What a breach check tells you
When a company's systems are breached, the stolen data — often including email addresses, passwords, and other details — frequently ends up published or traded. Have I Been Pwned catalogues these disclosed breaches. Checking your address tells you whether it appears in any of them, and which.
A clean result means your address isn't in the breaches HIBP has indexed. It's reassuring, but not a guarantee: breaches surface later, and this only covers what's publicly disclosed.
How your email is handled
The lookup happens on our server so your address never goes to HIBP from your browser directly. It's used for this one query and discarded — we don't store it, log it, or attach it to any profile. There's no account and no history.
What to do if you're in a breach
- Change the password on the breached service, and anywhere you reused it.
- Turn on two-factor authentication so a stolen password alone isn't enough.
- Use a password manager to give every account a unique password, so one breach stays contained.
Common questions
Do you keep my email address?
No. It's used only for the single lookup and immediately discarded. There's no account, no history, and nothing stored on our side.
My email wasn't found — am I safe?
It means your address isn't in the breaches HIBP has indexed today. New breaches are disclosed regularly, so treat a clean result as a snapshot, not a permanent all-clear.
The check said it's unavailable — why?
The breach lookup needs an API key this deployment hasn't set, or the service was temporarily unreachable. We report that rather than show a made-up result.
Related checks
Breaches are one exposure. These cover your live connection: