Run a lookup

How-to

How to find someone by email address, in five steps

The steps are ordered on purpose. Doing them out of order is how an afternoon disappears.

9 min read The DetectiveCheck team
EmailHow-to
A lit suspension bridge running into fog

The short answer

Find someone by email address in five steps: normalise the address to its canonical form, confirm it exists, check which services have an account registered to it, date it against breach records, then pivot to any handle or display name the search returned and run that instead.

  • Normalising first is not pedantry. Skip it and you miss accounts registered under the variant.
  • Step five returns more than steps one to four combined, and it is the one people stop before reaching.
  • A step that returns nothing is still a step. Which kind of nothing decides whether you continue.
  • The whole sequence is minutes, not an afternoon, provided you do it in this order.

What do you need before you start?

The address, and one honest answer about why you want it, written down before you begin rather than reconstructed afterwards.

Nothing else is required. You do not need the person's name, and having it is less useful than people expect — a name reaches 13 registers here against 71 sources for an address, so the address you already have is the stronger identifier of the two.

The reason to write down the purpose is legal rather than bureaucratic. In the EU and the UK, processing public personal data needs a lawful basis, and a basis you cannot describe later is one you did not have. It costs a sentence now.

If the address is at a company domain rather than a free provider, note that too. It changes what step three is likely to return.

1Normalise2Verify3Accounts4Date it5Pivot1Normalise2Verify3Accounts4Date it5Pivot
The order matters. Each step decides what the next one is worth.

Step one: which form of the address should you use?

The canonical one, which is often not the one you were given, and getting this wrong quietly costs you results in every step after it.

[email protected] and [email protected] reach the same mailbox, because Gmail ignores dots and everything after a plus sign. A service that was signed up to with the variant will not match a search for the plain form unless somebody normalises first.

The catch is that this is provider-specific. Gmail behaves this way; plenty of providers treat dots as significant, so normalising blindly is as wrong as not normalising at all. Our email lookup does this by provider, so paste the address in whatever form you have it.

Keep the original too. If a later step turns up an account under the exact variant you were given, that tells you which form the person actually types.

Step two: is the address real?

Establish this before spending effort on it, because a plausible address nobody ever created will come back empty from every source and look exactly like a careful person.

Two cheap signals settle it. The domain either resolves and accepts mail or it does not, which rules out invented domains immediately. And a breach appearance is proof of existence: an address in a 2016 dump was real in 2016, whatever it is doing now.

This step is fast and it changes how you read everything else. An empty report on a confirmed-real address means something about the person; an empty report on an address that may never have existed means nothing at all.

It is also the step that saves the most time, because it is the one that tells you to stop.

Nobody does this in one move. The value is in the second pass, on something the first pass handed you.

Nobody does this in one move. The value is in the second pass, on something the first pass handed you.

Step three: which accounts is it registered to?

This is the bulk of the answer and the reason the whole procedure works.

Sign-up and password-reset forms have to reveal whether an address is already in use, so any service can be asked. Seventy-one sources answer for an address on DetectiveCheck, in parallel, and the replies are merged rather than listed, because one account often comes back from three sources under three names. The mechanism is covered properly in why platforms answer at all.

Read the shape rather than the count. Accounts on services with no public profile — retail, delivery, ticketing — say the address is used for ordinary life. Accounts on forums and code hosts say something different, and hand you step five.

Forty hits on throwaway services is a weaker result than four on places somebody would have to care about.

Step four: how old is the address?

Breach records date it, and a date is what turns a list into a story.

Each known breach containing the address is a year in which it demonstrably existed and was used to register something. Sixty appearances spread from 2012 to 2024 describes a person who has been online for a decade. Two appearances, both from last year, describes something else entirely, and that difference is usually the finding.

Have I Been Pwned does this part free and is the authority on it. If dating the address is your whole question, you can stop here without paying anybody, and that is worth saying plainly.

What a full lookup adds is the join between the dates and the accounts: knowing an address leaked in 2016 matters more once you know which services still hold it.

Step five: what handle does it lead to?

The step people skip, and the one that returns more than the four before it put together.

Steps three and four routinely hand back a display name, an avatar or a profile URL whose last segment is a handle. That handle is a new identifier, and running it through the username lookup reaches 71 platforms that were never going to answer a question about an address.

It works because of an asymmetry in how people behave. Most of us hold several addresses and hand out a different one per context deliberately. Almost nobody holds several handles. So step five moves you off the identifier somebody was careful with and onto the one they picked at fourteen and never thought about again.

What if a step returns nothing?

Work out which kind of nothing before deciding whether to continue, because the two look identical in a badly built report and mean opposite things.

