Skip to content
Aback Tools Logo

Email Deobfuscator & Extractor

Extract email addresses from obfuscated HTML and text. The email deobfuscator automatically detects and reverses HTML entities, ROT13, [at]/[dot] patterns, split emails, JS char codes, URL encoding, reversed text, hex encoding, and Base64. Free, private, and no signup required.

Email Deobfuscator & Extractor

Paste obfuscated HTML, text, or code containing hidden email addresses below. The tool automatically detects and decodes emails obfuscated with HTML entities, ROT13, [at] patterns, split/concatenated strings, JS char codes, URL encoding, reversed text, hex encoding, and Base64.

Input Text with Obfuscated Emails

Your text stays in your browser. All email deobfuscation is done locally - nothing is uploaded to any server.

Why Use Our Email Deobfuscator & Extractor?

10 Obfuscation Detection Methods

Automatically detects and decodes emails obfuscated with HTML entities, ROT13, [at]/[dot] patterns, split/concatenated strings, JS char codes, URL encoding, reversed text, hex encoding, and Base64. Each detection is labeled with the method used so you know exactly how the email was hidden.

Secure Browser-Local Processing

All email deobfuscation is done entirely in your browser. Your text never leaves your device. No uploads, no servers, no third-party access - complete privacy when analyzing obfuscated email addresses or sensitive HTML content.

Deduplicated Results with Confidence Ratings

Extracted emails are automatically deduplicated and shown in a clean list. Each detection includes a confidence rating (high/medium) and shows the original obfuscated fragment for verification. Copy individual emails or all at once.

100% Free With No Limits

Our email deobfuscator is completely free with no signup required, no usage limits, and no text length restrictions. Analyze as much obfuscated content as you need, all in your browser for complete privacy.

Common Use Cases for Email Deobfuscator & Extractor

Email Harvesting Investigation

Investigate how email harvesters might extract addresses from your web pages. Use the email deobfuscator to test different obfuscation techniques and see which ones are easily reversed, helping you choose the most effective protection strategy.

Web Development & QA Testing

Web developers can test their email obfuscation implementations by verifying that obfuscated email addresses in HTML source code are properly hidden. The email deobfuscator reveals exactly how accessible your obfuscated emails are.

Contact Information Recovery

Recover legitimate email addresses from obfuscated contact pages, old backups, or migrated content where email addresses were encoded using various obfuscation techniques. Batch extract all hidden emails in seconds.

Security Research & Analysis

Security researchers can analyze obfuscation techniques used across different websites to catalog and understand email harvesting protection methods. The email deobfuscator provides detailed detection breakdowns for each method.

Penetration Testing & Auditing

During security audits, use the email deobfuscator to check if client websites have email addresses that are trivially deobfuscatable. Identify weak obfuscation that provides false confidence in email harvesting protection.

Educational Demonstrations

Teach web security concepts by demonstrating how common email obfuscation techniques work and how they can be reversed. The email deobfuscator shows each detection method with the original obfuscated fragment for clear understanding.

Understanding Email Deobfuscation

What is Email Deobfuscation?

Email deobfuscation is the process of reversing techniques used to hide email addresses in HTML, text, and code. Website owners often obfuscate email addresses to prevent automated email harvesters from collecting them for spam. An email deobfuscator and extractor automatically detects and reverses these hiding techniques, recovering the original email addresses. Common obfuscation methods include HTML entities (like @ for @), ROT13 encoding,[at] and [dot] patterns, split string concatenation, and various encoding schemes.

Our email deobfuscator supports 10 different detection methods and provides confidence ratings for each extracted email, making it easy to verify results.

How Our Email Deobfuscator & Extractor Works

  1. Paste obfuscated content - enter HTML source code, text with [at] and [dot] patterns, or any encoded content containing hidden email addresses. The tool accepts raw HTML, JavaScript code, and plain text.
  2. Automatic detection - the email deobfuscator applies all 10 detection methods simultaneously. It first scans for plain text emails, then applies each deobfuscation technique (HTML entity decoding, ROT13, pattern normalization, URL decoding, hex decoding, Base64 decoding, etc.) and scans each decoded result for email addresses.
  3. Review and extract - results are shown in a deduplicated list with each email labeled by detection method and confidence level. View the original obfuscated fragment alongside the decoded email for verification. Copy individual emails or all emails at once with one click.

