Email lookup
Reverse email lookup: how to find out who owns an email address
Got a message from an address you don't recognize? Here's how to find out who's behind it: free checks first, a full lookup when you need one, and how to tell a real match from a coincidence.
What is a reverse email lookup?
A reverse email lookup starts from an address and works backward to the person or company behind it. It checks which sites the address is registered on, which data breaches it shows up in, and which public profiles, photos or domains link back to it. The goal is simple: put a name and a context on an address you don't know.
A good lookup can return:
- Accounts registered with the address, on social networks, shopping sites and apps.
- A name and a photo, when a public profile uses the address. Gravatar alone has more than 80 million profiles tied to email addresses (Gravatar).
- Breach history: which leaked databases contain the address, and roughly when it was in use.
- Domain details, when the address sits on a company or personal domain rather than Gmail or Outlook.
What it can't return: the contents of the inbox, the password, or a home address. Anything that promises those is either lying or breaking the law.
Why check an unknown email address?
Because email is still how most scams start. In 2024, email was the most reported way scammers first contacted people: 371,651 reports, or 25% of the fraud reports that named a contact method, ahead of phone calls at 19% and texts at 16% (FTC Data Book 2024). Reported fraud losses that year passed $12.5 billion.
Businesses see the same thing from the other side. The FBI received 24,768 business email compromise complaints in 2025, with losses above $3 billion, and phishing or spoofing was the most reported crime type of all, with 191,561 complaints (FBI IC3).
So the everyday reasons are practical. Is this "recruiter" real? Is this invoice from the supplier we know, or from a lookalike address? Is the person I met online who they say they are? A few minutes of checking answers most of these before any money or data moves.
How to do a reverse email lookup for free
These six checks cost nothing and need no special tools. Do them in order: each one tells you what to look for in the next.
- Search the exact address in quotes. Put it in quotes on Google and Bing, then search the part before the @ on its own. People reuse the same handle for years, so
jdoe1987in an email often matchesjdoe1987on a forum or a social network. - Read the full headers. In Gmail, open the message, click the three dots and choose "Show original" (Google). In Outlook, use "View message source". Look at the SPF, DKIM and DMARC results and compare the From address with the Reply-To. A mismatch there is a classic sign of a fake.
- Check the domain. If the address isn't on a free provider, open the domain in a browser and look up its registration record. A company site that was registered last week and sends you invoices is a red flag.
- Look for a profile photo. Many accounts pull their avatar from Gravatar through the email address. Messaging and video apps sometimes show a name or photo once an address is saved as a contact.
- Check breach exposure. Have I Been Pwned indexes more than 17.8 billion breached accounts from 1,038 sites (HIBP, September 2026). The list of breaches tells you which services the address used and roughly when it was active.
- Write down where each clue came from. A screenshot and a URL for every finding. You'll need it in the next step, and you'll need it if this ever ends up with a bank, an employer or the police.
Don't use "forgot password" forms to test an address. It's a common trick, and it tells the owner someone is poking at their accounts: many services email them the moment a reset is requested. Passive checks leave no trace on the other side.
Free checks vs. a full email lookup
Manual checks work well when the address is public. They struggle when it isn't, because the useful signal is spread across hundreds of sites that don't show up in search. That's the gap automated tools fill. The open-source tool Holehe, for example, checks whether an address is registered on more than 120 sites without notifying the owner (Holehe).
| Method | What it tells you | Cost | Alerts the owner? |
|---|---|---|---|
| Search engines | Public pages that mention the address or handle | Free | No |
| Email headers | Whether the sender is authenticated, where replies really go | Free | No |
| Have I Been Pwned | Breaches the address appears in | Free | No |
| Holehe (command line) | Sites where the address is registered | Free, needs Python | No |
| "Forgot password" forms | Whether one site knows the address | Free | Often yes |
| Rocksosint | Registrations, breaches and public profiles from 200+ sources, each linked to where it was found | From $15/month | No |
The trade-off is time. Six manual checks take twenty minutes for one address and still miss most registrations. An automated lookup runs them together and puts every result next to its source, so you can check it yourself.
