Outbound Atlas

Atlas/Search/Player teardowns

ReachInbox: SEO teardown

ReachInbox's robots.txt points to 1,584 sitemap files of /people/ profile pages, roughly 20M URLs by our arithmetic, hosted on a public storage bucket, while the pages themselves sit behind a bot challenge and the site earns little search traffic.

Searchlow confidence6 minupdated 2026-10-057 sources
Domain
reachinbox.ai
Footprint
1,337,500 /people/ URLs read from 107 of 1,584 sitemap files (crawl truncated); ~77 marketing URLs and ~244 blog posts in sitemaps robots.txt does not list
AEO posture
No llms.txt, no pricing.md, no AI bot rules; people pages return a Cloudflare challenge with noindex
Subdomains
77 in cert logs, 68 live: 48 numbered 'ee' hosts (EmailEngine), affiliates, ltdpartners, docs, help, guide, mcp (404)
The read
A people-directory page farm on the scale of a data broker, attached to a budget sequencer. It barely ranks, it is blocked behind a challenge page, and it carries GDPR exposure for every EU name it lists.

ReachInbox has put the largest sitemap in this study behind a cheap cold-email tool: millions of /people/<first>/<last>/<id> profile URLs, generated once at the end of 2024 and served from a public storage bucket. The bet is the data-broker play, ranking for people's names the way ZoomInfo and RocketReach do. The evidence says it has not worked: about 577 ranking keywords, mostly the brand.

Footprint

Crawled 5 October 2026 (research/seo-data/reachinbox.ai.json), plus our own sitemap fetches.

SourceURLsWhat it is
robots.txt → 1,584 files on a public R2 bucket1,337,500 read (107 files)/people/First/Last/<24-hex id> profile pages
Same, extrapolated≈19.7M12,500 URLs per full file; the last file in each letter group is partial (we checked 3)
reachinbox.ai/sitemap.xml (not in robots.txt)77Marketing pages, A–Z company directory, /people/privacy-center
/blog/sitemap_index.xml (WordPress, not in robots.txt)~244Listicles, alternatives, templates

The people sitemaps are grouped by first-name initial, but only nine letters exist: f, i, o, u, v, w, x, y, z. Every lastmod we checked reads 31 December 2024, which looks like a single generation run. The extrapolated total is our arithmetic, not a count.

The numbers

1,584 sitemap files × up to 12,500 URLs ≈ 19.8M people pages listed, against ~577 ranking keywords for the whole domain (Similarweb estimate). Nearly 20 million pages produce no visible search footprint.

What ranks

Similarweb's free page shows about 107K visits, 80% of desktop traffic direct, and 577 keywords led by "reachinbox" (third-party panel estimate, August 2026 snapshot). It files the site under "Social Media Networks" and lists unrelated email-marketing tools as competitors, a sign of how thin the panel data is for a site this small. Its top countries are the UK (21%), France (17%) and Spain (15%) ahead of the US. We could not tell whether that European skew comes from people-page visits.

Brand queries in our search tool (not Google; indicative) returned review and deal pages: an AppSumo-era review, Woodpecker's and Stamina's reviews, Trustpilot, G2, Capterra and AppSumo reviews. We found no /people/ URL in any result.

Programmatic and template plays

  • People directory. We could not see a single profile. Every request (curl and our fetch tool) got a Cloudflare challenge (HTTP 403, "Just a moment…", cf-mitigated: challenge) with noindex,nofollow. If Googlebot meets the same wall, the pages cannot be indexed at all. The URL shape (name plus a 24-hex ID) matches database records, which suggests the pages are a public view onto the lead database behind the product (Built-in lead database).
  • Opt-out pages. The marketing sitemap lists /people/privacy-center, /remove and /update. A removal flow is what a people-search site needs to defend itself under privacy law.
  • Company directory. A–Z index pages under /company/directory/.
  • Blog. A WordPress install at /blog/ with "alternatives" and template posts. It is not referenced from robots.txt.
Gap in the record

We could not see what a people page shows (job title, company, masked or unmasked email), whether Google can crawl it, or how many are indexed. Treat everything about content and indexing as unverified.

