Enter a URL
Email addresses published in webpage source can be collected by visitors and automated crawlers. The Email Privacy Checker examines one public webpage and reports email-like addresses found in its returned HTML. It helps site owners identify exposed contact addresses for manual review.
This is a webpage exposure checker, not an email-account security scanner. It does not request or inspect an email password, mailbox, messages, contacts, mail server, spam folder or account settings. It also does not encrypt email, remove an address automatically, block spam, scan malware or prove that an email account is secure.
Enter a public webpage URL and submit the form. The tool validates the address, requests the page through its server and reads the returned content. It then searches that content for text matching a conventional email-address pattern. If matching text is detected, the result can list the email-like values found. If no match is detected, the tool reports that no email was found in the fetched content.
The check applies only to the URL submitted. It does not automatically crawl the entire website, follow every internal link or inspect private pages. To review several important pages, test each relevant URL separately. Typical candidates include the homepage, contact page, about page, support page, author profiles and publicly accessible documents converted into HTML.
Never enter email credentials into this tool. It requires a webpage URL only. If any unrelated page asks for an email password merely to check whether an address is publicly visible, stop and verify the service before proceeding.
A detected address means the fetched webpage content contained text matching the tool's email pattern. It may be an active contact address, an outdated address, an example used in documentation, text stored in markup, a structured-data value or content that is not visibly displayed by the browser. Review the actual page and source before deciding what to change.
Detection does not prove that an address has been harvested, added to a spam list, compromised or used in an attack. It only identifies potential exposure in the fetched content. Likewise, the absence of a match does not prove complete privacy because an address may appear elsewhere on the site, in a downloadable file, in an image, after JavaScript runs or through a format the pattern does not recognise.
Automated programs can collect addresses from public pages and use them for unsolicited messages, phishing attempts, address-list creation or other unwanted activity. Publishing an address can still be a legitimate business decision, especially when customers need a clear way to make contact. The goal is not to declare every visible address unsafe; it is to make exposure deliberate and manageable.
A role-based address such as support, sales or press may be easier to maintain than publishing a staff member's personal work address. It can be routed to a team, protected with mail filtering and replaced without changing an individual's primary account. The correct choice depends on business needs, legal obligations, accessibility and the expected volume of enquiries.
The tool processes the content fetched by its server. Modern websites may build parts of a page in the browser with JavaScript, load information after an interaction or return different content according to device, location, cookie or user agent. An address visible to you may therefore be absent from the fetched source, or source text may be detected even when it is hidden visually.
The checker searches for a practical email-like pattern. Real email-address syntax is complex, and text that matches a common format is not necessarily a working mailbox. Unusual but technically valid addresses may not match, while an example such as name@example.com may be reported despite not being a real contact for that website.
A website can block automated requests, require authentication, redirect unexpectedly, time out or return an error page. In those cases the checker may not receive the same content a normal visitor sees. Confirm that the submitted page is publicly accessible and review any fetch error before interpreting the result.
Delete addresses that no longer serve a business or user need. Check shared headers, footers, templates and reusable blocks because a single template change can affect many pages. Also review old campaign pages and staff profiles that remain publicly accessible.
A well-designed contact form can allow visitors to send a message without displaying the destination address in ordinary page text. Protect the form against automated abuse, validate submissions on the server and provide clear privacy information. A form does not eliminate spam or replace secure mail operations, but it can reduce direct address exposure.
Consider separate role addresses for customer support, sales, media or legal enquiries. Apply suitable access controls, multi-factor authentication, filtering and retention policies to the receiving accounts. Do not expose a personal address merely because it is convenient during initial website setup.
Writing an address as words, inserting spaces or encoding characters may stop a simple pattern but can reduce usability and may still be understood by more capable harvesters. Visitors using assistive technology may also find unusual formats difficult. Choose a solution that balances privacy, accessibility and reliable communication.
An email may remain in JSON-LD, metadata, comments, inactive components or theme settings after being removed from visible text. Search the page template and content management system, then clear caches or generated files as required. Do not remove data blindly if a legitimate service depends on it.
Public-address exposure is only one small part of email risk. Protect actual mail accounts with unique passwords, multi-factor authentication, controlled recovery options and timely software updates. Train users to recognise phishing and verify unusual requests through a separate channel. Review mailbox forwarding rules and connected applications when compromise is suspected.
Domain owners should separately examine email authentication and DNS configuration with tools intended for SPF, DKIM, DMARC and MX records. Transport encryption, gateway filtering, account access logs and incident response also require dedicated systems. A webpage scanner cannot replace those controls.
Inspect the page source, structured data, metadata, reusable template and hidden elements. The address may be stored in HTML even if CSS prevents it from appearing normally.
The address may be inserted by JavaScript, displayed as an image, written in an unusual format or loaded only after consent or interaction. Manually inspect the rendered page and use browser developer tools when necessary.
Clear the website, plugin, server and content-delivery caches as appropriate. Confirm that the correct template was edited and that the tool fetched the final public URL rather than an older redirected page.
Verify the URL and confirm that the page is publicly accessible. Automated-request protection, timeouts, certificate issues or server errors can prevent a successful fetch. Do not treat a failed request as proof that no address exists.
No. Enter only the public webpage URL you want to inspect. The checker does not need mailbox credentials.
No. It means the tool did not match an email-like string in the fetched content for that URL. The address could still appear elsewhere or in a form the checker cannot read.
No. Edit the relevant webpage, theme, template or content-management setting, publish the change and test again.
No. It does not connect to an inbox or inspect messages, attachments and account settings.
No. It only means matching text was found in public page content. Investigate account compromise through the mail provider and appropriate security procedures.
Email Privacy Checker provides a focused review of email-like text in one fetched webpage. Use the result to locate accidental or outdated exposure, then confirm each finding manually before making changes. Keep intentional contact methods accessible, protect receiving accounts with proper security controls and remember that this report does not assess the security of an email account or mail system.