Run a lookup

Guide

What can someone find out about me online

The uncomfortable part is not what you published. It is the third of it that you never did.

9 min read The DetectiveCheck team
PrivacyEmailUsernameGuide
A single lit window seen from the street

The short answer

What can be found about you falls into three kinds: what you published, what other people published about you, and what leaked without anybody deciding to publish it. You control the first, you can sometimes argue about the second, and the third is permanent. Checking means searching your own identifiers the way a stranger would.

  • Your handle gives away more than your name. People reuse one handle for a decade and several email addresses in a year.
  • The most revealing results are usually accounts you forgot you opened, on services you stopped using.
  • Breach records cannot be deleted. They are copies held by strangers, and no service can recall them.
  • Run it on yourself before you conclude anything. Most people overestimate what is public and underestimate what is old.

What can someone actually find out about you?

Three kinds of thing, and it is worth separating them before you look, because they behave completely differently.

  • What you published. Profiles, posts, a photograph you uploaded in 2014. Under your control, at least in theory, and the part everybody thinks of first.
  • What others published about you. A tagged photo, a company staff page, a race result, a court filing, a local news item. Not yours to delete, and sometimes not theirs either.
  • What leaked. Your address in a breach dump alongside a password you used in 2016. Nobody decided to publish this and nobody can unpublish it.

Most people brace for the first category and are ambushed by the third. It is the one with no undo button and the one that says the most about how long you have been online.

youyour own details inWhat you postedWhat others postedAccounts you forgotBreach recordsNothing hereyouyour own details inWhat you postedWhat others postedAccounts you forgotBreach recordsNothing here
Your own identifiers, and the three kinds of thing that come back. Only one of them is under your control.

Where do you start checking?

With the identifier you have reused the longest, which is almost never the one you would guess.

People assume their name is the exposure. It usually is not, because a name is shared by hundreds of people and no service indexes by it. The real exposure is the handle picked once, years ago, and typed into every sign-up form since. That single string ties a gaming account to a professional one across services that have nothing to do with each other.

So check in this order: the handle you have had longest, then your oldest email address, then the address you actually use now, then your name. Each one is a different question, and the first two answer most of it.

What does your email address give away?

Which services you have accounts on, and roughly how long you have been online.

Sign-up and password-reset forms have to say whether an address is already registered, so any address can be checked against a long list of services. Seventy-one sources answer for one on DetectiveCheck. What comes back is a list of platforms, sometimes a display name or an avatar, and the breach records containing the address.

The old address is the one worth checking. The address you use today is careful and boring. The one from 2009, still receiving mail, is attached to forums you have forgotten, a profile photograph you would not choose now, and a password you may still be using somewhere.

A work address is its own case. The domain is not a free provider, so it carries registration records, and the part before the at sign is usually built from your real name. That combination identifies you where a personal address would not.

Almost nothing here was published by the person it describes. That is the part people are unprepared for.

Almost nothing here was published by the person it describes. That is the part people are unprepared for.

What does your username give away?

More than anything else, and this is the part that surprises people who consider themselves careful.

A handle checked across 71 platforms comes back with the places it is taken, the display names attached, the avatars, and where a platform publishes one, the join date. Put together, that is a rough map of a decade: what you were interested in, when you started, and which communities you were part of.

The correction most people need is that a match is not proof. Handles get recycled, squatted, and picked independently by strangers, so some of what comes back under your handle is not you. That cuts both ways: a stranger looking you up will make exactly that mistake, and the account they attribute to you may not be yours.

What shows up that you never published?

Breach records, mostly, and they are the reason to do this at all.

A breach record is your address, and often a password hash, in a file that was copied out of a service that got broken into. Sixty appearances is not unusual for an address that has been in use since 2010. Each one is a service that once held a credential of yours, and the file has been copied so many times that no origin remains to appeal to.

The right response is not alarm and it is definitely not abandoning the address. It is checking whether any password in there is one you still use, and changing that everywhere you reused it. Strength stops mattering once a password is on a list, because nobody has to guess it.

Checking a password is safe to do. A well-built check never sends the password. Your browser hashes it and sends the first five characters of the hash, so the service cannot tell which of hundreds of thousands of passwords you asked about.

Can you remove what you find?

Some of it. Less than the industry selling removal implies, and the split is predictable.

What it isCan you remove itHow
An account you forgotYesLog in and delete it, or ask the service to
A profile you publishedYesDelete it, then wait for caches to expire
A data broker listingUsuallyOpt out, one broker at a time, and repeat
A tagged photo or mentionSometimesAsk the person or the platform. No right to insist
A public register or filingNoIt is a record of something that happened
A breach recordNoCopies are held by strangers. Change the password

The honest summary is that deleting accounts you no longer use is the highest-value action available to you, and it is free. Everything below that on the list is either slow, partial, or impossible, whatever a removal service charges for it.

What is a digital footprint check?

It is the same search, pointed at yourself, and the name is worth defining because several products mean different things by it.

