Run a lookup

Guide

Has my email been leaked?

You can find out which published breaches hold your address in about a second. Almost everything people read into that answer is wrong.

7 min read The DetectiveCheck team
GuideEmailSecurity
Identical crates stacked in a dark warehouse

The short answer

A breach check tells you which published breaches contain your address and what each of them exposed. It does not tell you a password is out, because the breach index never loaded one, and a clean result only means nothing public has surfaced yet.

  • Have I Been Pwned's breach index stores the address and the breach list, with no passwords attached to it. Its password corpus is a separate service.
  • Every breach exposed different fields. Some are an address in a marketing list and nothing more.
  • Checkers disagree because they ingested overlapping slices of the same recycled corpus.
  • A clean result is not evidence of safety. Most breaches are never published and some are never detected.

What does a breach check actually tell you?

Which published breaches contain the address, and what each of those breaches exposed.

The index behind almost all of these tools stores the address and the breaches it appeared in, and since 2025 the sites an address shows up against in stealer logs. Each breach carries a description of the fields it gave up, and those differ enormously.

So the useful reading is per breach rather than per hit. One entry may be an address sitting in a marketing list. Another may pair the address with a password hash, a name, a date of birth and a physical address.

Five of the seventy-one sources an address reaches here are breach corpora, and they returned in one to five seconds. Four answer this question. The fifth returns malware-harvested credentials, which is a different question with a different repair.

4breach dumpsWhich breachesWhat was exposedYour password1stealer logsSite, email, passwordSession cookiesWhose machine4breach dumpsWhich breachesWhat was exposedYour password1stealer logsSite, email, passwordSession cookiesWhose machine
Four sources answer which breaches hold an address. A fifth answers a different question entirely.

Does a hit mean my password is out?

Not by itself, and the service telling you about the hit cannot know.

Have I Been Pwned states it plainly: when addresses from a breach are loaded, no corresponding passwords are loaded with them. The address index and the password corpus are two separate systems that happen to live on one site.

Whether a breach exposed passwords is a property of that breach and sits among its listed fields. Whether anybody knows your password is a different check entirely, and it runs without sending the password anywhere.

The practical consequence is narrow. If a breach that holds you exposed credentials, change that password and change it anywhere you reused it. If it exposed a mailing list, there is nothing to rotate.

Why five checkers give five answers

Because they are reading overlapping copies of the same pile.

People trade, merge and republish these corpora constantly. A 2.7-billion-row set circulating alongside the sixteen-billion headline distilled down to 109 million unique addresses, and 96% of them were already indexed. About 4.4 million were new, and its author declined to extrapolate to the headline figure.

So a count of four on one service and eleven on another is not one of them lying. It is two different ingestion dates against two different slices of a recycled corpus, and the overlap between them is most of both.

Which is the argument for reading the breach names rather than the number. The names are checkable. The total is an artefact of whose copy you happened to query.

Most of what circulates as a new leak is an old leak counted again, which is why two checkers rarely agree.

Most of what circulates as a new leak is an old leak counted again, which is why two checkers rarely agree.

What does a clean result prove?

Less than the green tick suggests, and the operator says so.

The same FAQ puts it in one line: absence of evidence is not evidence of absence. The index holds a subset of what has been breached over the years, many breaches never result in a public release, and some are never detected at all.

Of the pages ranking for this query in July 2026, none quoted that sentence, which is striking: every one of them shows a clear result and none says what clear actually means.

Treat it as a floor rather than as a verdict. Nothing public has surfaced under this address yet, which is worth knowing and is not the same thing at all as being untouched.

Which breaches are kept out of the search?

Several categories, each for a stated reason.

Breaches marked sensitive, typically adult services, never appear in a public search: you see them only after proving control of the address. Unverified ones carry a warning, because nobody could establish legitimacy beyond doubt.

Spam lists carry their own flag again, because somebody aggregated them from many sources rather than taking them from any single breached system. Two entries have gone entirely, retired because the data stopped circulating elsewhere.

All of which means the public answer is deliberately narrower than the index behind it. Reading a result without knowing that is how somebody concludes an address is clean when the service is declining to say, which is a different answer wearing the same green tick.

Is a monitoring subscription worth paying for?

Rarely, and the free checkers attached to one are how it gets sold.

