WP Finder

How to Extract Emails From Websites (Manual and Bulk)

By WP Finder · Updated · 6 min read

How to Extract Emails From Websites (Manual and Bulk)

If you do outreach for web design, SEO or any B2B service, sooner or later you need to extract emails from websites. Sometimes it is one address for one prospect; sometimes it is a column of emails for a few hundred businesses. This guide covers the manual methods that work on almost any site, how to deal with hidden or obfuscated addresses, how to handle bulk extraction, how to keep your data clean, and the compliance basics you should not skip.

Where to extract emails from websites: the usual places

Before you start, it helps to know where to look. Most small and medium business sites put contact details in a handful of predictable places:

  • The footer, often next to the phone number and address.
  • The contact page (/contact/, /contact-us/, /get-in-touch/).
  • The about or team page, which sometimes lists individual staff emails.
  • Legal pages such as the privacy policy or terms, which often include a contact address for data requests.
  • Blog author boxes on content-heavy sites.

Manual methods to extract emails from a website

1. Search the visible page

Open the homepage and press Ctrl+F, then search for @. Repeat on the contact and about pages. It sounds basic, but it is the fastest way to find a visible address.

2. Search the page source

Some emails are only in the code, for example inside a mailto: link behind a button that says “Email us”. Press Ctrl+U to view the source and search for mailto: or @. You may also find addresses in structured data (look for "email" in JSON-LD blocks).

3. Check the privacy policy

Privacy policies often name a contact address for data questions. It is frequently a general mailbox, but on small business sites it may go straight to the owner.

4. Use a site search on Google

Search site:example.com "@example.com" to find pages on that domain that mention an email at the same domain. It can turn up staff pages or old blog posts you would not find by browsing. Our guide to Google search operators for lead generation has more patterns like this, and Google lists the basics in its search help.

How to extract emails from websites that hide them

Many websites deliberately hide email addresses from basic scrapers to reduce spam. You will commonly see:

What you see What it means How to read it
info [at] example [dot] com Text obfuscation Replace [at] with @ and [dot] with .
“[email protected]” Cloudflare email protection The real address is decoded by JavaScript in your browser; viewing the live page usually shows it
An image of an email Image-based hiding Type it out by hand
Only a contact form No public email Use the form, or look for a phone, WhatsApp or social profile instead

A contact form with no email is a clear signal that the owner prefers that channel. Respect it. You can still introduce yourself through the form with a short, relevant message.

How to extract emails from websites in bulk

Manual methods are fine for a few sites. For hundreds, you need a more systematic approach. An email extractor from website lists generally works like this:

  1. Input: a list of domains, or a keyword search that produces one.
  2. Crawl a few key pages per site: homepage, contact, about. Crawling every page of every site is slow and rarely adds much.
  3. Detect emails in visible text, mailto: links and common obfuscation formats, including Cloudflare protection.
  4. Collect other contacts such as phone numbers and social links while it is there.
  5. Output a clean spreadsheet with one row per site.

If you are starting from a domain list, prepare it properly first: our guide on finding emails from a list of domains covers cleaning, normalising and deduping.

Things to watch when you extract emails from websites

  • False positives: strings like image@2x.png look like emails but are not. Good extractors filter these out.
  • Third-party addresses: emails belonging to the web designer, theme author or a plugin vendor sometimes appear in the code.
  • Placeholder addresses such as you@example.com in form fields.
  • Timeouts and firewall pages that return no content; re-check these later rather than marking them empty.

Data quality: dedupe, role vs personal, and verification

Extracted emails are raw material. A little cleaning makes a big difference to replies and to your sending reputation.

Remove duplicates

The same address often appears on several pages, and the same business may appear twice in your list. Keep one row per business and one copy of each email. In Excel or Google Sheets, use “Remove duplicates” on the email column.

Separate role and personal addresses

Role addresses (info@, hello@, sales@, office@) go to a shared inbox. Personal addresses (jane@, j.smith@) reach an individual. For small businesses, info@ is often read by the owner, so don’t discard it. For larger firms, a named contact usually gets a better response. Add a column marking each type so you can tailor your message.

Watch for addresses you should not use

Drop addresses like noreply@, privacy@ or abuse@, and anything clearly meant for a different purpose such as job applications or complaints.

Verify before sending

Emails on old pages may no longer work. Sending to invalid addresses causes bounces, which can hurt your sender reputation. Run your list through an email verification service before a campaign, and set up SPF, DKIM and DMARC on your domain; see our deliverability guide.

Compliance basics

Being able to find an email does not automatically mean you can send anything you like to it. General points to keep in mind (not legal advice):

  • Only collect emails that are publicly published on the business’s own website.
  • Make sure your message is relevant to the recipient’s business role.
  • Identify yourself clearly and include an easy way to opt out, and honour opt-outs promptly.
  • Keep a do-not-email list so people who opted out are never contacted again.
  • Understand the rules where you and your recipients are, such as GDPR and PECR in the UK and EU and CAN-SPAM in the US. Rules for contacting individuals and sole traders can differ from those for companies.

Our article is cold email legal? gives a fuller overview.

Extract emails from websites with WP Finder

WP Finder pulls public emails from each site’s homepage, contact and about pages, including Cloudflare-protected addresses and “name [at] site” style text. It works on a keyword and country search or your own domain list, checks up to 40 sites at once, and also collects phone and WhatsApp numbers and social links. Results export to Excel or CSV with one column per contact type, or you can copy all emails at once. It also tells you which sites run WordPress, which is useful if you sell WordPress services. See the features page or try the first 150 sites free from the download page.

Conclusion

To extract emails from websites reliably, start with the obvious places (footer, contact, about, privacy policy), check the source for mailto: links, and decode obfuscated addresses. For larger lists, use a bulk email extractor from website lists, then dedupe, label role versus personal addresses, verify and respect opt-outs. Clean data and relevant messages matter far more than sheer volume. For the next step, read how to find a website owner’s email.

FAQ

How do I find an email address on a website that doesn’t show one?

Check the page source for mailto: links, look at the privacy policy, and try a Google site: search. If there is truly no email, use the contact form, phone number or social profiles instead.

What does “[email protected]” mean on a website?

It means the site uses Cloudflare email protection. The real address is decoded in your browser by JavaScript, so it usually appears when you view the live page normally.

Should I use info@ emails I extract from websites?

For small businesses, often yes, because the owner usually reads that inbox. For larger organisations, try to find a named contact relevant to your offer.

Is it legal to extract emails from websites?

Collecting publicly published business emails is common, but how you use them is regulated by laws such as GDPR, PECR and CAN-SPAM. Send relevant messages, identify yourself, offer an opt-out and honour it. This is not legal advice.