How do you know a result is really the same person?
This is where most lookups go wrong. Verizon found stolen credentials were the way in for 22% of breaches in its 2025 report (Verizon DBIR), which is a reminder that an address can be used by someone other than its owner. A result is a lead until two independent sources agree on it.
What counts as confirmation
Two findings that don't depend on each other and point to the same person. A LinkedIn profile and a Gravatar photo showing the same face is strong. Two sites that both copied the same public bio is not: that's one source seen twice.
What a registration does and doesn't prove
An address registered on a site proves that someone signed up with it. It doesn't prove the owner still uses that account, or even that the owner created it. Scammers register accounts with other people's addresses all the time. Read a registration as "this address has touched this service", nothing more.
Watch the dates
Breach data can be ten years old. A name attached to an address in a 2016 leak may belong to someone who gave the address up long ago. Prefer recent, first-hand sources over old copies.
Is a reverse email lookup legal?
Looking up public information about an email address is legal in most countries. The law cares about what you do next. In the US, the Fair Credit Reporting Act covers any report used, or expected to be used, for employment, housing, credit or similar decisions, and a disclaimer doesn't get a company out of it (FTC). The data broker Spokeo paid $800,000 in 2012 to settle FTC charges over exactly that (FTC).
In practice: checking a sender, vetting a business contact, investigating fraud or checking your own exposure are fine. Screening a job applicant or a tenant with a people-search tool is not, and neither is using what you find to contact, follow or pressure someone. In the EU and UK, the GDPR also applies to what you store. This isn't legal advice; our responsible use policy spells out what we allow on Rocksosint.
Running a full email lookup with Rocksosint
Rocksosint runs the checks above in one search. Type the address and it queries more than 200 open sources: registration checks built on Holehe and user-scanner, breach databases, public profiles and domain data. Every result shows the source it came from, so you can open it and confirm it yourself.
The owner of the address is never notified. No password resets, no messages, no connection requests. You can preview a search without an account, and paid plans start at $15 a month for 30 searches (see plans). How each module works, and what it can miss, is documented on our methodology page.
Frequently asked questions
Can you find out who owns an email address for free?
Often, yes. Searching the exact address in quotes, reading the email headers, checking the domain and running the address through Have I Been Pwned costs nothing. Those four checks identify many senders. A paid lookup helps when the address is private: it checks hundreds of sites for registrations at once and links each result to its source.
Can I find someone's location from their email address?
Only roughly, and often not at all. Big webmail providers such as Gmail usually leave the sender's own IP address out of the headers. When an IP does appear, it points to a network or a city, never a street address. Public profiles linked to the address are a better lead than the headers.
Will the person know I looked up their email address?
Not if you stick to passive checks: search engines, headers, breach databases and public profiles. What does alert people is typing their address into a "forgot password" form, because many services email the owner right away. Rocksosint's email modules don't trigger resets or send anything to the target.
Is it legal to look up who owns an email address?
Checking public information about an address is legal in most countries. What you do with it is what gets regulated. In the US, results can't be used for hiring, housing or credit decisions outside the FCRA, and harassment or stalking laws apply everywhere. See our responsible use policy.
What does it mean when an email address returns no results?
It usually means the address is new, used only for one service, or disposable. That is a finding in itself. An address that claims to belong to an established company or a long-time professional but has no footprint anywhere deserves more caution, not less.
Sources
- FTC: New FTC data show a big jump in reported losses to fraud, $12.5 billion in 2024 (March 10, 2025)
- FTC: Consumer Sentinel Network Data Book 2024
- FBI IC3: 2025 Internet Crime Report
- Verizon: 2025 Data Breach Investigations Report
- Have I Been Pwned (counter checked September 29, 2026)
- Gravatar developer documentation
- Holehe on GitHub
- Google: Trace an email with its full headers
- FTC: Background screening reports and the FCRA (January 10, 2013)
- FTC: Spokeo to pay $800,000 to settle FTC charges (June 12, 2012)