Supported Detection Methods

  • Plain Text Detection: Direct email regex matching to find any standard email addresses that were not obfuscated at all.
  • HTML Entity Decoding:Decodes decimal entities (@ -> @), hexadecimal entities (@ -> @), and named entities (@ -> @, ˙ -> .) commonly used in HTML source to hide email characters.
  • ROT13 Decoding: Applies ROT13 (rotation by 13 letters) to the input text and scans for emails. ROT13 is self-reciprocal and commonly used in simple email obfuscation.
  • [at]/[dot] Pattern Resolution:Normalizes common human-readable obfuscation patterns like "user [at] example [dot] com", "user(at)example(dot)com", and "user at example dot com" back to standard email format.
  • Split/Concatenated Email Resolution:Detects emails constructed from concatenated string fragments like "user" + "@" + "domain" + "." + "com" found in JavaScript code.
  • JS charCode Detection: Interprets String.fromCharCode() calls and char()/chr() patterns to reconstruct email addresses from numeric character codes.
  • URL Encoding:Decodes percent-encoded email characters (%40 -> @) commonly used in mailto links and URL parameters.
  • Reversed Text:Attempts to reverse the entire input to catch emails that were written backwards (moc.elpmaxe@ofni -> [email protected]).
  • Hex Encoding:Decodes hex-encoded email addresses (696e666f40 -> info@) where each character is represented as two hex digits.
  • Base64 Encoding: Decodes Base64-encoded email addresses, filtering for strings that decode to valid text containing email patterns.

Privacy, Security & Best Practices

All email deobfuscation happens entirely in your browser using JavaScript. Your input text, including any obfuscated email addresses or HTML content, never leaves your device. No data is uploaded, stored, or transmitted to any server. This tool is designed for legitimate purposes like web development testing, security research, and content recovery. Please use responsibly and respect others' privacy when analyzing obfuscated email addresses. For production email protection, consider using server-side rendering, contact forms, or CAPTCHA-based solutions rather than relying solely on obfuscation.

Frequently Asked Questions About Email Deobfuscator & Extractor

An email deobfuscator is a tool that detects and reverses techniques used to hide email addresses in HTML, text, and code. Website owners often obfuscate email addresses to prevent automated harvesters from collecting them. Our email deobfuscator and extractor supports 10 detection methods including HTML entities, ROT13, [at] patterns, split strings, JS char codes, URL encoding, reversed text, hex encoding, and Base64.

The email deobfuscator detects 10 techniques: plain text emails, HTML entities (@ @), ROT13 encoding, [at]/[dot] patterns, split/concatenated strings, JavaScript String.fromCharCode() calls, URL encoding (%40), reversed text, hex encoding, and Base64 encoding. Each detected email is labeled with the method used to decode it.

Extraction accuracy depends on the obfuscation method. Plain text, HTML entities, and [at] pattern detections have high accuracy. ROT13 and reversed text detections are marked as medium confidence because ROT13-decoded or reversed text may incidentally contain text that looks like email addresses. Each detection includes a confidence rating to help you verify results.

Absolutely. All email deobfuscation happens locally in your browser using JavaScript. Your text, including any obfuscated email addresses or HTML content, never leaves your device. No data is uploaded, stored, or transmitted to any server - complete privacy for sensitive analysis.

Yes. If you have obfuscated email addresses on your website and need to recover the original addresses for migration, backup, or verification purposes, the email deobfuscator can extract them. Paste your HTML source or obfuscated text and all email addresses will be decoded and listed.

Email harvesters often search for the @ symbol and dots in email patterns. To counter this, many websites write email addresses as "user [at] example [dot] com" or "user(at)example(dot)com". The email deobfuscator normalizes these patterns by replacing [at], (at), " at " with @ and [dot], (dot), " dot " with . to reconstruct the original email address.

No. This tool is designed for legitimate purposes: web developers testing their email obfuscation, security researchers analyzing protection methods, content migration, and educational demonstrations. It reveals what is already publicly visible in HTML source code that anyone can view with a browser. Use responsibly and respect others privacy.

Yes, it is 100% free with no signup required, no usage limits, no text length restrictions, and no hidden costs. Analyze as much obfuscated content as you need, all in your browser for complete privacy.