X-ray search is the technique of using a general search engine's site and URL operators to find public profile pages hosted on a platform, instead of searching inside that platform's own interface. It reaches pages a native search will not show, but it depends on what the engine has indexed, so results are incomplete and often out of date.
It works best where a site publishes stable public pages and wants them found: personal sites, documentation and package registries, open technical contributions, association member directories, conference and meetup listings, and university or research group pages. These are indexed willingly and rarely restructured. It works badly on login-walled applications, on anything rendered entirely by client-side script, and on platforms that treat their profile pages as a competitive asset. A useful habit is to check whether a site is indexed at all before building queries against it, rather than concluding from an empty result that nobody relevant is there.
Constrain the path, not just the domain, so the engine returns profile pages rather than help articles, tag pages and directory indexes. Exclude the listing pages that aggregate many names, since they match everything and tell you nothing. Then open the pages instead of trusting the snippet, because the snippet is drawn from the crawled copy and can predate a job change by a long way. Look for a visible date on the page. Most of the time lost to this technique goes on confidently reading a stale cache.
Teach it, but position it honestly as one route among several rather than as a signature technique. The genuinely transferable parts are the habits it forces: thinking about where evidence of a skill would be published, constructing a repeatable query, and verifying a claim on the page itself before acting on it. Those survive any platform change. Memorised query patterns do not, and a sourcer taught only patterns is stuck the first time a URL structure moves. Pair it with native search and with whatever licensed tooling the team already pays for.
An x-ray query points a general search engine at a single domain and, usually, at the URL pattern that platform uses for its public profile pages, then adds the terms you care about. What comes back is the engine's crawled copy of pages the platform chose to leave open to crawlers. You are searching a third party's index of that site rather than the site's own database.
Three consequences follow. You can only reach what is public, so anything behind a login is invisible no matter how the query is written. You see the page as it was when last crawled, which may be months ago. And you match visible page text rather than structured fields, so the filters the platform offers inside its own interface simply do not exist in the query.
The first reason is access. Native search interfaces cap how many results a given account can page through, and place the sharper filters behind higher licence tiers, so a recruiter on a basic seat hits a wall that has nothing to do with how many matching people exist. Querying through a search engine sidesteps that interface, though not the underlying limits on what any platform makes public.
The second reason is breadth, and it is the stronger one. Code hosts, community forums, personal portfolio sites, conference speaker listings, professional association directories, meetup groups and university pages hold a great deal of evidence about who does what, and they share no common search interface. One query pattern, repointed at each domain in turn, is the only practical way to sweep across them.
Less dependable than its reputation suggests, and it is worth being blunt about why. Search engines index public pages at their own discretion, so coverage of any given site is partial and shifting. Large platforms actively discourage crawling through robots directives and login interstitials. URL structures change without notice, so a query pattern that worked reliably last year can silently return nothing at all.
The practical rule is that a null result proves nothing. It may mean the people are not there, or that the pattern is stale, or that the engine has dropped coverage of that path. Before concluding a market is thin, verify through a second route: the platform's own search, a licensed database, or a community where the same people gather. Treat the technique as one probe among several.
Platform terms commonly restrict automated collection, scripted querying and bulk export, including of pages any visitor can see. Public visibility and permitted use are different things, and manual searching is usually treated very differently from harvesting at scale. Read the terms of the surfaces your team relies on, and expect both enforcement and the technical countermeasures behind it to change without warning.
Storing what you find raises a separate question, because you are recording identifiable details about people who never approached you. Obligations vary by country and sometimes by state, so check local data-protection rules rather than assuming a widespread practice is lawful. A defensible working position is to capture only what the role requires, note the public source of each detail, keep it in a governed system, and delete on a schedule.
When the filters carry the search. Current employer, time in role, precise location, and any signal a platform derives from member behaviour live in structured fields a general search engine never sees. If the shortlist depends on those attributes, querying crawled page text is the wrong instrument and will quietly return a worse set than the native interface would, with no indication that anything was missed.
Volume is the other case. A licensed sourcing database maintains its own index, refreshes it deliberately, returns repeatable results, exports cleanly into an applicant tracking system, and has support behind it when something breaks. X-ray earns its place where no good native search exists, across the long tail of community and portfolio sites, and as a cross-check when a platform's own ranking seems to be hiding people.
Pitch N Hire is an applicant tracking system built for recruiters and hiring teams. Everything on this page — sourcing, screening, interviewing, offers — runs in one pipeline.
Free for 1 user · No credit card · Talk to a real hiring expert
Pitch N Hire unifies sourcing, screening and hiring decisions on one AI-native platform. Book a quick demo on your real roles.
Prefer to talk? Book a demo · Talk to sales · View pricing
Free 1-user plan · No credit card · Talk to a real hiring expert
See your true cost-per-hire and how much Pitch N Hire could save you — our free Recruitment ROI Calculator gives you the numbers in under a minute. No signup required.
Open the free ROI calculatorPrefer a tailored walkthrough on your real roles? Drop your work email:
★ Free 1-user plan · No spam · Talk to a real hiring expert