Digital footprint

How to find accounts linked to your email

Most people have far more online accounts than they remember. Your inbox is the best place to start, because confirmations, receipts, password resets and security alerts all leave a trail.

Last updated: 10 min readIndependent guidance, Australia-first

The short answer

To find the accounts linked to your email, use five methods together: search your inbox for signup and login keywords, review your saved passwords, check the apps connected to your Google, Apple and Microsoft sign-ins, run a breach check, and compile what you find into a single account inventory. No method is complete on its own, but together they surface the large majority of your accounts. Budget about an hour.

In The Event Of is an Australian digital footprint manager that helps you find the accounts linked to your email, see your breach exposure, and get a prioritised plan of what to do after a breach or a life change.

Australian & independentThird-party security assessmentSources cited

Key takeaways

  • Your inbox is the richest source, almost every account emails you at some point.
  • Gmail search operators like from:, subject: and older_than: make the search fast, and Outlook has equivalents.
  • Saved passwords and 'Sign in with Google/Apple' lists catch accounts your inbox misses.
  • A breach check reveals services you may have forgotten you ever used, and needs no login.
  • No single method is complete, which is why the five are worth running together.
  • Turn the results into one inventory so you can secure or close each account.

Why start here

Why your email is the best place to start

Most accounts leave an email footprint: welcome messages, login codes, shipping receipts, invoices, password resets, renewal notices, privacy-policy updates and breach notifications. That means your inbox can act like a rough map of your accounts, even when your memory has politely moved on.

It is worth being clear about what you are reconstructing, because it changes how you search. There is no central register of the services holding your email address, and no single tool can produce one. What you can do is combine several partial views, each of which covers a gap the others leave. An account that never emailed you will not show up in your inbox, but it may appear in your saved passwords. An account you created with a social sign-in button may have sent you nothing at all, but it will be listed by the identity provider. A service you forgot entirely may only surface because it was breached.

That is the whole logic of the five methods below. They are ordered by yield: the first one finds the most, and each subsequent one exists to catch what the previous ones structurally cannot.

At a glance

The five methods compared

Five methods for finding accounts linked to an email address, with what each one finds and misses
MethodWhat it findsWhat it missesTime
Search your inbox for the emails accounts leave behindAlmost any account that has ever emailed youAccounts that never emailed, or used a different address20–40 min
Check your saved passwordsLogins you chose to save, and which are reusedAnything you never saved, and social sign-ins5–10 min
Review the apps connected to your Google, Apple and Microsoft sign-insServices you used a social sign-in button forAccounts with their own separate username and password5 min
Check your breach exposureBreached services, including ones you had forgottenAnything never breached, or not yet disclosed2 min
Build a single account inventoryNothing new, it consolidates the other fourNothing, this is the output step15 min

Run all five, in order

Each method has a blind spot that another one covers. Running only the inbox search is the most common mistake, because it silently misses every account that signed you up with a social button and never sent you mail.

Method 1

1. Search your inbox for the emails accounts leave behind

Your inbox is the highest-yield source, and search operators are what make it fast. Rather than scrolling years of mail, you search for the handful of phrases that almost every signup produces. Start with these terms:

welcomeverify your emailconfirm your accountpassword resetsecurity alertsubscriptionreceiptinvoicefrom:noreplyolder_than:1ynewer_than:30d

Work through them one at a time and write down every distinct service name you see. Do not stop at the first page of results, and do not skip the promotional and spam folders, which is where old marketing mail from dormant accounts usually ends up.

Gmail

Google's search operators narrow messages by sender, subject, age and date range. from:noreply is the single most productive search, because automated senders are almost always transactional account mail. Pair it with older_than:1y to surface the dormant accounts specifically, and use subject: to target phrases, which catches most signup confirmations in one pass.

Outlook, Hotmail and Live

Outlook supports the same idea with slightly different syntax: Microsoft documents the search filters for narrowing by sender, subject, date and folder. Search from:noreply and from:no-reply separately, because Outlook treats them as different strings, and remember to include the Other inbox if you have Focused Inbox turned on, since transactional mail is frequently sorted there.

Apple Mail and iCloud

Apple Mail has no operator syntax as rich as Gmail's, so the practical approach is to search the plain phrases above and then sort by sender to group results. If you have used Hide My Email, check those addresses as well, because each one represents a separate service that has your relay address rather than your real one.

Yahoo

Yahoo Mail search accepts the same keyword phrases. Its more useful feature for this exercise is the account security page rather than the mailbox, which is covered in method 3 below.

Method 2

2. Check your saved passwords

Your browser or password manager already holds a list of logins you have saved, and it is the fastest win on this list. Reviewing it takes a few minutes and catches accounts that never sent you mail at all.

While you are there, open the health or checkup view. Chrome, Safari, Firefox and every major password manager will flag reused, weak and breached passwords. That matters here for a specific reason: a reused password turns one breached account into every account sharing it, so the reuse report tells you which of your newly discovered accounts to deal with first.

Add anything you find to your list even if you are certain you will keep the account. The point of this exercise is a complete picture, and deciding what to close comes later.

Method 3

3. Review the apps connected to your Google, Apple and Microsoft sign-ins

Every time you used a “Sign in with” button instead of creating a password, the identity provider recorded it. Those lists are the only reliable record of accounts that may never have emailed you and were never saved in a password manager, which makes this the method people most often skip and most often need.

