LinkedIn Email Scraper
The address is almost never on the profile, so the tool that promises to scrape it is quietly doing something else, and the something else is where both the accuracy and the legal exposure live.
A LinkedIn profile does not publish an email address. What a LinkedIn email scraper actually does is take the identity off the profile, a name and a company, and find an address somewhere else: by generating the most likely pattern and testing it, by looking the person up in a contact database, or by reading the contact card that a member chose to show their connections. Each route has a different accuracy, a different failure mode and a different legal footing, and the differences are worth knowing before a list is bought.
On this page
Where the address actually comes from
Three routes, and most commercial tools chain all three in order until one answers.
- Pattern generation with verification. Take the company domain, the first name and the last name, build the addresses the company is known to use, and test each one against the receiving mail server. This route invents the address and then tries to prove it.
- A contact database. Look the person up in a store of addresses gathered earlier from other sources, which may include data that customers contributed, partner feeds, or previous collection. This route returns whatever was recorded, at whatever age it has.
- The LinkedIn contact card. Read the address a member put into their own profile’s contact info, which LinkedIn shows according to that member’s visibility setting. This is the only one of the three where LinkedIn genuinely holds the data, and it is also the one a regulator has already ruled on.
The distinction matters because it decides what you are buying. A pattern lookup sells you a probability. A database sells you a record whose age you cannot see. The contact card sells you something the person disclosed to a specific audience, and possibly not to you.
The contact card, and the case about it
France’s data protection regulator fined Kaspr, a LinkedIn contact-scraping browser extension, EUR 240,000 on 5 December 2024, and the decision is the clearest public description of how this product category works and where it goes wrong. In the CNIL’s own words, the company “markets a pay-for extension for the Chrome browser that enables customers to obtain the professional contact details of people they visit the profiles on the LinkedIn social network”, backed by a database of “about 160 million contacts”.
Three findings from that decision apply to the whole category.
- A visibility setting is not consent to a third party’s database. The regulator recorded that the company “also collected the contact details of those who had chosen to restrict visibility to their 1st and 2nd-degree connections.” Showing a colleague your address is not the same permission as being entered into a prospecting product.
- Five years outlives the job. The regulator found that “the company was keeping the contact details of users for 5 years from each data update”, which it treated as disproportionate for people who change jobs inside that window.
- The notice is owed, and late is a finding. The company “started to inform data subjects that their personal data had been collected only in 2022, that is to say four years after the implementation.”
The full legal picture, including the case law behind the scraping question and what actually reaches an operator, is on is scraping LinkedIn legal.
How a pattern lookup works
The mechanics are worth understanding because the vocabulary on these products hides a guess inside a confident-looking number. Hunter’s API documentation describes its own Email Finder plainly: the endpoint “finds the most likely email address from a domain name, a first name and a last name”, and the score attached to it is “our estimation of the probability the email address returned is correct.”
Verification is a second step, and it returns one of a small set of states. The two that matter are the ones people skip over. Valid means the receiving server accepted the specific address. Accept_all, often called catch-all, means “the email address is valid but any email address is accepted by the server”, which is a polite way of saying the test proved nothing. A meaningful share of corporate domains are configured that way, and every address at such a domain comes back with the same non-answer.
Two more states shape a list’s real quality. Webmail flags a personal Gmail or Outlook address, which is usually the wrong address to use for business outreach even when it is correct. Unknown means verification failed, which is common on servers that refuse to answer probing at all.
So a bought list of a thousand “verified” addresses typically decomposes into some genuinely confirmed, some catch-all guesses that will bounce or land with a stranger, some personal accounts, and some that nobody could test. A vendor that reports one number has averaged those together.
What a match rate is worth
Match rate is the headline metric in this category and it is close to meaningless on its own, because a provider chooses what counts as a match. A guess with a 60% confidence score can be reported as a match. A catch-all result can be reported as a match. An address from 2021 can be reported as a match.
The honest test takes an afternoon and is worth doing before any annual contract.
- Build a truth set. Two hundred people you already have correct addresses for, drawn from the segment you actually sell to, with the addresses withheld from the vendor.
- Measure coverage and accuracy separately. Coverage is how many rows came back with anything. Accuracy is how many of those match your known address exactly. A provider can win one and lose the other badly.
- Count the catch-alls as their own column. They are neither found nor failed, and rolling them into either number is what produces the 95% figures on landing pages.
- Then send. Bounce rate against a small sample is the only measurement the mailbox provider cares about, and it is the one your sending reputation is scored on.
Segment matters more than the vendor for most teams. Coverage on large US technology companies is a different world from coverage on small firms in non-English markets, and a rate quoted without a segment is a rate quoted about somebody else’s list.
What your own account is exposed to
The extension shape of this product, the one that sits in your browser and reveals a contact while you are looking at a profile, runs inside your own logged-in LinkedIn session. That has a consequence people discover late: the profile views, the pace and the volume are attributed to your account, and bulk enrichment through an extension looks like bulk browsing.
