Data Breach Email Checker
If your email appears in a breach: change that password everywhere it was reused, and turn on two-factor authentication.
Enter an email address and the checker looks it up against the public breach index maintained by Have I Been Pwned. It tells you in how many breaches the address has shown up, the name of each breach (LinkedIn 2016, Adobe 2013, Collection #1, and so on) and what types of data were exposed, so you know whether to rotate a password, review a card or just stay alert for phishing.
How to check an email for breaches
-
1
Type an email address
The full address in the format name@domain.tld. The checker validates the syntax before querying anything.
-
2
Submit the lookup
The tool opens the Have I Been Pwned unified search for that address. HIBP does the actual breach matching.
-
3
Review the result
You will see a count of breaches (e.g. "found in 7 breaches") and a list with each breach name, date and exposed data types.
-
4
Act on what is listed
Rotate passwords reused with that email, enable two-factor auth on the affected services, and stay alert for targeted phishing in the weeks after a fresh breach.
What counts as a “breach”
A breach is any incident where data from a service was leaked or sold outside the organisation that held it. The HIBP index covers:
| Incident type | Example | Typical exposure |
|---|---|---|
| Server compromise | Adobe 2013, LinkedIn 2016 | Emails, hashed passwords, sometimes plain ones |
| Credential stuffing dumps | Collection #1 (2019) | Email/password pairs pasted from older breaches |
| Scraped public data | LinkedIn 2021 scraping | Public profile fields, no passwords |
| Forum leaks | MyFitnessPal 2018 | Emails, usernames, hashed passwords |
| Third-party vendor hacks | Various SaaS providers | Whatever the vendor held |
What to do if you show up in a breach
- Identify reused passwords. Any password you set on the breached site that you have used elsewhere must be changed. Use a password manager to find reuse quickly.
- Rotate the breached password. Even if it is not reused, rotate it, dumps stay in circulation for years.
- Turn on two-factor authentication on the most critical accounts (email, bank, password manager, work SSO). TOTP or passkeys, not SMS if you can help it.
- Watch for targeted phishing. Fresh breaches spawn personalised scam emails using the leaked data. If an email seems to know too much, assume phishing and verify through a separate channel.
- Consider the age of the breach. A 2012 breach is mostly noise today; a 2024 breach still matters.
Limits of any breach checker
- Not every breach is public. Private company incidents and law-enforcement seizures rarely hit the public index for months or years.
- A “not found” result does not mean “safe”. It means your email has not appeared in any known breach.
- Breaches of services that never held your email cannot affect it, but password reuse can still take you down with other people’s data.
The healthier habit
Breach checks are reactive. The proactive habit is a password manager with unique passwords everywhere, plus two-factor auth on every account that supports it. Treat the checker as a periodic audit, not a real-time alarm.
Frequently Asked Questions
Yes, the lookup is performed against the public Have I Been Pwned API, so your email has to reach their server. The request is HTTPS and HIBP publishes its own privacy policy. Nothing is stored on this site beyond the usual access logs.
These are aggregations of older breaches. The single most useful action is to change any password you ever reused across multiple sites, then turn on a password manager so you never have to reuse again.
Not here. For passwords, use a dedicated checker that uses the k-anonymity API, it only ever sends the first 5 characters of the password hash, so the password itself never leaves your device.
Not always. Some breaches only leaked email addresses or phone numbers. Others leaked password hashes that may or may not have been cracked. Check the “compromised data” list for each specific breach to know what was exposed.
Scraping breaches collect public data, and aggregation breaches mash together older leaks. You may also have signed up years ago and forgotten, or someone used your address without confirmation.
Related Tools
What Is My IP
See the IP address this server received for your request, its IPv4 or IPv6 family, and an approximate country when local GeoIP data is available.
IP Address Lookup
Look up any public IPv4 or IPv6 address for approximate country, region, city, coordinates, ISP, ASN, organization and timezone.
Speed Test
Run a fast, free, browser-based internet speed test. Measure your download speed in Mbps plus round-trip latency and jitter, and see whether your connection is ready for 4K streaming, gaming and video calls, no app, no signup.
WHOIS Lookup
Look up public WHOIS registration data for a domain: registrar, nameservers, status codes and expiry dates.
DNS Lookup
Query the A, AAAA, MX, TXT, NS, CNAME and SOA records of any domain without opening a terminal.
API Endpoint Checker
Test a CORS-enabled HTTP or HTTPS endpoint from your browser. Inspect its final status, exposed headers, response time and a bounded body preview.
Tool available in other languages
- E-postkontroll för dataintrång [SV]
- Data Breach Email Checker [ID]
- เครื่องตรวจสอบอีเมลที่เกี่ยวข้องกับการรั่วไหลของข้อมูล [TH]
- データ漏洩メールチェッカー [JA]
- Trình kiểm tra email liên quan đến sự rò rỉ dữ liệu [VI]
- Verificador de correos electrónicos de filtraciones de datos [ES]
- Veri Sızıntısı E-posta Kontrolcüsü [TR]
- E-Mail-Prüfer für Datenpannen [DE]
- Vérificateur d'Email de Fuite de Données [FR]
- Verificador de E-mail de Vazamento de Dados [PT]
- 数据泄露邮件检测工具 [ZH]
- مدقق البريد الإلكتروني لخرق البيانات [AR]
- 데이터 유출 이메일 검사기 [KO]
- Datalek-e-mailcontrole [NL]
- Sprawdzanie e-maila pod kątem wycieków danych [PL]
- Инструмент для проверки электронных писем на наличие утечки данных [RU]
- Controllore Email per Violazioni di Dati [IT]