LinkedIn Email Finder - Verified Work Emails from Profile URLs avatar

LinkedIn Email Finder - Verified Work Emails from Profile URLs

Pricing

$30.00 / 1,000 confirmed work emails

Go to Apify Store
LinkedIn Email Finder - Verified Work Emails from Profile URLs

LinkedIn Email Finder - Verified Work Emails from Profile URLs

Paste LinkedIn profile URLs, get each person's work email confirmed by their company's mail server. Reads the public profile (no login, no cookies), finds the employer's domain and checks the likely addresses over SMTP with catch-all detection. $0.03 per confirmed email, other rows free.

Pricing

$30.00 / 1,000 confirmed work emails

Rating

0.0

(0)

Developer

Muhamed Didovic

Muhamed Didovic

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

3 hours ago

Last modified

Share

Paste LinkedIn profile URLs. Get back each person's work email, confirmed by their own company's mail server.

You pay $0.03 for each confirmed email and nothing else - no fee per profile, no fee for catch-all guesses, no fee for profiles where no address could be confirmed. No LinkedIn login, no cookies, no API keys.

Why Use This Scraper?

  • You pay only for confirmed emails. One event, $0.03, charged only when the company's mail server accepted that exact mailbox on a domain that is not catch-all. Every other row is free.
  • Real mailbox check, not a pattern guess. The likely addresses (first.last@, flast@, first@ ...) are asked of the company's mail server one by one, with a random-address test that catches catch-all domains.
  • The company's own pattern first. The company website is scanned for published addresses, so when the company writes j.doe@ or jdoe@, that pattern is tried before the generic ones.
  • No LinkedIn account at risk. Profiles are read the way a logged-out visitor sees them. You never hand over cookies or a session.
  • A row for every profile, with the reason. Each profile gets a status (confirmed, catch-all, unverified, not-found, no-company ...) and a sendDecision (send / review / skip), so you know what to do with the ones that did not confirm.
  • Track record. The same lookup engine runs inside memo23/email-finder: 642 of 661 public runs succeeded over the last 30 days (97.1%).

Price and reliability against the best-known alternative

This actorpequod-labs/linkedin-profile-verified-email
Per confirmed / verified email$0.03$0.028 + $0.004 for the profile = $0.032
Profile read, no email foundfree$0.004
Catch-all best guessfreefree
Public runs succeeded, last 30 days97.1% (642 of 661, same engine in memo23/email-finder)95.4% (719 of 754)

Figures read from the Apify Store on 2026-10-01.

Overview

This actor is for sales, recruiting and growth teams who already have a list of people on LinkedIn - from Sales Navigator, a search export, a CRM, an event attendee list - and need an email they can actually send to.

For each profile URL it returns one dataset row: the person's name and headline, their current employer and its domain, the work email, and the mail server's verdict on that email. The output is flat, so it exports straight to CSV, Excel, Google Sheets or a CRM import.

An email is marked confirmed only when the company's mail server said the mailbox exists and the domain does not accept every address. That is the email you are billed for.

Supported Inputs

URL types

InputExampleSupported
Public profile URLhttps://www.linkedin.com/in/satyanadella/Yes
Country subdomainhttps://uk.linkedin.com/in/jane-doe-4b2a1c9Yes (normalized to www)
URL with tracking parametershttps://www.linkedin.com/in/jane-doe?trk=public_profileYes (cleaned)
Profile URL plus a company domainhttps://www.linkedin.com/in/jane-doe/, acme.comYes - the domain is used for that person

Copy-pasteable input

{
"linkedinUrls": [
"https://www.linkedin.com/in/satyanadella/",
"https://www.linkedin.com/in/dharmesh/"
]
}

Bulk paste

Paste a whole column into Bulk paste - one profile per line. A line can carry the person's company domain after a comma or a tab, which skips the employer lookup for that person:

https://www.linkedin.com/in/satyanadella/
https://www.linkedin.com/in/jane-doe-4b2a1c9/, acme.com
https://www.linkedin.com/in/john-smith globex.io

Both fields can be used together. Duplicates across them are removed, and a duplicate that brings a domain the first mention lacked keeps the domain.

Unsupported inputs

  • Company pages (linkedin.com/company/...), job posts, posts, groups and search result URLs - only /in/ profiles.
  • Sales Navigator lead URLs (linkedin.com/sales/lead/...) - open the lead and copy its public /in/ URL.
  • Names without a profile URL - use memo23/email-finder (name + company domain) instead.
  • Personal emails (Gmail, Outlook.com and the like). This actor finds work emails at the person's current employer.