AEO posture

There is none. The site has no llms.txt or pricing.md, and its docs subdomain has no llms.txt either (docs.reachinbox.ai/llms.txt returns 404). robots.txt contains a bare User-agent: * followed by 1,584 sitemap lines and no rules. An mcp.reachinbox.ai hostname exists but returns 404. The homepage embeds Organization data naming the founder organisation as "Outbox Labs" and the founding date as 2023.

Subdomains

There are 77 names in the certificate logs, and 68 answered. They show the infrastructure:

  • 48 numbered ee hosts (ee, ee2…ee48, all 403) plus eeverify, which serves the EmailEngine page. The naming suggests ReachInbox shards its IMAP/SMTP layer on the same self-hosted gateway that EmailBison runs per tenant.
  • Elastic (search cluster login), mailers, mailersapi and warmverify.
  • Monetisation: affiliates, ltdaffiliates, ltdpartners ("ReachInbox - Lifetime Deals") and pay.
  • Support: help, guide, docs and roadmap.
  • stageseo (403), an SEO staging host.
Same owner as Zapmail

ReachInbox's footer reads "© Outbox Labs" (terms page), and Zapmail's llms.txt opens "Zapmail (by Outbox Labs Inc.)". Zapmail's subdomains repeat the pattern: 96 numbered ee shards, stageseo, onebox. One company runs a sequencer and an inbox reseller on shared plumbing (see Zapmail).

Off-site

  • Lifetime deals. AppSumo coverage, an /ltd page and a dedicated LTD-partner portal. LTD buyers write reviews and affiliate content, which is why AppSumo pages rank for the brand.
  • Affiliates through affiliates.reachinbox.ai and coupon sites (JoinSecret, FounderPass).
  • Review sites. G2 lists it under the slug outbox-lab-reachinbox, alongside Trustpilot and Capterra.

Weak spots

  • Legal exposure. A public directory of named individuals (the samples include German, Hungarian and Greek names) is personal-data processing under GDPR. It needs a lawful basis, normally an Article 14 notice to the people listed, and an opt-out that works. A privacy centre helps; it does not settle the basis (GDPR and ePrivacy, Data sourcing law).
  • Doorway and scaled-content risk. Millions of near-identical pages, all stamped with the same day in December 2024, are the textbook case. Any penalty would also hit the sequencer's own pages.
  • Discovery is broken. The real marketing and blog sitemaps are not in robots.txt, while the people sitemaps are, on another host.
  • The challenge page defeats the point. If bots cannot get through, the pages cost crawl budget and earn nothing.

What this means for an entrant

  • Do not build a people directory, least of all from the EU. The cost is legal and reputational, the payoff here is nil, and an EU-native vendor selling compliance cannot carry it (EU-native compliant outbound, Trust as positioning).
  • Price floor ≠ search moat. ReachInbox has the cheapest volume tier we found (Sequencing & sending) and almost no organic reach. Low price is distributed through LTDs and affiliates, not search.
  • Watch the Outbox Labs bundle. A sequencer plus an inbox reseller under one owner is a smaller version of the Forge playbook (Salesforge and the Forge: SEO teardown). It competes on price per inbox, not content.
  • Basic hygiene is a cheap win. List your real sitemaps in robots.txt, ship llms.txt and pricing.md, and keep staging hosts private.
7 sources cited on this page · 7 domains
  1. about 107K visits, 80% of desktop traffic direct, and 577 keywords led by reachinbox similarweb.com
  2. an AppSumo-era review daveswift.com
  3. AppSumo reviews appsumo.com
  4. terms page reachinbox.ai
  5. Zapmail's llms.txt zapmail.ai
  6. JoinSecret joinsecret.com
  7. outbox-lab-reachinbox g2.com