Sources answered, found nothing. That is a finding. Continue: it usually means a young address, one used only to receive mail, or one that was never registered anywhere. If you are checking whether somebody who contacted you has any history, you already have your answer.

Sources failed to answer. That is not a finding. In a run measured in July 2026, 11 of 74 sources errored and 4 were rate-limited — a fifth of the run. Try again later rather than concluding anything, and treat any tool that shows you only the hits as one that has hidden this distinction from you.

What can these five steps not tell you?

Four things, and each is promised by somebody selling something.

None of these is a limit of one product. They are limits of what public sources contain, so a competitor claiming otherwise is describing a database rather than a search.

There is a fifth limit that is legal rather than technical. In the United States, using any of this to decide employment, housing, credit, insurance or tenancy falls under the Fair Credit Reporting Act, and a consumer lookup service is not a consumer reporting agency. That use is not permitted here.

  • A name, reliably. A work address usually gives one because the domain identifies the employer. A free-provider address gives one only if the owner attached it to something public.
  • A home address. Not attached to an email address in any public source. Anything offering one is selling a broker file of unknown age.
  • Who was typing. The procedure describes an address and what is attached to it. Addresses get shared, sold and stolen.
  • Anything behind a login. Existence is public; contents are not.

How long does the whole thing take?

Minutes, if you keep the order, and most of that is waiting rather than working.

Steps one to four happen in a single lookup: paste the address into the email lookup, and the normalisation, the existence check, the account checks and the breach records all run in parallel. A run measured in July 2026 took 24 seconds and returned 19 confirmed accounts and 60 breach records out of the 74 sources checked then.

Step five is a second lookup on whatever the first one handed you, and it is the only part that needs a decision from you: which of the returned names is worth running.

Every finding carries its source and a confidence rating, and the sources that errored are listed beside the ones that answered. You can see the whole shape in the sample report before creating an account.

Common questions

How do I find someone by their email address?

In five steps and in this order: normalise the address to its canonical form, confirm it actually exists, check which services have an account registered to it, date it against known breaches, then pivot to any handle or display name that came back and run that instead. The last step usually returns the most.

Why does normalising the address matter?

Because a service signed up to with a variant will not match a search for the plain form. Gmail ignores dots and everything after a plus sign, so [email protected] and [email protected] are one mailbox. Other providers treat dots as significant, so normalisation has to know the provider rather than applying one rule everywhere.

Can I find someone's name from their email address?

Sometimes. A work address usually gives a name, because the domain identifies the employer and the part before the at sign is normally built from a real name. A free-provider address gives one only where the owner attached it to something public. No tool can produce a name that was never published.

What is the most useful step?

The fifth, and it is the one people stop before reaching. Steps three and four hand back display names and profile URLs, and each of those is a handle. Running a handle reaches 71 platforms that would never answer a question about an email address, because people reuse one handle for years and several addresses in a year.

How long does an email lookup take?

Under half a minute for the first four steps, because the sources run in parallel rather than one after another. A run measured in July 2026 took 24 seconds and returned 19 confirmed accounts and 60 breach records. Step five is a second lookup on whatever the first one returned.

What if the email address returns no results?

Check whether the sources answered and found nothing, or failed to answer at all. The first is a finding: usually a young address, one used only for mail, or one never registered anywhere. The second is not: in a run measured in July 2026, 15 of 74 sources never answered, and that is a reason to retry rather than a conclusion.

Is it legal to look up an email address?

Searching publicly available sources is legal in the United States and the EU. Use is restricted: in the US, deciding employment, housing, credit, insurance or tenancy from a lookup falls under the Fair Credit Reporting Act and is not permitted with a consumer service. In the EU and UK, public personal data still needs a lawful basis under the GDPR.

Will the person know I searched for their address?

No. The steps query public sources and the account-existence behaviour that platforms expose to anybody who asks. Nothing is sent to the address: no mail, no password reset, no notification of any kind. What can reach them is what you choose to do after the search, such as writing to the address you confirmed.

In short

Five steps, and the order is the method: normalise, verify, find the accounts, date it, then pivot. Step five returns more than the first four combined and is the one most people never reach.

A step returning nothing is still information, provided you can tell a source that answered and found nothing from a source that failed to answer. Roughly a fifth of a typical run is the second kind.

Written by the DetectiveCheck team

We build the lookup engine this site runs on, so the numbers in these guides are the ones our own reports use: 71 sources against an email address, 71 platforms against a username, 13 registers against a name, and 8 against a phone number. Where a module is thin, we say so rather than round it up.

Run one yourself

Create an account and the first report is a couple of minutes away. Nobody you look up is told.

Create my account

Plans from $15 a month. Cancel in one click. Or read a sample report first.

Try it on something you already have