Breached data gets reused
When a company you hold an account with is breached, your address and often your password end up in lists that are traded and tried against other services automatically. Your email account is the first target.
See whether your email address, your shared mailboxes or your company appear in known data breaches.
Why it matters
When a company you hold an account with is breached, your address and often your password end up in lists that are traded and tried against other services automatically. Your email account is the first target.
info@ and accounts@ are signed up to the most supplier portals, shared between the most people and protected the least. They are where reused passwords live.
If an address is out there, the fix is a password change and two-factor authentication now, not after someone has been into the mailbox.
Common questions
Two public sources: the Have I Been Pwned breach catalogue, which lists companies whose data has been breached, and the XposedOrNot index, which lists addresses that appeared in those breaches. Both are free and public; we hold no dark web access and buy no data.
No. We never look a password up and the sources we use do not return them. The report tells you whether passwords were part of what was exposed, not what they were.
Clean means not in the public indexes. Plenty of stolen data is traded privately and never indexed, so a clean result lowers the odds rather than removing them. Two-factor authentication is still worth having.
Checking every staff address at a domain is only possible through a paid, ownership-verified service. The free public indexes let us check the company itself and the common shared addresses. Individual addresses can be checked one at a time above.
The lookups are public and read-only, but please only check addresses and domains you are responsible for. We do not store what you enter.