X-ray Search for Recruiters: How to Write Strings That Find People
What X-ray search is, how to build a string one step at a time, where it works beyond LinkedIn, and how to fix one that returns the wrong people

X-ray search is a Google query that uses the site: operator and Boolean terms to find candidate profiles inside one website. It costs nothing but your time. It also reaches people who never applied to your job post and aren't in your database. When few people apply, those extra names can give you enough candidates to send the hiring manager or client a real shortlist.
Key takeaways
- Point site: at the part of a website that holds people, such as linkedin.com/in, so job posts and company pages drop out.
- Add one term at a time and read the first page after each change, so you can see which term helped and which one cut good people.
- Treat LinkedIn results as a supplement to other sources, because search engines show only what members chose to make public.
- Plan a separate step for contact details, since results often give you a name and a page with no email or phone number.
What is X-ray search?
X-ray search means pointing a search engine at one website and asking it for pages that match your terms. It's also called Google X-ray search, and Google is where the examples below run. The site: operator does the pointing, and Boolean terms such as OR and the minus sign decide which pages come back.
That's where the two ideas split. Boolean search is the logic you write, and X-ray is the place you aim it. If you already write strings for job boards or your applicant tracking system (ATS), the Boolean search guide covers the operators in depth.
Pointed at public web pages, those strings make X-ray sourcing one channel within candidate sourcing, alongside job posts, referrals, and paid databases.
How to write an X-ray search string
You write an X-ray search string by adding one part at a time. The parts are the site, the job titles, a must-have term, the location, and the exclusions. After each addition, read the first page of results before you change anything else.
A university library guide explains the operators you'll use. Quotation marks match an exact phrase, a capitalized OR looks for either term, and site: searches within one site or domain.
Say you're filling an HVAC service technician role in Columbus, Ohio, for a commercial building services company (an illustrative example). Each step below shows how the string grows and what changes in the results.
1. Pick the site: Start with the part of the site that holds people. On LinkedIn, public profiles sit under /in, so this first line returns profiles of every kind.
site:linkedin.com/in
2. Add the job title variants: People describe the same job in different words, so put the common titles in quotes and join them with OR. Pull the variants from the job description. The way the hiring manager or client talks about the role is another good source. The results now lean toward HVAC work, but they still cover the whole country.
site:linkedin.com/in ("HVAC technician" OR "HVAC service technician" OR "HVAC mechanic")
3. Add a must-have credential or skill: Pick the one term a qualified person is likely to list, which here is EPA 608. The list gets shorter, but you'll lose people who never wrote it down, so add one must-have rather than three.
site:linkedin.com/in ("HVAC technician" OR "HVAC service technician" OR "HVAC mechanic") "EPA 608"
4. Add the location: Put the city and state together in quotes so people in Columbus, Georgia, and Columbus, Indiana, drop out. If the commute allows, add nearby suburbs with OR.
site:linkedin.com/in ("HVAC technician" OR "HVAC service technician" OR "HVAC mechanic") "EPA 608" ("Columbus Ohio" OR "Dublin Ohio" OR "Westerville Ohio")
5. Exclude the noise: A minus sign removes any page that contains a word. Recruiter profiles and hiring announcements often crowd the first pass, so -recruiter and -hiring clear them out. Use exclusions sparingly, because each one also removes any good candidate whose profile happens to use that word.
site:linkedin.com/in ("HVAC technician" OR "HVAC service technician" OR "HVAC mechanic") "EPA 608" ("Columbus Ohio" OR "Dublin Ohio" OR "Westerville Ohio") -recruiter -hiring
6. Check the first page and adjust: Open five or six results and ask whether you'd call these people. If most of them install residential systems and the client needs commercial service experience, add the word commercial. If the page comes back nearly empty, remove the last term you added.
site:linkedin.com/in ("HVAC technician" OR "HVAC service technician" OR "HVAC mechanic") "EPA 608" ("Columbus Ohio" OR "Dublin Ohio") commercial -recruiter -hiring
LinkedIn X-ray search
A LinkedIn X-ray search uses site:linkedin.com/in to bring public member profiles into Google's results. What you see depends on what each member has made public to search engines. Some profiles won't appear at all, and others show only part of what's on the page.
Because of that, results can be patchy, and two similar strings may surface different people. Treat these results as a supplement to your other sources. It's good at showing you who exists in a market and which titles they use, and those titles then sharpen the searches you run elsewhere. If you're weighing it against paid options, the guide to sourcing tools covers where each fits.