Some tools mean a username scan and give you a list of platforms. Some mean a breach lookup. Some mean data-broker removal with a scan attached to sell it. All three are genuinely useful and none of them is the whole picture, which is a list that has been merged: the same person's accounts, breaches and public mentions in one place, with the source of each one shown.

The distinction that matters when you compare them is whether a tool shows you what it failed to check. A scan that lists only hits looks cleaner and tells you less, because you cannot tell a genuine absence from a source that timed out.

Is checking yourself different from checking someone else?

Legally, yes, and it removes the only real constraint in this whole area.

Searching public sources is lawful either way. The restrictions live in what the result is used for: in the United States, deciding somebody's employment, housing, credit, insurance or tenancy from a lookup falls under the Fair Credit Reporting Act, and a consumer service is not a consumer reporting agency. None of that applies when the subject is you.

In the EU and the UK you also gain something. The GDPR gives you a right of access and a right to erasure against organisations holding your data, and a report naming which services hold what is the practical starting point for using either.

Ethically the difference is simpler still. Nobody else's expectations are involved, so the only judgement you have to make about the result is what to do with it.

How to check yourself on DetectiveCheck

Four passes, in the order that finds the most.

  1. Your oldest handle, through the username lookup. This normally returns the most.
  2. Your oldest email address, through the email lookup, not the address you are careful with today.
  3. Any password you still reuse, through the password check. It costs nothing and never sends the password.
  4. Your name last, and expect little unless it is rare.

Read the sources that failed alongside the ones that answered. A platform that timed out is unknown rather than clear, and on your own report that distinction decides whether a gap is real.

Then act on one thing rather than reading all of it. Delete the oldest account you no longer use, or change the one reused password. A report you read and did nothing with has not made you any harder to find.

Common questions

How do I find out what information about me is online?

Search your own identifiers the way a stranger would, starting with the handle you have reused longest and your oldest email address. Check them against the platforms that confirm whether an account exists, and against breach corpora. Your name is the weakest starting point, because hundreds of people share it and no service indexes by it.

What is a digital footprint check?

A search of your own identifiers across the sources a stranger could use: accounts registered to your email address or handle, breach records containing them, and public mentions. Tools vary in what they mean by the term, from a username scan to a broker removal service. What separates them is whether they show you the sources that failed as well as the ones that answered.

Can I delete my personal information from the internet?

Partly. Accounts you no longer use can be deleted, and that is the highest-value action available to you. Data broker listings can usually be opted out of, one at a time. Public registers, court filings and news items generally cannot. Breach records never can, because copies are held by strangers with nobody to appeal to.

Why does my old email address show more than my current one?

Because it has had longer to accumulate and you were less careful with it. An address from 2009 is attached to forums you have forgotten, profiles you would not choose now, and services that were later breached. The address you use today is newer, used deliberately, and usually returns a short and unremarkable report.

Is it safe to check my own password against a breach list?

Yes, if the check is built properly. Your browser hashes the password and sends only the first five characters of that hash. The service returns every hash beginning with those five characters and the comparison happens on your machine, so it never learns which password you asked about. Never type a password into a tool that does not work this way.

Does looking myself up put me at more risk?

No. The search queries public sources and the account-existence behaviour that platforms expose to anybody who asks. It publishes nothing, it sends no mail or password reset, and it creates no new record about you anywhere. Everything it returns was already there before you looked, which is precisely the reason to look.

Why do results appear under my username that are not me?

Because a handle is not owned. The same string gets picked independently by strangers, gets recycled after an account is deleted, and gets squatted deliberately. Some of what comes back under your handle belongs to somebody else. That is worth knowing in both directions, since anyone looking you up will make the same mistake.

What should I do first after checking myself?

One thing, not everything. Either delete the oldest account you no longer use, or change a password that appeared in a breach and that you reused elsewhere. Both take minutes and both measurably reduce what is findable. Reading a full report and acting on none of it changes nothing about your exposure.

Do I have a legal right to have my data removed?

In the EU and the UK, the GDPR gives you a right of access and a right to erasure against organisations holding your personal data, though neither is absolute and both have exemptions. In the United States it depends on your state. Either way a report naming which services hold what is the practical starting point for making the request.

In short

Three kinds of thing are findable about you, and only one is yours: what you published, what others published, and what leaked. The third has no undo button, which is why the password is the thing to act on rather than the record.

Check your oldest handle first and your oldest address second. Then do one thing about it. Deleting an account you no longer use is free and permanent, and it beats reading the whole report and closing the tab.

Written by the DetectiveCheck team

We build the lookup engine this site runs on, so the numbers in these guides are the ones our own reports use: 71 sources against an email address, 71 platforms against a username, 13 registers against a name, and 8 against a phone number. Where a module is thin, we say so rather than round it up.

Run one yourself

Create an account and the first report is a couple of minutes away. Nobody you look up is told.

Create my account

Plans from $15 a month. Cancel in one click. Or read a sample report first.

Try it on something you already have