Tools · Email

IS YOUR EMAIL IN A DATA BREACH?

We first send a verification link to the address you enter; only once you confirm do we query the breach database. What goes there is a hash, not the address.

The check answers one question: has this email address turned up in data that got out of breached services? The result is a list of breaches and their dates — not an overview of your accounts, and not information that somebody got in anywhere.

The address is sent to our server — otherwise we could not send a verification email to it. The breach database we query is LeakCheck, a British service, and only a shortened hash of the address goes to it. The details are further down and in the privacy policy.

The result is incomplete by design The tool looks into one breach database. When an address is not found, that means "it is not in LeakCheck data" — not "it never leaked anywhere". Plenty of breaches are never published, plenty of others are traded and never collected anywhere, and what leaked yesterday is in no database yet. The reverse holds too: a hit does not mean somebody got into the particular service where you use the address, nor that anyone knows your password.

We will send a link to the address you enter. It opens a page with a button, and the check only starts when you press it — that is how we verify you are asking about your own mailbox, not somebody else's.

We keep no record of the address and do not write it to any log — on the server it stays only encrypted in a short-lived record attached to the link, for 60 minutes at most, and using the link deletes it. The link in the email carries neither the address nor anything the address could be computed from: it is a random number under which that record is stored. It is valid for 60 minutes and works only once. What goes to the breach database is a shortened hash of the address, not the address. More in the privacy policy.

How the check works

Why the email comes first

Anyone can type somebody else's address into the form. That is why we do not ask straight away — first we verify that the person asking owns the mailbox.

01

You enter the address

The address arrives at our server. At that moment we ask nobody about it — no query to a breach database, no passing it on. We do not file the address in any record; it is used to send one message and, until the link is confirmed, it stays only in an encrypted short-lived record.

02

A verification email arrives

A message with a single-use link arrives in the mailbox. The link carries neither the address nor anything the address could be computed from — it is a random number. Our server holds the address encrypted alongside it, for as long as the link is valid, that is 60 minutes.

03

You confirm and we ask

The link opens a page with a button — opening it triggers nothing, because links in email are also opened by scanners and previews. The query is made only when the button is pressed. What goes to the British service LeakCheck is the first 24 characters of a SHA-256 hash computed from the address, not the address itself. The hash can be verified by a party that already knows the address — so it is not anonymous data, the address simply cannot be read out of it.

04

What the other side sees

LeakCheck sees our server's IP address, the time of the query and that hash. It does not see who was asking or from where. This page, on the other hand, behaves like any other on this site: the Google Analytics script loads regardless of cookie consent whenever it is enabled, so Google sees your IP either way. Our own traffic measurement starts only after consent. On the page the link from the email leads to, neither of them runs: its URL is single-use and has nowhere to go from.

Verification by email is here because of other people's addresses. A query to a breach database about somebody else is a transfer of their personal data abroad, and it creates a duty to inform that person — from the moment of the query, not from the moment a result is shown. A verification message is the only way to offer the tool publicly and not talk your way out of that. The confirmation button is then what holds the whole procedure together: without it the query would be triggered by opening the link, and links in email are also opened by machines.

What the tool does not do

More tools

What you can check right away

Content valid as of 8 August 2026

One address is one sample

For a company it is not
about one mailbox, but
about what can be done with it.

Leaked employee addresses are the way in for phishing and account takeover. What to do about it — a second factor, a password manager, rules for accounts and training for people — is something a security assessment can work through.