Where else X-ray search works
The same method works on any site where people post their own work or credentials as public pages. The table below lists site types worth trying, what each one holds, and a sample string to start from. Resume searches rely on filetype:, which Michigan Tech's library guide describes as showing only results of a specific file type. They also use intitle:, which looks for a word in the page title.
| Site type | What you'll find | Sample string |
|---|---|---|
| Public profile sites | Profiles members chose to make public | site:linkedin.com/in "HVAC technician" "Columbus Ohio" |
| Resumes posted as documents | Resumes saved as PDF or Word files | (filetype:pdf OR filetype:doc) intitle:resume HVAC Ohio |
| Association member directories and conference speaker lists | Members and speakers in a trade or field | site:org "member directory" HVAC Ohio |
| Code hosting for developers | Developer profiles and public code | site:github.com "Columbus Ohio" Python |
| Portfolio sites for designers | Design work with the designer's name | site:dribbble.com "product designer" Chicago |
| State license lookups where public | The state's public license search page | site:ohio.gov "license lookup" |
For the HVAC search, the resume and association rows are the next ones to try, since a technician may never have built a full online profile. A developer search would start with code hosting instead. Use a state license lookup to confirm a license a candidate mentions, not as a list to search for new people.
How to fix an X-ray search that returns the wrong people
Bad results often come from one term that's too broad, too narrow, or aimed at the wrong part of a site. Match what you see on the first page to a row below. Make that one change and run the string again.
| What you see | Likely cause | Fix |
|---|---|---|
| Too many results to read | Broad titles with nothing to narrow them | Add one must-have term in quotes or tighten the location |
| Job posts instead of people | The site: target covers job pages too | Point site: at the profile path and add -jobs |
| People in the wrong city | The city name matches other states or past jobs | Put the city and state together in quotes |
| Zero results | Too many quoted terms or an OR typed in lowercase | Capitalize OR and remove the last term you added |
| The same few profiles every time | Your titles match how only a few people describe the job | Swap in other title variants and drop one filter |
In the HVAC example, the repeat-profile problem is the one to watch. Technicians may call themselves a refrigeration technician or a service tech, so a string built only on HVAC titles keeps finding the same people. Adding one variant at a time shows which word brings in new names.
When X-ray search is worth the time
X-ray search pays off for niche or local roles, small sourcing budgets, and quick checks on how many people a market holds. A rough count like that can feed a talent map before a kickoff call.
It also helps when the job post brings in too few people. SHRM's 2025 Talent Trends survey of human resources (HR) professionals found that low applicant numbers were the top challenge (51%) among those having trouble recruiting. Searching the public web is a low-cost way to add names when that happens to you.
It's weaker when you need volume or contact details fast, because you read pages one at a time. Track replies and hires by channel with sourcing metrics so you can see whether the hours pay off.
One note on responsible use. An X-ray query reads public pages one search at a time, the same way anyone uses a search engine. Automated scraping tools that copy pages in bulk are a different thing and may break a site's terms, so check with your company before you use one. That's practice advice, not a legal opinion.
Check for contact details before you rely on X-ray
X-ray results often stop at a name, a title, and a page, with no way to reach the person. For the HVAC role, a profile may show EPA 608 and the right city but no email or phone number. Before you build a plan around X-ray, open a handful of results and look for contact details. If most have none, budget time for that step or pair X-ray with a source where candidates shared them.
Check the first page before you widen the search
A useful string comes from small changes to the words and the site, each judged against the people on the first page. Even a strong list leaves a second job, which is finding a way to reach each person, so budget for it. Folding X-ray into a one-page sourcing plan keeps it in proportion with your paid and referral sources. Pick one open role today, build its string one step at a time, and read the first page before you add anything else.
Start from a brief instead of a blank search bar
Book a demoFrequently asked questions
Is X-ray search free?
Running one costs nothing beyond your time, since it uses an ordinary search engine. The cost that matters is the hours spent reading pages and tracking down contact details. Compare those hours with what a paid source would cost for the same role before you decide which to use.
Can you X-ray search with engines other than Google?
Other search engines support site-style operators to varying degrees, so the same string can return different pages. Run your string on a second engine and compare the first page with Google's. If an operator seems to be ignored, cut the string back to site: plus a few quoted terms.
About the author

Founder & CEO of Rotto, building tools that help tech recruiters source better candidates, faster.





