Security Tools

Email Breach Checker

See which known data breaches included an email address. The tool asks the Have I Been Pwned API v3 and lists each breach with the website, date, number of affected accounts, the kinds of data exposed and whether it is verified, followed by clear steps to secure your accounts. The search needs a Have I Been Pwned API key; if the site owner has not added one, the tool says so honestly and checks nothing.

  • Encrypted connection
  • No sign-up
  • Free to use
The breach search is not configured on this site yet: it needs a Have I Been Pwned API key, which the site owner adds in the admin panel. Until then you can search directly at haveibeenpwned.com, and check passwords with our Password Leak Checker, which needs no key.

Check only addresses you own or are allowed to check. The address is sent to Have I Been Pwned over HTTPS for this one search and is not logged or stored by this site.

How to use Email Breach Checker

  1. Enter your email address.
  2. Click Check breaches.
  3. Review each breach and the exposed data.
  4. Change affected passwords and enable two-factor authentication.

Email Breach Checker features

Have I Been Pwned

The most widely used breach database.

Exposed data

Passwords, phone numbers, addresses…

Clear next steps

What to change first.

Privacy

The address is not logged or stored.

Sensitive breaches hidden

Never shown in public searches.

Honest setup

Says when no API key is configured.

When to use Email Breach Checker

  • Checking your own accounts.
  • Security awareness at work.
  • After a breach notification email.
  • Family digital safety.

Email Breach Checker FAQ

Why does it need an API key?

Have I Been Pwned only allows email searches through its paid API. The site owner adds the key in the admin panel; without it the tool does not search.

Is my email stored?

No. It is sent to Have I Been Pwned for this one search over HTTPS and not logged or cached by this site.

Can I check someone else’s address?

Only check addresses you own or are allowed to check.

What if my email was found?

Change the passwords of the affected accounts and anywhere you reused them, and turn on two-factor authentication.

Breaches happen to everyone

Most people’s email addresses have appeared in several breaches. What matters is that passwords are unique and accounts are protected with a second factor.

How it works: checks that need the network are made by our server through a guarded client that only connects to public addresses on the standard web ports, pins every connection to the validated address and limits time and response size. Pasted input is analysed in your browser and never sent. Nothing you check is stored, and requests are rate-limited to keep the service fair.

Every finding is rule-based and explained: the tool tells you what it saw, why it matters and what to change, instead of showing an unexplained score. Grades summarise the findings so you can compare sites and track progress after a fix, but the individual checks are what you should act on.

Only check systems you own or are authorised to assess. The probes behave like a normal browser or client – they read public responses and perform ordinary handshakes – and never try to exploit a weakness, guess passwords or overload a server.

Related tools on this site cover the rest of a security review – security header generators, CSP and CORS generators, SSL certificate and expiry checks, SPF, DKIM and DMARC record checkers, JWT tools and password generators – so you can fix what you find in the same place.

Other useful tools