Has your data been leaked?
Everything is checked from your device: our server never sees your address or your password.
When you click, your address goes straight from your device to XposedOrNot, which says it does not keep it. It never goes through our server.
How it works
- You type your address and click “Check”.
- Your device asks XposedOrNot, a free service that lists known breaches; the answer comes straight back to your device.
- You see each breach, what leaked, and what to do.
Good habits
A good password is long — three or four random words — and different for every site. A password manager remembers them for you.
- Use a password manager: a long, different password for every site, without the effort.
- Turn on two-factor authentication wherever you can, starting with your email.
- Be wary of emails that mention one of these sites or rush you to act: it is the most common scam after a breach.
Your password never leaves this device: its fingerprint is calculated here, only its first 5 characters (out of 40) are sent to Have I Been Pwned, and the rest is looked up here.
Checked with Pwned Passwords, by Have I Been Pwned.
Good habits
A good password is long — three or four random words — and different for every site. A password manager remembers them for you.
- Turn on two-factor authentication wherever you can, starting with your email.
- Be wary of emails that mention one of these sites or rush you to act: it is the most common scam after a breach.
Have I Been Pwned's public catalogue of breaches. Your device downloads it when you open this tab.
To get an email when your address appears in a NEW breach, two free services can do it for you. They first write to you to check that the address really is yours.
These are their services: you give them your address directly, without going through us.
Good habits
- Use a password manager: a long, different password for every site, without the effort.
- Turn on two-factor authentication wherever you can, starting with your email.
- Be wary of emails that mention one of these sites or rush you to act: it is the most common scam after a breach.