Data Breach Email Checker

We never transmit your email to our servers. The check is performed directly at Have I Been Pwned when you click the button.
Enter a valid email address.

If your email appears in a breach: change that password everywhere it was reused, and turn on two-factor authentication.

Enter an email address and the checker looks it up against the public breach index maintained by Have I Been Pwned. It tells you in how many breaches the address has shown up, the name of each breach (LinkedIn 2016, Adobe 2013, Collection #1, and so on) and what types of data were exposed, so you know whether to rotate a password, review a card or just stay alert for phishing.

How to check an email for breaches

  1. 1

    Type an email address

    The full address in the format name@domain.tld. The checker validates the syntax before querying anything.

  2. 2

    Submit the lookup

    The tool opens the Have I Been Pwned unified search for that address. HIBP does the actual breach matching.

  3. 3

    Review the result

    You will see a count of breaches (e.g. "found in 7 breaches") and a list with each breach name, date and exposed data types.

  4. 4

    Act on what is listed

    Rotate passwords reused with that email, enable two-factor auth on the affected services, and stay alert for targeted phishing in the weeks after a fresh breach.

What counts as a “breach”

A breach is any incident where data from a service was leaked or sold outside the organisation that held it. The HIBP index covers:

Incident type Example Typical exposure
Server compromise Adobe 2013, LinkedIn 2016 Emails, hashed passwords, sometimes plain ones
Credential stuffing dumps Collection #1 (2019) Email/password pairs pasted from older breaches
Scraped public data LinkedIn 2021 scraping Public profile fields, no passwords
Forum leaks MyFitnessPal 2018 Emails, usernames, hashed passwords
Third-party vendor hacks Various SaaS providers Whatever the vendor held

What to do if you show up in a breach

  1. Identify reused passwords. Any password you set on the breached site that you have used elsewhere must be changed. Use a password manager to find reuse quickly.
  2. Rotate the breached password. Even if it is not reused, rotate it, dumps stay in circulation for years.
  3. Turn on two-factor authentication on the most critical accounts (email, bank, password manager, work SSO). TOTP or passkeys, not SMS if you can help it.
  4. Watch for targeted phishing. Fresh breaches spawn personalised scam emails using the leaked data. If an email seems to know too much, assume phishing and verify through a separate channel.
  5. Consider the age of the breach. A 2012 breach is mostly noise today; a 2024 breach still matters.

Limits of any breach checker

  • Not every breach is public. Private company incidents and law-enforcement seizures rarely hit the public index for months or years.
  • A “not found” result does not mean “safe”. It means your email has not appeared in any known breach.
  • Breaches of services that never held your email cannot affect it, but password reuse can still take you down with other people’s data.

The healthier habit

Breach checks are reactive. The proactive habit is a password manager with unique passwords everywhere, plus two-factor auth on every account that supports it. Treat the checker as a periodic audit, not a real-time alarm.

Frequently Asked Questions

Yes, the lookup is performed against the public Have I Been Pwned API, so your email has to reach their server. The request is HTTPS and HIBP publishes its own privacy policy. Nothing is stored on this site beyond the usual access logs.

These are aggregations of older breaches. The single most useful action is to change any password you ever reused across multiple sites, then turn on a password manager so you never have to reuse again.

Not here. For passwords, use a dedicated checker that uses the k-anonymity API, it only ever sends the first 5 characters of the password hash, so the password itself never leaves your device.

Not always. Some breaches only leaked email addresses or phone numbers. Others leaked password hashes that may or may not have been cracked. Check the “compromised data” list for each specific breach to know what was exposed.

Scraping breaches collect public data, and aggregation breaches mash together older leaks. You may also have signed up years ago and forgotten, or someone used your address without confirmation.

Related Tools

Tool available in other languages