T-07 · api

Breach Check

When a service you use is breached, your email and other details can end up in public dumps. This checks your address against Have I Been Pwned's index of known, disclosed breaches.

How this page is funded. Some links here are affiliate links — if you buy through them we may earn a commission, at no extra cost to you. It never changes your result: the test above reports exactly what it finds, and no product placement can alter a verdict.
TEST T-07 · checks Have I Been Pwned · email not stored

Checked server-side against Have I Been Pwned and discarded — we don't store your address, and there's no account.

What a breach check tells you

When a company's systems are breached, the stolen data — often including email addresses, passwords, and other details — frequently ends up published or traded. Have I Been Pwned catalogues these disclosed breaches. Checking your address tells you whether it appears in any of them, and which.

A clean result means your address isn't in the breaches HIBP has indexed. It's reassuring, but not a guarantee: breaches surface later, and this only covers what's publicly disclosed.

How your email is handled

The lookup happens on our server so your address never goes to HIBP from your browser directly. It's used for this one query and discarded — we don't store it, log it, or attach it to any profile. There's no account and no history.

What to do if you're in a breach

  • Change the password on the breached service, and anywhere you reused it.
  • Turn on two-factor authentication so a stolen password alone isn't enough.
  • Use a password manager to give every account a unique password, so one breach stays contained.

Common questions

Do you keep my email address?

No. It's used only for the single lookup and immediately discarded. There's no account, no history, and nothing stored on our side.

My email wasn't found — am I safe?

It means your address isn't in the breaches HIBP has indexed today. New breaches are disclosed regularly, so treat a clean result as a snapshot, not a permanent all-clear.

The check said it's unavailable — why?

The breach lookup needs an API key this deployment hasn't set, or the service was temporarily unreachable. We report that rather than show a made-up result.

Related checks

Breaches are one exposure. These cover your live connection: