Have I Been Pwned Alternatives: How to Check If Your Email Was Leaked

📄 7 min readUpdated October 7, 2026

The quickest way to check if your email was leaked is still Have I Been Pwned. It's free, and when we checked in October 2026 it covered more than 17 billion accounts from over 1,000 breached sites. The useful alternatives aren't really replacements. They're the breach reports built into your password manager or browser, which check your passwords as well as your email. Once you know what leaked, our Password Generator and Password Strength Checker help you replace it.

What does Have I Been Pwned actually tell you?

You type an email address and it lists every breach that address appears in, with the date and the kinds of data exposed, such as passwords, phone numbers or physical addresses. It doesn't show you the leaked records themselves. That's deliberate. It tells you what to fix without becoming a place to look people up.

The free notification service emails you when your address turns up in a new breach. Domain owners can search a whole company domain, which normally needs a subscription, and the email search API needs a paid key. The Pwned Passwords API is free and doesn't need a key at all.

Which Have I Been Pwned alternatives are worth using?

Here's how the main options compare. Several of them use Have I Been Pwned's data behind the scenes, so you won't necessarily find more breaches by switching. You'll find them in a more convenient place.

ServiceChecks emailsChecks passwordsCostGood for
Have I Been PwnedYesYes, Pwned PasswordsFree for individualsThe reference check, plus alerts
Mozilla MonitorYesNoFree scan and alertsOngoing alerts in a friendlier dashboard
Bitwarden reportsYour vault's logins (free)Exposed passwords report (Premium)Free, Premium for passwordsChecking everything you've saved at once
Chrome Password CheckupNoSaved passwordsFreePeople who save passwords in Chrome
Apple PasswordsNoSaved passwordsFree on Apple devicesiPhone and Mac users
1Password WatchtowerYesYesPaid subscriptionExisting 1Password users
DeHashed, Intelligence XYesShows leaked recordsMostly paidInvestigators and security teams

Google's dark web report used to be on this list. Google stopped scanning for new breaches on January 15, 2026 and switched the reports off on February 16, 2026, so if you relied on it, Have I Been Pwned's free alerts are the simplest swap.

How can you check a password without giving it away?

This is the clever part, and it's why you can trust the good breach checkers with a password. They use a method called k-anonymity. Your device turns the password into a SHA-1 hash, then sends only the first five characters of that hash. The service sends back every leaked hash starting with those five characters, and your device looks for a full match locally.

Take the password password. Its SHA-1 hash is 5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8. Only 5BAA6 goes over the network. There are 1,048,576 possible five-character prefixes, and each one matches a large batch of leaked hashes, so the server can't tell which password you were checking. You can see the hash for yourself with our Hash Generator. Just don't paste a password you actually use into any website you haven't checked.

What should you do if your email shows up in a breach?

Don't panic. Most adults with an email address older than a few years will show up somewhere. What you do next depends on what leaked alongside it.

What leakedRiskWhat to do
Email address onlySpam and phishingBe wary of emails that mention the breached service
Password (any form)Account takeover, especially if reusedChange it on that site and every site where you reused it, turn on 2FA
Phone numberScam texts, SIM-swap attemptsAdd a carrier PIN or port-out lock, avoid SMS codes where an app works
Physical address, date of birthIdentity fraud, convincing phishingWatch your credit reports, be skeptical of "verification" calls
Security question answersAccount recovery abuseChange the answers, or use random ones stored in a password manager
Social Security number, ID scansNew accounts opened in your nameFreeze your credit with Equifax, Experian and TransUnion (free in the US)
Payment cardFraudulent chargesAsk your bank for a new card number

How do you stop the next breach from hurting?

You can't stop companies getting breached. You can make sure each breach only costs you one account. That comes down to three habits.

Use a different password everywhere. Reuse is what turns a leak at a forum you forgot about into someone logging into your email. A password manager makes this painless, and our Password Generator will create one when you need it. Our guide to what makes a password strong explains why length beats clever symbols.

Turn on two-factor authentication for email, banking and anything that can reset other accounts. An authenticator app or passkey is stronger than a text message.

Set up alerts once. Subscribe your main addresses to Have I Been Pwned's notifications, or run your password manager's breach report every few months. Then you'll hear about the next breach from them, not from a stranger trying your password.

For the rest of your privacy toolkit, see our roundup of the best free privacy tools.

Frequently Asked Questions

Is Have I Been Pwned safe to use?

Yes. It's run by security researcher Troy Hunt, it's free for individuals, and its FAQ says searches aren't explicitly logged. Checking an email there doesn't add it to any list. For passwords, its Pwned Passwords service only ever receives the first 5 characters of a SHA-1 hash, never the password.

What happened to Google's dark web report?

Google shut it down. Scans for new breaches stopped on January 15, 2026, and the reports became unavailable on February 16, 2026. Google said people often found no useful next step after seeing a result. Have I Been Pwned, Mozilla Monitor and your password manager's breach report cover the same ground.

My email was in a breach. Do I need to change my email address?

Usually not. An email address on its own isn't secret, and most breaches leak it. What matters is what leaked with it. If a password leaked, change it on that site and anywhere you reused it, and turn on two-factor authentication. Expect more phishing to that address for a while.

Can I check if a password was leaked without typing it into a website?

Yes. Password managers such as 1Password, Bitwarden Premium, Chrome, Firefox and Apple Passwords check saved passwords against breach lists using the same partial-hash method Have I Been Pwned uses, so the full password is never sent. Have I Been Pwned's own Pwned Passwords page does the hashing in your browser too.

Is DeHashed or a paid breach search better than Have I Been Pwned?

They do a different job. Have I Been Pwned tells you which breaches include your email but never shows the leaked data itself. Paid search engines such as DeHashed show the actual records, which is useful for investigators and security teams. For a regular person deciding what to change, Have I Been Pwned's answer is enough.

Related Tools