How to check if your email address has appeared in a data breach
When a company's systems are compromised, the customer data taken often ends up circulating publicly or being sold on β email addresses, passwords, sometimes far more. Have I Been Pwned collects records from thousands of these breaches into one free, searchable database, so you can find out in seconds whether your address is among them.
What you'll need: The email address you want to check. Any web browser, on desktop or mobile.
Open Have I Been Pwned
Go to haveibeenpwned.com in your browser. No account or sign-in is needed to search.
Enter the email address
Type the address you want to check into the search box on the homepage.
Run the search
Click pwned?. The site checks the address against its database and shows a result within a few seconds.
Read the result
A clean address shows a message confirming no breaches were found. An exposed one lists every breach it turned up in, most recent first, each with its name and the date it happened.
Check what each breach exposed
Click on a listed breach to expand its details. This shows which data classes were taken β email addresses, passwords, dates of birth, physical addresses, and so on vary from breach to breach.
Change any passwords still in use
For each breach where Passwords is listed as an exposed data class, change your password on that site. If you've used the same password anywhere else, change it there too β reused passwords are what let one breach compromise several unrelated accounts.
Set up notifications for future breaches
Scroll down the homepage to Notify me, enter your email address, and confirm it through the link the site sends you. Any future breach involving that address will trigger an email alert automatically, without you needing to check back.
Variations
Have I Been Pwned's separate Pwned Passwords tool checks whether a specific password has appeared in a breach, rather than checking an address. It works by sending a partial hash of the password rather than the password itself, so the full password never leaves your device. Useful for testing a password you're thinking of reusing, before you commit to it.
Google Password Manager includes a Password Checkup that flags saved passwords found in known breaches, alongside weak or reused ones. On a Mac or iPhone, the Passwords app has a Security Recommendations section that does the same for anything saved in Apple's password manager. Neither replaces a manual check β they only cover passwords you've actually saved in that manager.
Worth doing even for an old, retired email address β it's still checked for phishing attempts if listed as a recovery address elsewhere, and knowing whether it was exposed tells you whether accounts tied to it are worth double-checking too.
Troubleshooting
It means your address isn't in any breach currently in the database, not that it's never been exposed. New breaches are added on an ongoing basis, and some incidents never become public or take a long time to surface. Worth checking again periodically rather than treating a clean result as permanent.
Check your spam or junk folder. If it's still not there, wait a few minutes and try subscribing again β the confirmation link only works once and expires after a period of time.
Each address needs searching individually β there's no bulk-check option for a personal collection of unrelated addresses. Domain-wide search is available, but only to someone who can verify ownership of that domain, which is aimed at businesses checking their own company addresses rather than individuals.
Need a calculator rather than a guide? Try Simplicalcs β