Email Breach Checker
See which known data breaches included an email address. The tool asks the Have I Been Pwned API v3 and lists each breach with the website, date, number of affected accounts, the kinds of data exposed and whether it is verified, followed by clear steps to secure your accounts. The search needs a Have I Been Pwned API key; if the site owner has not added one, the tool says so honestly and checks nothing.
- Encrypted connection
- No sign-up
- Free to use
How to use Email Breach Checker
- Enter your email address.
- Click Check breaches.
- Review each breach and the exposed data.
- Change affected passwords and enable two-factor authentication.
Email Breach Checker features
Have I Been Pwned
The most widely used breach database.
Exposed data
Passwords, phone numbers, addresses…
Clear next steps
What to change first.
Privacy
The address is not logged or stored.
Sensitive breaches hidden
Never shown in public searches.
Honest setup
Says when no API key is configured.
When to use Email Breach Checker
- Checking your own accounts.
- Security awareness at work.
- After a breach notification email.
- Family digital safety.
Email Breach Checker FAQ
Why does it need an API key?
Have I Been Pwned only allows email searches through its paid API. The site owner adds the key in the admin panel; without it the tool does not search.
Is my email stored?
No. It is sent to Have I Been Pwned for this one search over HTTPS and not logged or cached by this site.
Can I check someone else’s address?
Only check addresses you own or are allowed to check.
What if my email was found?
Change the passwords of the affected accounts and anywhere you reused them, and turn on two-factor authentication.
Breaches happen to everyone
Most people’s email addresses have appeared in several breaches. What matters is that passwords are unique and accounts are protected with a second factor.
How it works: checks that need the network are made by our server through a guarded client that only connects to public addresses on the standard web ports, pins every connection to the validated address and limits time and response size. Pasted input is analysed in your browser and never sent. Nothing you check is stored, and requests are rate-limited to keep the service fair.
Every finding is rule-based and explained: the tool tells you what it saw, why it matters and what to change, instead of showing an unexplained score. Grades summarise the findings so you can compare sites and track progress after a fix, but the individual checks are what you should act on.
Only check systems you own or are authorised to assess. The probes behave like a normal browser or client – they read public responses and perform ordinary handshakes – and never try to exploit a weakness, guess passwords or overload a server.
Related tools on this site cover the rest of a security review – security header generators, CSP and CORS generators, SSL certificate and expiry checks, SPF, DKIM and DMARC record checkers, JWT tools and password generators – so you can fix what you find in the same place.