Recruiting Basics

X-Ray Search

X-ray search is the technique of using a general search engine's site and URL operators to find public profile pages hosted on a platform, instead of searching inside that platform's own interface. It reaches pages a native search will not show, but it depends on what the engine has indexed, so results are incomplete and often out of date.

Which surfaces does x-ray search work well on?

It works best where a site publishes stable public pages and wants them found: personal sites, documentation and package registries, open technical contributions, association member directories, conference and meetup listings, and university or research group pages. These are indexed willingly and rarely restructured. It works badly on login-walled applications, on anything rendered entirely by client-side script, and on platforms that treat their profile pages as a competitive asset. A useful habit is to check whether a site is indexed at all before building queries against it, rather than concluding from an empty result that nobody relevant is there.

How do you stop an x-ray result set from being mostly noise?

Constrain the path, not just the domain, so the engine returns profile pages rather than help articles, tag pages and directory indexes. Exclude the listing pages that aggregate many names, since they match everything and tell you nothing. Then open the pages instead of trusting the snippet, because the snippet is drawn from the crawled copy and can predate a job change by a long way. Look for a visible date on the page. Most of the time lost to this technique goes on confidently reading a stale cache.

Should a new sourcer be taught x-ray search as a core skill?

Teach it, but position it honestly as one route among several rather than as a signature technique. The genuinely transferable parts are the habits it forces: thinking about where evidence of a skill would be published, constructing a repeatable query, and verifying a claim on the page itself before acting on it. Those survive any platform change. Memorised query patterns do not, and a sourcer taught only patterns is stuck the first time a URL structure moves. Pair it with native search and with whatever licensed tooling the team already pays for.

How does an x-ray query differ from searching inside a platform?

An x-ray query points a general search engine at a single domain and, usually, at the URL pattern that platform uses for its public profile pages, then adds the terms you care about. What comes back is the engine's crawled copy of pages the platform chose to leave open to crawlers. You are searching a third party's index of that site rather than the site's own database.

Three consequences follow. You can only reach what is public, so anything behind a login is invisible no matter how the query is written. You see the page as it was when last crawled, which may be months ago. And you match visible page text rather than structured fields, so the filters the platform offers inside its own interface simply do not exist in the query.

Why do recruiters reach for x-ray search at all?

The first reason is access. Native search interfaces cap how many results a given account can page through, and place the sharper filters behind higher licence tiers, so a recruiter on a basic seat hits a wall that has nothing to do with how many matching people exist. Querying through a search engine sidesteps that interface, though not the underlying limits on what any platform makes public.

The second reason is breadth, and it is the stronger one. Code hosts, community forums, personal portfolio sites, conference speaker listings, professional association directories, meetup groups and university pages hold a great deal of evidence about who does what, and they share no common search interface. One query pattern, repointed at each domain in turn, is the only practical way to sweep across them.

How dependable is x-ray search in practice?

Less dependable than its reputation suggests, and it is worth being blunt about why. Search engines index public pages at their own discretion, so coverage of any given site is partial and shifting. Large platforms actively discourage crawling through robots directives and login interstitials. URL structures change without notice, so a query pattern that worked reliably last year can silently return nothing at all.

The practical rule is that a null result proves nothing. It may mean the people are not there, or that the pattern is stale, or that the engine has dropped coverage of that path. Before concluding a market is thin, verify through a second route: the platform's own search, a licensed database, or a community where the same people gather. Treat the technique as one probe among several.

What terms-of-service and personal-data limits apply?

Platform terms commonly restrict automated collection, scripted querying and bulk export, including of pages any visitor can see. Public visibility and permitted use are different things, and manual searching is usually treated very differently from harvesting at scale. Read the terms of the surfaces your team relies on, and expect both enforcement and the technical countermeasures behind it to change without warning.

Storing what you find raises a separate question, because you are recording identifiable details about people who never approached you. Obligations vary by country and sometimes by state, so check local data-protection rules rather than assuming a widespread practice is lawful. A defensible working position is to capture only what the role requires, note the public source of each detail, keep it in a governed system, and delete on a schedule.

When is native search or a licensed tool simply the better answer?

When the filters carry the search. Current employer, time in role, precise location, and any signal a platform derives from member behaviour live in structured fields a general search engine never sees. If the shortlist depends on those attributes, querying crawled page text is the wrong instrument and will quietly return a worse set than the native interface would, with no indication that anything was missed.

Volume is the other case. A licensed sourcing database maintains its own index, refreshes it deliberately, returns repeatable results, exports cleanly into an applicant tracking system, and has support behind it when something breaks. X-ray earns its place where no good native search exists, across the long tail of community and portfolio sites, and as a cross-check when a platform's own ranking seems to be hiding people.

See how Pitch N Hire handles x-ray search on your roles

FAQ

X-Ray Search — FAQs

Is x-ray search legal? +
Reading public web pages through a search engine is not inherently unlawful, but the answer depends on jurisdiction, on the platform's terms, and on what you then do with the data. Automated collection and storage of personal details are the parts that attract rules. Take local legal advice rather than relying on custom.
Why does a query that used to work now return nothing? +
Usually the URL pattern changed, or the platform tightened what crawlers may index, or the engine reduced coverage of that path. Test the pattern against a page you know exists before assuming the market is empty, and keep a note of when each pattern was last confirmed working.
Can x-ray search replace a paid sourcing licence? +
Not reliably. It reaches surfaces a licence does not cover, which is genuine value, but it cannot match structured filtering, refresh cadence, export or support. Teams that drop a licence in favour of it usually find the gap shows up in repeatability rather than in raw reach.
Does x-ray search work on more than one search engine? +
Yes, and the results differ enough to be worth checking. Engines index different subsets of a site, support slightly different operators and rank differently, so running the same intent through a second engine sometimes surfaces pages the first never showed. Regional engines matter in some markets.
How current are the pages an x-ray search returns? +
As current as the last crawl, which is not visible from the result and can be months old. Treat every finding as a lead to verify rather than a fact, particularly current employer and title, and confirm on the live page before writing an approach that references it.
Pitch N Hire ATS

See how this works in a real applicant tracking system

Pitch N Hire is an applicant tracking system built for recruiters and hiring teams. Everything on this page — sourcing, screening, interviewing, offers — runs in one pipeline.

  • One pipeline for every role, applicant, and interview stage
  • Structured scorecards so the panel compares candidates on the same criteria
  • Careers page, job posting, and candidate communication in one place

Free for 1 user · No credit card · Talk to a real hiring expert

Built for recruiters & hiring teams

See X-Ray Search in action

Pitch N Hire unifies sourcing, screening and hiring decisions on one AI-native platform. Book a quick demo on your real roles.

Prefer to talk? Book a demo · Talk to sales · View pricing

Free 1-user plan · No credit card · Talk to a real hiring expert

One Hiring Infrastructure.
Zero Tool Chaos.

Demos are consultative. We respect privacy and enterprise
governance. No lock-ins.

Start free Book demo