Use Cases

WhoWhat they use it for
Sales teams and SDRsTurn a Sales Navigator or LinkedIn search export into a sequence-ready list with confirmed work emails
RecruitersReach a candidate at work after finding them on LinkedIn, without InMail credits
Agencies and lead-gen shopsEnrich client prospect lists in bulk and bill only for what confirmed
Founders and growth teamsEmail the people who engaged with a post, attended an event, or follow a competitor
RevOps and data teamsFill missing emails in CRM contacts that already carry a LinkedIn URL

How It Works

How the LinkedIn Email Finder works

  1. Read the profile. Each URL is opened as a logged-out visitor to read the name, headline and current employer. When LinkedIn hides a profile from every logged-out visitor, the search engine's listing for that exact profile is used instead.
  2. Find the employer's domain. The company name is matched to its website (a company-name match, so a namesake domain is not accepted). A domain you supply on the line or in Company domain skips this step.
  3. Learn the company's address pattern. The company website is scanned for published addresses. A direct match, or the pattern they show (first.last, f.last ...), moves to the front of the queue.
  4. Ask the mail server. Up to four likely addresses are checked with the company's mail server in order, plus a random address to detect catch-all domains. The first address the server accepts on a non-catch-all domain is confirmed.
  5. Bill and save. A confirmed email is billed once at $0.03 and saved with its evidence. Every other outcome is saved free, with its status.

Input Configuration

Input fields

FieldTypeDefaultDescription
linkedinUrlsarray of strings-Public linkedin.com/in/... profile URLs. An entry may carry a domain after a comma: https://www.linkedin.com/in/jane-doe/, acme.com.
linkedinUrlsTextstring (textarea)-Bulk paste, one profile per line, optional domain after a comma or tab.
companyDomainstring-Domain used for every profile that has no domain on its own line, instead of the employer read from LinkedIn.
smtpCheckbooleantrueConfirm each email with the company's mail server. Off: unconfirmed best guesses only, nothing billed.
onlyConfirmedbooleanfalseKeep only confirmed emails in the dataset. Off: every profile gets a row (free unless confirmed).
maxItemsinteger1000Most profiles processed per run, after duplicates are removed. Free Apify plans: 25 per run.
maxConcurrencyinteger5Profiles processed in parallel (1-20).

Common scenarios

A list of profiles, every row back for review:

{
"linkedinUrls": [
"https://www.linkedin.com/in/satyanadella/",
"https://www.linkedin.com/in/dharmesh/"
]
}

Everyone works at one company - set the domain once:

{
"linkedinUrlsText": "https://www.linkedin.com/in/jane-doe-4b2a1c9/\nhttps://www.linkedin.com/in/john-smith-81b2a/",
"companyDomain": "acme.com"
}

Import-ready output - only the billed, confirmed rows:

{
"linkedinUrlsText": "https://www.linkedin.com/in/satyanadella/\nhttps://www.linkedin.com/in/dharmesh/",
"onlyConfirmed": true,
"maxItems": 500
}

Spending cap. Set Maximum cost per run in the run options. The actor stops starting new profiles once the cap cannot pay for another confirmed email, and never returns a confirmed email it could not bill.

Output Overview

One row per input profile (or per confirmed profile with onlyConfirmed). Each row has three groups of fields:

  • The person - fullName, title (the LinkedIn headline), companyName, linkedinUrl, your original input line and its position inputIndex.
  • The email - email, status, sendDecision, billed, confidence, pattern, mailboxConfirmed.
  • The evidence - companyDomain and where it came from, the mail provider, the mail server's answer, and the ranked candidate addresses with the server's answer for each.

Rows are written as profiles finish, so their order can differ from your list. Sort by inputIndex to restore it.

The dataset has three views in the console: Emails (the import columns), Verification details and Profile lookup.

Output Samples

Real rows from a platform run on 2026-10-01 (build 0.0.1, two of the five profiles confirmed and billed), trimmed. Email local parts are masked in this README; the dataset carries the full address.