Removing access is not closing the account

Revoking a connected app stops it signing you in. It does not delete the account or the data the service already holds. If you want the account gone, close it with the service directly, then revoke.

Method 4

4. Check your breach exposure

A breach check can reveal services you had forgotten you ever signed up to, and it is the one method that needs no login anywhere. Have I Been Pwned lets you check, for free, which known breaches your email appears in.

Read the results as an account list rather than a threat list. Every breached service named there is, by definition, a service that held your address at the time. If you do not recognise one, that is an account to add to your inventory and probably to close. If you want a second opinion, no breach corpus is complete, so our Have I Been Pwned alternatives guide covers the checkers worth running alongside it. See what to do if your email is in a data breach for the full response.

Method 5

5. Build a single account inventory

Pull the results of the methods above into a single list, a spreadsheet works fine to start. For each account, note the service, the email used, whether it holds payment or identity details, and whether you still need it.

Sort that list by what the account holds rather than by how old it is. An abandoned forum login with nothing but a username is a much smaller problem than a dormant retailer account with a saved card and a delivery address, even if the forum account is older. That inventory is the foundation for the digital footprint checklist and for deciding what to keep, secure or delete.

Skip the spreadsheet

In The Event Of can scan a connected inbox for account-related metadata and build your account map for you, so you can focus on what to do next rather than the discovery.

Map your accounts free

What next

What to do with the accounts you find

Once you can see the accounts, decide on each one. Close accounts you no longer use, especially those holding payment details, addresses or identity documents, because every dormant account is extra breach exposure. Our guide to deleting old accounts covers the Australian deletion rights worth citing when a service makes closing an account difficult.

For the accounts you keep, set a unique passphrase and turn on multi-factor authentication, starting with the ones the password reuse report flagged. Then check the recovery details, because an old phone number or a dead secondary address on an account you are keeping is its own quiet risk.

Using In The Event Of

How In The Event Of helps

In The Event Of is built around turning inbox noise into an account map. You can connect a supported inbox (Gmail or Outlook) so it can scan for account-related metadata, sender addresses, subject lines, labels and timestamps, not the body of your emails, or add services manually. It then organises what it finds into a digital footprint, highlights breach exposure, and gives you guided steps to secure or update each account. You stay in control of every change.

It automates method 1 and method 4, which are the two slowest steps here, and it keeps the resulting inventory current instead of leaving you with a spreadsheet that goes stale the week after you build it. The Free tier is A$0 and does not require a credit card.

FAQ

Frequently asked questions

Can I find every account linked to my email?
Not perfectly. Inbox searches, saved passwords, connected-app settings and breach checks will surface many accounts, but some may have been deleted, created with a different email, or never sent any useful email records. The goal is a thorough working inventory, not absolute completeness.
Where is my email being used?
There is no central register that lists every service holding your email address, because no such register exists. The practical answer is to reconstruct it from four independent traces: the emails services have sent you, the logins your browser or password manager saved, the third-party apps connected to your Google, Apple or Microsoft account, and the breach records that name services which held your address. Each one covers a gap the others miss.
How do I find all accounts linked to my email address for free?
Every method on this page is free. Searching your own inbox costs nothing, reviewing saved passwords in your browser or password manager costs nothing, the connected-apps pages at Google, Apple, Microsoft and Yahoo are free account settings, and Have I Been Pwned's email search is free. In The Event Of also has a free tier at A$0 that automates the inbox-scanning step if you would rather not do it by hand.
Can I find accounts linked to an email without the password?
Partly. A breach check works from the outside and needs no access at all, and searching the public web for the address in quotes can surface public profiles. Everything else on this page requires you to be signed in, because inbox search, saved passwords and connected-app lists are all private account data. If you cannot sign in to the inbox itself, start account recovery with the provider rather than looking for a workaround.
Is this the same as checking my saved passwords?
No. Saved passwords only show logins you chose to store. Your email can reveal accounts where you never saved a password, used social sign-in, abandoned the account, or only interacted once, so the two methods complement each other.
What if I have used several email addresses over the years?
Run the whole process once per address. Old addresses are usually where the forgotten accounts live, because they were current when you signed up to services you no longer think about. If an old inbox is still reachable, search it first, because it is the richest source. If it has been closed, a breach check on that address is often the only trace left.
Should I delete old accounts I find?
Delete accounts you no longer need, especially if they hold payment details, identity documents, addresses or old passwords, every dormant account is extra breach exposure. Keep accounts that are legally, financially or practically important, and secure them with a unique passphrase and MFA.
Does searching my inbox put my data at risk?
No. Searching your own inbox with the operators above happens entirely within your email account. If you later connect your inbox to a tool, check what it accesses, In The Event Of's footprint scan, for example, reads only metadata such as sender, subject and timestamps, not the body of your emails.

Disclaimer: Third-party account-management steps are summarised from official help pages, which were checked in August 2026 and may change. This guide is general information only and is not legal, financial, or security advice. It is based on publicly available sources at the time of writing and may not reflect the most recent developments. In The Event Of Pty Ltd (ABN 38 687 352 647) is an independent Australian company and is not affiliated with the third-party services named in this guide.