How to Audit Your Email Exposure in an Afternoon

Two hours, no cost, and you stop guessing about where you actually stand.


Six checks, about two hours, no cost โ€” and afterwards you stop guessing. Search results, breach records, people-search listings, WHOIS, public code repositories, and your own list of accounts. Most people find their exposure is different from what they assumed: usually fewer published records than feared, and far more accounts than expected.

1. Search for your address

Put your address in quotes and search it. Repeat on a second search engine โ€” different indexes surface different pages. Note every page that appears.

Anything here has been scraped, because harvesters read the same public pages crawlers do. Getting it removed reduces future collection, not past. The removal order that works

2. Check breach records

Run your address through a breach-notification service. Note which breaches, when, and โ€” most importantly โ€” what categories of data each exposed. "Email addresses only" is a very different situation from "email addresses and password hashes".

Any breach that included passwords means rotating that password and anywhere you reused it. That's the one item on this whole audit with immediate security consequence. Reading the result correctly

3. Search your name on people-search sites

Search your full name in quotes with your city. Open the people-search results and record which sites list you and what they show โ€” address, age, relatives, phone.

This is a separate problem from email and often a more consequential one. Write the list down with the date; it's your baseline for any removal work. What these sites are

4. Check WHOIS on any domain you own

Run a WHOIS lookup. If your name, postal address or phone number appears, privacy protection is off โ€” turn it on today. Registrant records are a standard harvesting source. How

5. Check your public code repositories

If you write code, your commit metadata contains an email address and it's indexed. Check what address your commits carry. Technical recruiters and harvesters both mine this systematically, and most people have no idea it's there.

6. List the accounts using your address

Password manager, a search of your own mail archive for signup phrases, breach records, and your sign-in-with providers. This is the longest step and the most surprising โ€” most people guess forty accounts and find two hundred. The four methods

What to do with the results

What you foundActionPriority
A breach that included passwordsRotate that password and every reuseToday
Address published on a public pageRemove at source, then ask the index to refreshThis week
WHOIS exposing your detailsEnable privacy protectionThis week
People-search listingsDROP if eligible, else opt out manuallyThis month
Accounts you'd forgottenClose the ones you're finished withThis month
Everything on one addressStart per-service addresses from todayOngoing

How often to repeat it

Once properly, then let free breach alerting handle the monitoring. Re-run the people-search check every few months if you found listings, because removal doesn't stay done. Why

Repeating the whole audit frequently achieves little โ€” the actions it produces are the same ones you can take now regardless of what any specific check says.

More: the checklist ยท the complete guide

Part of the Email Privacy guides.

The full picture: The Complete Guide to Email Privacy

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started โ€” free

Keep reading