way: only matched records.

Integrations

Use the dataset with any Apify integration — Zapier, Make, n8n, Google Sheets, webhooks — or call it from code:

const { ApifyClient } = require('apify-client');
const client = new ApifyClient({ token: process.env.APIFY_TOKEN });
const run = await client.actor('apricot_blackberry/reverse-contact-osint').call({ emails: ['jane.doe@acme.com'] });
const { items } = await client.dataset(run.defaultDatasetId).listItems();

FAQ

Is this legal / GDPR-compliant? It queries only public, unauthenticated endpoints and returns aggregate breach metadata, never raw records. You are the data controller for how you use the output; the usual legitimate-interest basis (GDPR Art. 6(1)(f)) and CCPA rules apply to B2B outreach.

Why did an email return a miss? Check notFoundReason: role-mailbox (info@, sales@…), disposable-email, domain-does-not-resolve, or no-public-footprint (the person has no public trace linked to that exact address). Misses are free.

Why is a LinkedIn URL sometimes missing when the name is found? LinkedIn discovery relies on web search. Enable Apify residential proxy in the input — search engines honour exact-phrase and site: operators far more reliably from residential IPs.

Can I bring my own keys? Yes: githubToken raises GitHub limits and enables commit-author search; hibpApiKey turns on the breach signal; emailrepApiKey improves EmailRep limits. All are optional and stored as secrets.

Does it verify that the email is deliverable? It checks the domain accepts mail (MX) and whether the address fits the company's published email format. It does not do SMTP verification.

Confidence model

Identity-anchored hits (Gravatar hash, Keybase proof, LinkedIn page that cites the email) score highest. Name inference from first.last@ alone never produces a match on its own — it needs corroboration. Disposable domains, role mailboxes and dead domains are penalised and returned as explicit misses with a notFoundReason, so you can filter before outreach.

Extending

src/enrich.js holds a SOURCES registry. Add your own module as { fn, phase, scope } — phase 1 runs in parallel, phase 2 receives the merged name/company guesses. Each source returns { hit, data } and gets a row in sourceLog automatically.

Data handling

Only public, non-authenticated endpoints are queried. Breach data is aggregate-only by design (count / names / dates); raw records, passwords and hashes are never fetched or stored. Respect applicable law (GDPR Art. 6(1)(f), CCPA) and each site's terms when using the output for outreach.


Built by Creator Fusion LLC. Related actors: LinkedIn → email, company enrichment from domain, Apify Store lead-gen suite.