SSL & Security

Data Breach Checker

Breach Exposure

Check an Email Address

Enter an email address to check if it has appeared in any known data breaches.

Tool features

Privacy-first email breach detection
4 features

Breach Detection

Check against hundreds of known data breaches

Privacy First

We never store or log your email address

Detailed Reports

See exactly which services were breached and what data was exposed

Action Guide

Get specific steps to protect yourself after a breach

What is a data breach & how it works

How leaked data is used against your accounts

A data breach is an incident where a service's user data is stolen and often published or sold. Leaked email addresses, password hashes, names and phone numbers are then used for credential stuffing, targeted phishing and account takeover, sometimes years later.

This checker looks up your email address in the Have I Been Pwned database, which indexes billions of accounts from known breaches and pastes. It shows which breaches included the address, when they happened and what types of data were exposed, so you know which passwords to change first.

Breach
A confirmed compromise of a service, catalogued with the data it exposed.
Paste
Data dumped publicly on a paste site, often an early sign of a breach.
Credential stuffing
Trying leaked email and password pairs on other sites; stopped by unique passwords.

How to use this tool

Check an email address for breaches in four steps
1
Enter your email
Type the email address you want to check.
2
Run the check
The address is looked up in the Have I Been Pwned breach and paste database.
3
Review the breaches
See each breach that included the address, its date and which data classes were exposed.
4
Secure your accounts
Change the password on affected services and anywhere you reused it, and turn on two-factor authentication.

Frequently asked questions

Common questions about data breaches
5 Q&A

From Have I Been Pwned (HIBP), the widely used breach-notification service run by security researcher Troy Hunt, which catalogues verified breaches and public pastes.

No. The address is sent to the HIBP API to perform the lookup and is not stored or logged by ShowDNS.

Change the password for that service and for any other account where you used the same password. Use a password manager to create unique passwords, enable two-factor authentication, and be wary of phishing emails that reference the breached service.

It means the address does not appear in any breach HIBP has catalogued. Unreported or unverified breaches are not included, so unique passwords and two-factor authentication remain important.

Check the data classes listed for each breach. If passwords are listed, assume that password is compromised even if the service stored it hashed.