Dark web exposure check.

See whether your email address, your shared mailboxes or your company appear in known data breaches.

Enter an email address to see whether it appears in known data breaches, or your domain to check your company and its shared mailboxes.

Why it matters

Breached data gets reused

When a company you hold an account with is breached, your address and often your password end up in lists that are traded and tried against other services automatically. Your email account is the first target.

Shared mailboxes are the weak spot

info@ and accounts@ are signed up to the most supplier portals, shared between the most people and protected the least. They are where reused passwords live.

Knowing changes what you do today

If an address is out there, the fix is a password change and two-factor authentication now, not after someone has been into the mailbox.

Common questions

Before you run it, or after you have.

Where does this information come from?

Two public sources: the Have I Been Pwned breach catalogue, which lists companies whose data has been breached, and the XposedOrNot index, which lists addresses that appeared in those breaches. Both are free and public; we hold no dark web access and buy no data.

Do you see my password?

No. We never look a password up and the sources we use do not return them. The report tells you whether passwords were part of what was exposed, not what they were.

The address came back clean. Am I safe?

Clean means not in the public indexes. Plenty of stolen data is traded privately and never indexed, so a clean result lowers the odds rather than removing them. Two-factor authentication is still worth having.

Why does the domain check only cover shared mailboxes?

Checking every staff address at a domain is only possible through a paid, ownership-verified service. The free public indexes let us check the company itself and the common shared addresses. Individual addresses can be checked one at a time above.

Is it safe to look up an address that isn’t mine?

The lookups are public and read-only, but please only check addresses and domains you are responsible for. We do not store what you enter.