Tools · Email
We first send a verification link to the address you enter; only once you confirm do we query the breach database. What goes there is a hash, not the address.
The check answers one question: has this email address turned up in data that got out of breached services? The result is a list of breaches and their dates — not an overview of your accounts, and not information that somebody got in anywhere.
The address is sent to our server — otherwise we could not send a verification email to it. The breach database we query is LeakCheck, a British service, and only a shortened hash of the address goes to it. The details are further down and in the privacy policy.
How the check works
Anyone can type somebody else's address into the form. That is why we do not ask straight away — first we verify that the person asking owns the mailbox.
The address arrives at our server. At that moment we ask nobody about it — no query to a breach database, no passing it on. We do not file the address in any record; it is used to send one message and, until the link is confirmed, it stays only in an encrypted short-lived record.
A message with a single-use link arrives in the mailbox. The link carries neither the address nor anything the address could be computed from — it is a random number. Our server holds the address encrypted alongside it, for as long as the link is valid, that is 60 minutes.
The link opens a page with a button — opening it triggers nothing, because links in email are also opened by scanners and previews. The query is made only when the button is pressed. What goes to the British service LeakCheck is the first 24 characters of a SHA-256 hash computed from the address, not the address itself. The hash can be verified by a party that already knows the address — so it is not anonymous data, the address simply cannot be read out of it.
LeakCheck sees our server's IP address, the time of the query and that hash. It does not see who was asking or from where. This page, on the other hand, behaves like any other on this site: the Google Analytics script loads regardless of cookie consent whenever it is enabled, so Google sees your IP either way. Our own traffic measurement starts only after consent. On the page the link from the email leads to, neither of them runs: its URL is single-use and has nowhere to go from.
Verification by email is here because of other people's addresses. A query to a breach database about somebody else is a transfer of their personal data abroad, and it creates a duty to inform that person — from the moment of the query, not from the moment a result is shown. A verification message is the only way to offer the tool publicly and not talk your way out of that. The confirmation button is then what holds the whole procedure together: without it the query would be triggered by opening the link, and links in email are also opened by machines.
More tools
One address is one sample
Leaked employee addresses are the way in for phishing and account takeover. What to do about it — a second factor, a password manager, rules for accounts and training for people — is something a security assessment can work through.