One plain-text address in a footer template appears on every page of a site. The Kwebby Email Privacy Checker is an email address scanner for your own pages. Enter a URL, click Scan and it lists every address visible in that page's HTML source, then reports whether the page uses mailto links and Cloudflare Email Protection. This guide explains how address harvesting works, how to read a scan and what to do with the result. It checks pages you publish, and it does not look up anyone's email address.
Key Takeaways
- The tool scans one URL at a time and reads the page's HTML source. The result card shows a count, and an "Exposed Emails" list names each address found.
- A "Protection Status" panel reports two things: "Mailto Links Present" and "Cloudflare Email Protection".
- The scan matches anything shaped like an email address, so review each hit. It skips form placeholder text such as placeholder="[email protected]", image file names and example.com addresses.
- Spammers use automated web spiders to collect addresses from pages, according to Wikipedia's overview of email address harvesting. Every defense, from forms to scripts, trades some usability or accessibility.
- Cloudflare's obfuscation hides addresses in page text and in link targets, but it does not cover other HTML attributes, so a re-scan after you enable it is worth running.
- Use the tool on pages you own or manage. The tool is free and needs no account.
What Is the Kwebby Email Privacy Checker?
The Kwebby Email Privacy Checker is a free email address scanner for web pages you own or manage. Enter one page URL, click Scan and it lists every email address visible in that page's HTML source, plus whether the page has mailto links and Cloudflare Email Protection.
It belongs to Kwebby's SEO tools. To see the raw markup around an address it finds, open the page in Get Source Code of Webpage.
Key Features and How It Works
One page per scan
The input box shows the placeholder "https://example.com/contact". Type or paste a page address and click Scan, or press Enter. A bare domain such as kwebby.com also worked in our test, and the scan ran on its home page.
While the tool works, the button reads "Scanning…" and a spinner shows "Scanning for email addresses…". It checks only the URL you enter, so scan each page that might carry an address.
The count card
The first result is a large number. A green card reads "No email addresses found". A red card shows the count with a message that the addresses are exposed in the page source. The count helps you triage, but the list below it holds the facts.
The Exposed Emails list
When the count is above zero, the "Exposed Emails" panel lists each address found, one per row, in monospace type. Compare the list with your intent. A published support address may be fine. A staff member's personal address, an old address or a test address deserves a decision.
Protection Status
The "Protection Status" panel has two rows. "Mailto Links Present" marks a page that links an address with mailto:, a pattern the tool flags as easy for bots to collect. "Cloudflare Email Protection" marks a page where Cloudflare's address obfuscation is active. Each row shows a tick when the feature is found and a cross when it is not.
Fix tip
When addresses appear, an amber tip suggests replacing plain-text addresses with a contact form or using Cloudflare Email Protection. Both options appear again in the best practices below, with their trade-offs.
Why Email Exposure Matters
An address in your page source is public. Automated spiders read HTML the way search engines do, so any address that sits in the markup can be collected without a human ever visiting the page. Wikipedia notes that spammers use such programs to find addresses on web pages.
Once an address is collected, you cannot call it back. The practical response is to keep the addresses you care about out of plain text, or to publish only addresses that you expect to receive unsolicited mail.
No defense is free. Wikipedia lists contact forms, images, spelling out the address, CAPTCHAs and JavaScript. Forms avoid publishing the address at all. JavaScript gives visitors a normal clickable link, though it reduces accessibility for people on screen readers and text browsers.
How to Use the Email Privacy Checker
- Open the tool and click in the box that shows "https://example.com/contact".
- Enter the address of a page you own, such as your contact page.
- Click "Scan", or press Enter. The button reads "Scanning…" while the page loads.
- Read the count card at the top.
- Review each address in the "Exposed Emails" list and decide whether it should stay public.
- Read the "Protection Status" rows, then repeat for your footer, team page and author pages.
Best Practices for Protecting Email Addresses
Scan the pages where addresses live
Start with the contact page. Then scan an ordinary article page, because footers and sidebars repeat on every template. Add team pages, author boxes and legal pages.
Review every hit
The scanner matches the shape of an address, not its purpose. It ignores form placeholder attributes and example.com addresses, but sample addresses in documentation and old addresses in a footer still appear in the list. Sort them into keep, remove and replace.
Prefer a contact form for general enquiries
A form sends mail without printing the recipient address in the page. The trade-off, as Wikipedia notes, is that visitors cannot use their own email program. For a business, that trade is usually worth it for the main contact route.
Choose role addresses for anything you must publish
If an address has to appear, use a shared inbox such as a sales or support address and not a person's personal address. A shared inbox is easier to filter and to replace if it attracts spam.
Re-scan after you add protection
Cloudflare's obfuscation replaces visible addresses with encoded links and relies on a script to restore them for people. Its documentation says attributes other than a link's href are not covered. After you turn it on, scan the page again and confirm the list is empty and the "Cloudflare Email Protection" row shows a tick.
Keep accessibility in mind
Script-based hiding can break the link for visitors who browse without JavaScript. Keep a contact form as a fallback.
Common Use Cases
- Pre-launch checks. Scan templates before a new site goes live.
- Redesign and migration QA. Confirm that old addresses did not carry over.
- Plugin and theme audits. Find addresses that a plugin prints into the page source.
- Client audits. Add an address-exposure check to a technical review, alongside the Website Links Count Checker results for the same page.
- Spam investigations. If one inbox draws far more junk than the rest, scan the pages where that address appears. A flagged domain is a separate problem, which Blacklist Lookup can check.
Related Kwebby Tools
Get Source Code of Webpage shows the raw HTML around an address, so you can see where it sits. The Website Links Count Checker counts the links on a page, and Blacklist Lookup checks whether your domain or IP appears on spam blacklists. For a safety review of a domain, run the Suspicious Domain Checker.
Frequently Asked Questions (FAQs)
What is an email address scanner?
An email address scanner is a tool that finds email addresses in a source, such as a web page. Kwebby's version reads the HTML of one URL and lists the addresses it finds. Other tools with the same name verify inboxes or look up people, and this one does neither.
How do spam bots find email addresses on a website?
Bots run web spiders that download pages and search the HTML for text shaped like an email address. Any address in plain text, a mailto link or a form attribute can match. The bot does not need a person to visit the page.
How do I hide my email address on my website?
Use a contact form, or obfuscate the address with a script or a service such as Cloudflare. Each method trades something: forms stop visitors from using their own email program, and scripts can reduce accessibility. Scan the page afterward to confirm the address is gone from the source.
Does Cloudflare Email Protection hide every address?
No. Cloudflare's documentation says it hides addresses in page text and in the href of a link, not in other HTML attributes. It also needs JavaScript to restore the address for visitors, and it does not apply in several cases, such as code added by Workers.
Can this tool find someone's email address?
No. It lists only addresses that already appear in the HTML of the one page you enter. It cannot find an address that the page does not print, and it is meant for checking your own pages.
Is the Email Privacy Checker free?
Yes. Kwebby states that the tool is completely free and needs no account.
Final Thoughts
The Email Privacy Checker shows what a spider sees in your page source, which is the fastest way to judge your exposure. Run it on your contact page, your footer and your team page. Remove or replace what you do not want public, put a form in front of your main inbox, and re-scan to confirm the fix.