Two ceilings apply whether or not the tool mentions them. The commercial use limit throttles search once a monthly allowance is spent, which we cover on LinkedIn search limits, and account health degrades on burst behaviour long before any formal restriction appears, which is the subject of LinkedIn shadow ban. The prevention checklist is on how to avoid getting banned on LinkedIn.
A database lookup by name and domain, with no extension in your browser, carries none of that. It buys a record from a third party and leaves your account alone, which is a real advantage of that route and is separate from the question of where the record came from.
The legal position
An email address attached to a named person is personal data, so the copy is processing and the record needs a lawful basis, a defensible retention period and a notice to the person. The notice duty is the one that catches prospecting databases: where data was not obtained from the person themselves, the GDPR puts a clock on telling them, and the Kaspr decision turned a four-year delay into a finding.
Outbound email carries a second layer on top of data protection. Anti-spam regimes govern the send itself, and they differ by country, with consent requirements in some markets that a legitimate-interest argument for the database does not satisfy. Guidelines for LinkedIn outreach specifically, sorted by which rulebook each one comes from, are on ethical LinkedIn outreach guidelines.
The practical version: whoever holds the copy owes the duties, and buying the list does not move them to the vendor.
Reaching the person on LinkedIn
A good share of email-scraping projects exist because the team wanted to reach someone they found on LinkedIn, and email was the only channel they knew how to automate. The other option is to reach them where you found them, through an account you own, with the invitation and the message as typed API calls and per-action budgets enforced before dispatch.
That route has its own ceilings, published in full on LinkedIn limits, and it has one property an enrichment waterfall cannot offer: there is no address to get wrong, no bounce, and no catch-all. The identity you matched is the identity that receives the message. On that stack, gtm-api.com reports 20,000+ accounts at under a 1% ban rate.
The honest comparison between scraping routes and account-based reads, including when a dataset really is the right purchase, is on LinkedIn scraping vs a safe API.
Frequently Asked Questions
Can you scrape email addresses from LinkedIn?
Only in one narrow case, and not the one most tools are selling. LinkedIn profiles do not publish email addresses. A member can put an address into their own contact info with a visibility setting attached, and that is the single place LinkedIn holds one. Everything else in this category takes the name and company off the profile and finds an address elsewhere, either by generating the likely pattern and testing it or by looking the person up in a contact database.
Why do verified emails still bounce?
Usually because the verification returned accept_all rather than valid. A catch-all server accepts every address at the domain, so a test against it proves the domain exists and nothing about the person. Providers commonly count those rows as matches, which is how a list advertised at high accuracy arrives with a bounce rate that damages your sending reputation. Ask for catch-all results as their own column, and test a sample by sending before you buy volume.
Is scraping LinkedIn emails legal?
An email address tied to a named person is personal data, so the copy needs a lawful basis, a retention period you can defend and a notice to the person within the window the GDPR sets. France’s regulator fined a LinkedIn contact extension EUR 240,000 in December 2024 on exactly these points, including collecting details from members who had limited visibility to their own connections, keeping records for five years, and notifying people four years late. The duties sit with whoever holds the copy, so buying a list does not move them.
Do email-finder extensions put my LinkedIn account at risk?
An extension works inside your own logged-in session, so the profile views and the pace belong to your account. Bulk enrichment through one looks like bulk browsing, which spends the monthly commercial use allowance on search and contributes to the burst behaviour that precedes a distribution problem. A server-side lookup by name and domain avoids that entirely, since nothing happens in your browser and no LinkedIn activity is attributed to you.
What match rate should I expect from a LinkedIn email tool?
No number quoted without a segment means anything, because coverage on large US technology firms and coverage on small companies in non-English markets are different products. Run your own test: two hundred people from the segment you sell to, addresses withheld, then measure coverage and exact-match accuracy separately and keep catch-all results in their own column. Finish by sending to a sample, because bounce rate is the only figure your mailbox provider scores you on.
Sources & Further Reading
- CNIL, data scraping: KASPR fined EUR 240,000 (the 5 December 2024 decision, the browser-extension product description, the 160 million contacts, the restricted-visibility finding, the five-year retention and the four-year notification delay)
- Hunter, API documentation (the Email Finder as “the most likely email address from a domain name, a first name and a last name”, the confidence score as an estimated probability, and the verification states including accept_all, webmail and unknown)
- gtm-api.com, product · pricing (our own numbers)
- Related: Is scraping LinkedIn legal · LinkedIn scraping vs a safe API · LinkedIn profile data API · Ethical LinkedIn outreach guidelines · LinkedIn search limits
Message the person you matched.
Connect a LinkedIn account you own, send the invitation and the follow-up as typed API calls, and let the server hold the per-action budget under every one. No address to guess and nothing to bounce. On that stack, gtm-api.com reports 20,000+ accounts at under a 1% ban rate. Free plan, then from $10 per connected account at volume.
Last updated: September 2026 · The regulator’s findings and the verification definitions on this page were read off the CNIL’s own decision summary and the provider’s published API documentation on 11 September 2026 and are linked in Sources. Providers change their scoring and their coverage without notice, so run your own test on your own segment before you buy volume.
