Skip to main content

Privacy tool

Data Breach Check

Check whether an email address has appeared in a known data breach. We check it against Have I Been Pwned's breach database and never log or store the address you enter.

We never log or store the address you enter. It's used only for this one check, then discarded.

What happens to the address you enter.

It's sent securely to our server and checked against Have I Been Pwned's breach database, then discarded. We don't log it, store it, or use it for anything else, and we never see the results of anyone else's check.

How this check works

When you submit an email address, our server sends it securely to Have I Been Pwned, a breach database that tracks which email addresses have appeared in publicly known data breaches, and reports back whether it found a match. The address is used only for that one check: it is never written to a log, never stored in a database, and never used for anything beyond running that single lookup.

What a match means, and what it doesn't

A match means the email address appeared in the data a known breach exposed, not that the account is currently compromised. If you see a match, the most useful next step is changing the password on that account, and on any other account where you've reused the same password, then turning on multi-factor authentication wherever it's available.

What this check doesn't cover

Have I Been Pwned's database only includes breaches it has verified and ingested. A clean result is a good sign, not a guarantee: new breaches surface regularly, and some never become public at all. Treat this as one signal among several, alongside good password hygiene and a password manager, rather than a complete answer.