The quickest way to check if your email was leaked is still Have I Been Pwned. It's free, and when we checked in October 2026 it covered more than 17 billion accounts from over 1,000 breached sites. The useful alternatives aren't really replacements. They're the breach reports built into your password manager or browser, which check your passwords as well as your email. Once you know what leaked, our Password Generator and Password Strength Checker help you replace it.
You type an email address and it lists every breach that address appears in, with the date and the kinds of data exposed, such as passwords, phone numbers or physical addresses. It doesn't show you the leaked records themselves. That's deliberate. It tells you what to fix without becoming a place to look people up.
The free notification service emails you when your address turns up in a new breach. Domain owners can search a whole company domain, which normally needs a subscription, and the email search API needs a paid key. The Pwned Passwords API is free and doesn't need a key at all.
Here's how the main options compare. Several of them use Have I Been Pwned's data behind the scenes, so you won't necessarily find more breaches by switching. You'll find them in a more convenient place.
| Service | Checks emails | Checks passwords | Cost | Good for |
|---|---|---|---|---|
| Have I Been Pwned | Yes | Yes, Pwned Passwords | Free for individuals | The reference check, plus alerts |
| Mozilla Monitor | Yes | No | Free scan and alerts | Ongoing alerts in a friendlier dashboard |
| Bitwarden reports | Your vault's logins (free) | Exposed passwords report (Premium) | Free, Premium for passwords | Checking everything you've saved at once |
| Chrome Password Checkup | No | Saved passwords | Free | People who save passwords in Chrome |
| Apple Passwords | No | Saved passwords | Free on Apple devices | iPhone and Mac users |
| 1Password Watchtower | Yes | Yes | Paid subscription | Existing 1Password users |
| DeHashed, Intelligence X | Yes | Shows leaked records | Mostly paid | Investigators and security teams |
Google's dark web report used to be on this list. Google stopped scanning for new breaches on January 15, 2026 and switched the reports off on February 16, 2026, so if you relied on it, Have I Been Pwned's free alerts are the simplest swap.
This is the clever part, and it's why you can trust the good breach checkers with a password. They use a method called k-anonymity. Your device turns the password into a SHA-1 hash, then sends only the first five characters of that hash. The service sends back every leaked hash starting with those five characters, and your device looks for a full match locally.
Take the password password. Its SHA-1 hash is 5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8. Only 5BAA6 goes over the network. There are 1,048,576 possible five-character prefixes, and each one matches a large batch of leaked hashes, so the server can't tell which password you were checking. You can see the hash for yourself with our Hash Generator. Just don't paste a password you actually use into any website you haven't checked.
Don't panic. Most adults with an email address older than a few years will show up somewhere. What you do next depends on what leaked alongside it.
| What leaked | Risk | What to do |
|---|---|---|
| Email address only | Spam and phishing | Be wary of emails that mention the breached service |
| Password (any form) | Account takeover, especially if reused | Change it on that site and every site where you reused it, turn on 2FA |
| Phone number | Scam texts, SIM-swap attempts | Add a carrier PIN or port-out lock, avoid SMS codes where an app works |
| Physical address, date of birth | Identity fraud, convincing phishing | Watch your credit reports, be skeptical of "verification" calls |
| Security question answers | Account recovery abuse | Change the answers, or use random ones stored in a password manager |
| Social Security number, ID scans | New accounts opened in your name | Freeze your credit with Equifax, Experian and TransUnion (free in the US) |
| Payment card | Fraudulent charges | Ask your bank for a new card number |
You can't stop companies getting breached. You can make sure each breach only costs you one account. That comes down to three habits.
Use a different password everywhere. Reuse is what turns a leak at a forum you forgot about into someone logging into your email. A password manager makes this painless, and our Password Generator will create one when you need it. Our guide to what makes a password strong explains why length beats clever symbols.
Turn on two-factor authentication for email, banking and anything that can reset other accounts. An authenticator app or passkey is stronger than a text message.
Set up alerts once. Subscribe your main addresses to Have I Been Pwned's notifications, or run your password manager's breach report every few months. Then you'll hear about the next breach from them, not from a stranger trying your password.
For the rest of your privacy toolkit, see our roundup of the best free privacy tools.
Yes. It's run by security researcher Troy Hunt, it's free for individuals, and its FAQ says searches aren't explicitly logged. Checking an email there doesn't add it to any list. For passwords, its Pwned Passwords service only ever receives the first 5 characters of a SHA-1 hash, never the password.
Google shut it down. Scans for new breaches stopped on January 15, 2026, and the reports became unavailable on February 16, 2026. Google said people often found no useful next step after seeing a result. Have I Been Pwned, Mozilla Monitor and your password manager's breach report cover the same ground.
Usually not. An email address on its own isn't secret, and most breaches leak it. What matters is what leaked with it. If a password leaked, change it on that site and anywhere you reused it, and turn on two-factor authentication. Expect more phishing to that address for a while.
Yes. Password managers such as 1Password, Bitwarden Premium, Chrome, Firefox and Apple Passwords check saved passwords against breach lists using the same partial-hash method Have I Been Pwned uses, so the full password is never sent. Have I Been Pwned's own Pwned Passwords page does the hashing in your browser too.
They do a different job. Have I Been Pwned tells you which breaches include your email but never shows the leaked data itself. Paid search engines such as DeHashed show the actual records, which is useful for investigators and security teams. For a regular person deciding what to change, Have I Been Pwned's answer is enough.