A work inbox is the wrong place to ask someone to leave
A passive candidate is in a job and not looking. The easiest address to find for them is their work email, and it is the one address you must not use. Their employer owns that inbox. It can be monitored, archived and read by whoever inherits it, and a message about leaving sits there next to their manager's.
So this play looks for one thing: an address the person keeps whoever employs them. It walks the personal-email chain, three providers in a fixed order, and stops at the first hit. One rule sits over all three. If the address that comes back is on the domain of the person's current employer, it is not a personal email, whatever the provider called it. It is refused, it is not charged, and the row carries on down the chain.
Plenty of people have no findable personal address. For them the play does not reach for a work email and does not guess. The row is marked LinkedIn only, and the profile stays the way to reach them.
What you get back
Your candidate list with a personal email column. Each address carries the provider that supplied it and a deliverability verdict.
Rows without an address are split in two. LinkedIn only means nothing was found, or the only find was an employer address. Unmatchable means the row gave the providers nothing to work with.
Nothing is sent.
Variations worth knowing
Engineers. Public code commits often carry a personal address, and reading them costs nothing. See engineering sourcing on GitHub. Employer addresses found there are discarded, and a commit address is a follow-up to a LinkedIn approach, not the opener.
Straight from a talent map. A list built with a talent map of passive candidates comes with LinkedIn URLs, which is the input this chain matches best on.
A mixed list. Hiring managers get a work email, which is a different chain. Split them out, or use get emails and mobiles for a list you already have, which asks who is who and routes each group.
Where this goes wrong
No employer domain on the row. The employer rule compares the found address with the employer's web domain on the row. With no domain there is nothing to compare, and a work address can come back labelled as personal. The same happens if the row names a company the person has left.
No LinkedIn URL. The first provider in the chain works from a profile URL and nothing else. Rows with only a name and an employer skip it and start further down, so they are found less often.
Reading LinkedIn only as a failure. It is a normal result on any passive list. Coverage depends on the person, not on how hard anyone looks, and the profile link is a channel in its own right.