Confirmed, company pattern first.last (billed)

{
"inputIndex": 2,
"linkedinUrl": "https://www.linkedin.com/in/dharmesh/",
"fullName": "Dharmesh Shah",
"title": "HubSpot",
"companyName": "HubSpot",
"companyDomain": "hubspot.com",
"domainSource": "profile",
"email": "d*******.s****@hubspot.com",
"status": "confirmed",
"sendDecision": "send",
"billed": true,
"mailboxConfirmed": true,
"confidence": "high",
"pattern": "first.last",
"smtpStatus": "confirmed",
"emailProvider": "google-workspace",
"mxValid": true,
"candidates": [
{ "email": "d*******.s****@hubspot.com", "pattern": "first.last", "score": 40, "smtp": "accepted" },
{ "email": "d*******@hubspot.com", "pattern": "first", "score": 15 }
]
}

Confirmed after the server refused first.last (billed)

{
"inputIndex": 1,
"linkedinUrl": "https://www.linkedin.com/in/satyanadella/",
"fullName": "Satya Nadella",
"title": "Chairman and CEO",
"companyName": "Microsoft",
"companyDomain": "microsoft.com",
"email": "s****@microsoft.com",
"status": "confirmed",
"sendDecision": "send",
"billed": true,
"confidence": "medium",
"pattern": "first",
"emailProvider": "microsoft-365",
"candidates": [
{ "email": "s****@microsoft.com", "pattern": "first", "score": 15, "smtp": "accepted" },
{ "email": "s****.n******@microsoft.com", "pattern": "first.last", "score": 40, "smtp": "rejected" }
]
}

confidence is medium here because a first-name-only mailbox at a large company could belong to someone else with that first name. The mailbox is real; the attribution is less certain than for first.last.

Catch-all domain (free)

{
"inputIndex": 3,
"linkedinUrl": "https://www.linkedin.com/in/patrickcollison/",
"fullName": "Patrick Collison",
"companyName": "Stripe",
"companyDomain": "stripe.com",
"email": "p******.c*******@stripe.com",
"status": "catch-all",
"sendDecision": "review",
"billed": false,
"confidence": "medium",
"smtpStatus": "catch-all"
}

Profile LinkedIn hides from logged-out visitors (free)

{
"inputIndex": 4,
"input": "https://www.linkedin.com/in/rauchg/, vercel.com",
"companyDomain": "vercel.com",
"domainSource": "input-line",
"fullName": null,
"email": null,
"status": "no-name",
"sendDecision": "skip",
"billed": false
}

Key Output Fields

Person

FieldDescription
inputIndexPosition of the profile in your de-duplicated input (1-based)
inputYour original entry or line
linkedinUrlNormalized profile URL
fullNameName as shown on LinkedIn (or from the URL when the page is hidden)
titleLinkedIn headline or current job title
companyNameCurrent employer as shown on LinkedIn
nameSource / profileSourceprofile, search-result or url-slug

Email

FieldDescription
emailConfirmed address, or the best unconfirmed guess (catch-all / unverified), or null
statusconfirmed, catch-all, unverified, not-found, no-mail-server, no-company, no-name, charge-limit
sendDecisionsend (confirmed), review (catch-all or unverified), skip (everything else)
billedTrue only for the confirmed row that was charged
mailboxConfirmedThe mail server accepted this mailbox and the domain is not catch-all
confidencehigh (confirmed with first and last name), medium, low
patternAddress pattern of email: first.last, flast, first ...

Evidence

FieldDescription
companyDomainDomain the addresses were built on
domainSourceprofile (matched from the employer), input-line, input (Company domain field)
smtpStatusMail server's overall answer: confirmed, rejected, catch-all, unknown, skipped
emailSourcesite-match (published on the company site), site-pattern (company style learned from the site), pattern
emailProviderMail host read from DNS: google-workspace, microsoft-365, proofpoint, mimecast ...
mxValidThe domain accepts email
candidates[]Up to six ranked addresses { email, pattern, score, smtp } with the server's answer for each one checked
checkedAtISO timestamp

FAQ

What exactly am I billed for?

Only person-email-confirmed, $0.03, once per profile whose work email the company's mail server confirmed on a domain that is not catch-all. The billed field shows it on every row. Profiles without a confirmed email cost nothing, whatever the reason.

Why do some rows say catch-all?

Some companies' mail servers accept mail for any address, so no checker can tell a real mailbox from a made-up one there. You get the most likely address for free, marked catch-all and sendDecision: review.

Is an email sent to the person?