What a monitoring service adds is a notification when a new breach lands, which the free index already offers by email at no cost. The paid tiers wrap that in insurance, credit-file alerts and a removal service, and those are separate products with separate value.

The part worth paying attention to is that none of it prevents anything. A breach happens on somebody else's server, and the only lever on your side of the line is not reusing the credential that leaks.

Which is the honest ranking of effort. A password manager and two-factor authentication cost nothing and remove most of the exposure; a subscription tells you faster about something you can already be told about.

What should you do first?

Sort the hits by what each breach actually exposed, then act on the credential ones.

Change the password for any breached service that held one, and change it everywhere you reused it, because credential stuffing is the automated replay of known pairs against other sites. Reuse is the whole attack.

Then turn on two-factor authentication where the account matters, and expect targeted phishing for a while: an attacker holding your address and the name of a service you used has enough for a convincing message.

None of that costs anything, and none of it needs a monitoring subscription, which is what most of the free checkers are attached to. The order is what matters: rotate the reused credentials first, because that is the one an attacker can replay tonight.

Common questions

How do I check if my email has been leaked?

Search the address against the public breach indexes. What comes back is the list of published breaches containing it and a description of what each one exposed. Reading those descriptions matters more than the count, because one breach may have taken credentials and another only an address on a mailing list.

Does a data breach mean my password was stolen?

Not necessarily, and the checker cannot tell you. Have I Been Pwned states that no passwords are loaded alongside the addresses, so a hit describes the breach rather than your credentials. That breach either exposed passwords or did not, and its field list says which; whether anybody knows yours is a separate check.

Why do different breach checkers show different numbers?

Because they ingested overlapping copies of the same recycled data at different times. A 2.7-billion-row set circulating alongside the sixteen-billion headline distilled to 109 million unique addresses, 96% of them already indexed elsewhere. A different total is corpus overlap rather than one service knowing something the other does not.

Is my email safe if the check comes back clean?

It means nothing public has surfaced under it yet. The operator of the largest index says outright that absence of evidence is not evidence of absence: it holds a subset of what has been breached, many breaches are never published, and some are never detected. Treat a clean result as a floor, not a verdict.

What should I do if my email is in a data breach?

Sort the hits by what each breach exposed. Change the password for any breached service that held one, and change it anywhere you reused it, because credential stuffing replays known pairs against other sites. Turn on two-factor authentication where the account matters, and expect targeted phishing for a while.

Should I change my email address after a breach?

Almost never. The address is not a secret and changing it means re-registering everything while old accounts stay pointed at the old one. The credential is the thing worth rotating. An exception is an address that has become unusable through spam volume, which is a deliverability problem rather than a security one.

Are breach checkers safe to use?

The reputable ones search an index of addresses and return which breaches contain yours; they do not need or receive your password. The thing to check is what the site does after answering. Most pages ranking for this query are free checkers attached to a monitoring subscription, which is a sales model rather than a risk.

Why can't I see every breach my address is in?

The index withholds several categories deliberately. Breaches marked sensitive never appear in a public search and surface only after you prove control of the address. Unverified ones carry a warning, because nobody could establish legitimacy. Spam lists carry their own flag, since somebody aggregated them rather than taking them from a breached system.

Can I stop my address turning up in future breaches?

Not directly, because the exposure happens on somebody else's server. What you can control is the blast radius: a distinct password per service means one breach stays one breach, and a separate address for sign-ups you do not care about keeps the important one out of the low-value lists that get traded most.

In short

A breach check answers one question: which published breaches contain this address, and what each exposed. It holds no passwords, so it cannot tell you a credential is out, and the field list per breach is the part worth reading.

Two checkers disagreeing is corpus overlap, not a contradiction, and a clean result is a floor rather than a verdict. The free actions — rotate reused passwords, turn on two-factor — are the ones that matter.

Written by the DetectiveCheck team

We build the lookup engine this site runs on, so the numbers in these guides are the ones our own reports use: 71 sources against an email address, 71 platforms against a username, 13 registers against a name, and 8 against a phone number. Where a module is thin, we say so rather than round it up.

Run one yourself

Create an account and the first report is a couple of minutes away. Nobody you look up is told.

Create my account

Plans from $15 a month. Cancel in one click. Or read a sample report first.

Try it on something you already have