SSL & Security
Data Breach Checker
Check an Email Address
Tool features
4 features
Breach Detection
Check against hundreds of known data breaches
Privacy First
We never store or log your email address
Detailed Reports
See exactly which services were breached and what data was exposed
Action Guide
Get specific steps to protect yourself after a breach
What is a data breach & how it works
A data breach is an incident where a service's user data is stolen and often published or sold. Leaked email addresses, password hashes, names and phone numbers are then used for credential stuffing, targeted phishing and account takeover, sometimes years later.
This checker looks up your email address in the Have I Been Pwned database, which indexes billions of accounts from known breaches and pastes. It shows which breaches included the address, when they happened and what types of data were exposed, so you know which passwords to change first.
Breach
A confirmed compromise of a service, catalogued with the data it exposed.
Paste
Data dumped publicly on a paste site, often an early sign of a breach.
Credential stuffing
Trying leaked email and password pairs on other sites; stopped by unique passwords.
How to use this tool
1
Enter your email
Type the email address you want to check.
2
Run the check
The address is looked up in the Have I Been Pwned breach and paste database.
3
Review the breaches
See each breach that included the address, its date and which data classes were exposed.
4
Secure your accounts
Change the password on affected services and anywhere you reused it, and turn on two-factor authentication.
Related tools
3 tools
SSL Checker
Comprehensive SSL certificate analysis including validity, expiration, chain verification, TLS versions, and security assessment
Secure Header Checker
Check security headers like CSP, HSTS, X-Frame-Options, and more with security scoring
IP Blacklist Checker
Check if IP address is blacklisted across multiple DNSBL and spam databases
Frequently asked questions
5 Q&A
No. The address is sent to the HIBP API to perform the lookup and is not stored or logged by ShowDNS.
Change the password for that service and for any other account where you used the same password. Use a password manager to create unique passwords, enable two-factor authentication, and be wary of phishing emails that reference the breached service.
It means the address does not appear in any breach HIBP has catalogued. Unreported or unverified breaches are not included, so unique passwords and two-factor authentication remain important.
Check the data classes listed for each breach. If passwords are listed, assume that password is compromised even if the service stored it hashed.