No. The check stops before any message is sent: the server is asked whether it would accept mail for the address, and the conversation ends there.

Do I need a LinkedIn account or cookies?

No. Profiles are read as a logged-out visitor sees them. No session, cookie or account of yours is used, so nothing on your LinkedIn account is at risk.

What if LinkedIn shows the wrong company, or none?

Add the right domain after the URL on that line (..., acme.com), or set Company domain for the whole list. A domain you give always wins over the one read from LinkedIn.

Why did a profile return no-name?

A few members hide their public profile from every logged-out visitor, and the search engine had no listing for it either. When the URL itself spells a name (jane-doe-4b2a1c9), the actor still uses that; a one-word URL (rauchg) leaves nothing to build an address from.

Does it find personal emails or phone numbers?

No. Only work emails at the person's current employer. For phones and company inboxes, see memo23/email-finder.

How fast is it?

Most profiles take 5-10 seconds, nearly all of it the mail server check; slow servers such as Microsoft 365 can take 20-30 seconds. With the default concurrency of 5, a list of 1,000 profiles takes roughly 20-40 minutes.

Can I cap what a run costs?

Yes. Set Maximum cost per run. The actor stops starting new profiles when the cap cannot pay for another confirmed email, and a confirmed email it cannot bill is withheld (status: charge-limit), never given away and never overcharged.

Is there a free trial?

Free Apify plan users can process up to 25 profiles per run, billed the same way from their monthly platform credit.

Support

Additional Services

Need something beyond the standard output? I build and maintain custom actors and data pipelines:

  • Email lookups wired into your CRM or outreach tool on a schedule
  • Custom fields, filters or export formats for your workflow
  • Private or dedicated actors for high-volume or compliance-sensitive use

Reach out via the Issues tab or email and describe what you need.

Explore More Scrapers

Full list at apify.com/memo23.

🤖 For AI Agents & LLM Apps

Compact reference for AI agents calling this actor via the Apify MCP server or the Apify API (actor: memo23/linkedin-email-finder).

Purpose: LinkedIn /in/ profile URL -> the person's work email, confirmed by the company's mail server over SMTP with catch-all detection. No LinkedIn login.

Minimal input:

{ "linkedinUrls": ["https://www.linkedin.com/in/satyanadella/"], "maxItems": 10 }

Output: one row per profile - inputIndex, input, linkedinUrl, fullName, title, companyName, companyDomain, domainSource, email, status, sendDecision, billed, mailboxConfirmed, confidence, pattern, smtpStatus, emailSource, emailProvider, mxValid, candidates[] {email, pattern, score, smtp}, checkedAt.

Behaviors an agent should know:

  • Use only rows with status: "confirmed" (equivalently sendDecision: "send") as deliverable; catch-all and unverified rows carry an unconfirmed guess.
  • Billing: person-email-confirmed $0.03 per confirmed row, nothing else. billed is true on exactly those rows.
  • onlyConfirmed: true drops every non-billed row from the dataset.
  • A domain after the URL ("https://www.linkedin.com/in/x/, acme.com") or companyDomain overrides the employer read from LinkedIn.
  • Rows arrive out of input order; sort by inputIndex.
  • smtpCheck: false returns pattern guesses only and bills nothing.
  • Free Apify plans: 25 profiles per run.

⚠️ Disclaimer

This Actor is an independent tool and is not affiliated with, endorsed by, or sponsored by LinkedIn Corporation or Microsoft Corporation, or any of their subsidiaries. All trademarks mentioned are the property of their respective owners.

The actor accesses only publicly available LinkedIn profile pages - no authenticated endpoints, paid features, or content behind the linkedin.com login wall - and checks addresses with mail servers without sending any message. Users are responsible for ensuring their use complies with LinkedIn's Terms of Service, applicable data-protection and anti-spam law (GDPR, CCPA, CAN-SPAM, etc.), and any contractual obligations of their own organization.


SEO Keywords

linkedin email finder, linkedin profile email finder, find email from linkedin profile, linkedin to email, linkedin email extractor, linkedin email scraper, Apify linkedin email, work email finder, verified email finder, SMTP email verification, catch-all email detection, b2b email finder, bulk linkedin email lookup, sales navigator email finder, prospect email list, recruiter email finder, cold outreach emails, lead enrichment, CRM email enrichment, Hunter alternative, Apollo alternative, Lusha alternative, RocketReach alternative