How to Audit Every Account Tied to Your Email Address

Most people have three times more accounts than they'd guess. Here's how to find them.


Four sources between them surface almost everything: your password manager, a search of your own mail archive, breach-notification records, and your sign-in-with providers. Most people find three to five times more accounts than they expected. The point isn't tidiness โ€” it's knowing what depends on your address before you change anything, and closing the ones you've finished with.

Method 1 โ€” Your password manager

Start here; it's the highest-yield source and takes a minute. Export or scan the vault: every saved login is an account, and most managers record which email address you used.

Limitation: it only knows what you saved. Accounts created before you started using it, or ones where you declined to save, are missing.

Method 2 โ€” Search your own archive

Your inbox is a record of every service that has ever emailed you. Search your mail โ€” including archived and deleted folders โ€” for phrases that appear in signup and account mail:

  • "welcome to"
  • "verify your email" / "confirm your email"
  • "your account"
  • "password reset"
  • "thanks for signing up"
  • "your order" / "your receipt"
  • unsubscribe โ€” broad, but it catches every marketing sender

This is the method that surfaces the forgotten ones: the competition you entered in 2019, the wifi portal, the shop you used once.

Method 3 โ€” Breach records

A breach-notification service lists known breaches containing your address, and each one names a company you had an account with. It's an imperfect list โ€” it only covers breaches that became public โ€” but every entry is a confirmed account. How to read the results

Method 4 โ€” Sign-in-with providers

Check the third-party access lists in your Google, Apple, Microsoft and Facebook accounts. Each shows every site you've used social sign-in with โ€” accounts that often don't appear in a password manager because there was never a password.

Worth doing for a second reason: it shows what data those apps can still read, and revoking access you no longer need is quick.

What to do with the list

  1. Close what you're finished with. The most effective single step โ€” an account that doesn't exist can't be breached, sold, or acquired by someone with different marketing plans. Look for "delete account" in settings; in the EU/UK you have a right to erasure you can invoke if it's hidden.
  2. Change reused passwords. The audit will surface these, and it's the item with real security consequence.
  3. Move the important ones to their own address. Bank, government, utilities, insurance, anything financial.
  4. Leave the long tail. Don't migrate everything; let it move opportunistically as services email you.
  5. Keep the list. You'll want it if you ever do change address, and it's tedious to rebuild.
The number that surprises people

Most people guess forty or fifty accounts and find two hundred or more. That gap is the useful output of the exercise: it explains the spam volume, and it's why "just change my email address" is a much bigger project than it sounds. Whether that's worth it

Doing it once, then never again

The reason this audit is painful is that a single address gives you no record of who has it. Per-service addresses invert that: the list of your aliases is the list of your accounts, maintained automatically as a side effect of signing up.

That's a quiet benefit that only shows up later, and it's one of the better arguments for readable naming โ€” ikea@yourdomain.com is self-documenting in a way x7fq2k@ never is. Naming conventions

More: the 30-day plan ยท the checklist

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started โ€” free

Keep reading