You can't just run it on random people emails aren't disclosed and even if you know someone on the app in real life, chances are good that they use a personal address that you won't have.
The token should only be accessible to the user requesting the password reset, meaning that it would be sent via email this is the standard password reset flow.
That could narrow down the list significantly.
Only an email of a Grindr user had to be hacked.