Six checks, about two hours, no cost โ and afterwards you stop guessing. Search results, breach records, people-search listings, WHOIS, public code repositories, and your own list of accounts. Most people find their exposure is different from what they assumed: usually fewer published records than feared, and far more accounts than expected.
1. Search for your address
Put your address in quotes and search it. Repeat on a second search engine โ different indexes surface different pages. Note every page that appears.
Anything here has been scraped, because harvesters read the same public pages crawlers do. Getting it removed reduces future collection, not past. The removal order that works
2. Check breach records
Run your address through a breach-notification service. Note which breaches, when, and โ most importantly โ what categories of data each exposed. "Email addresses only" is a very different situation from "email addresses and password hashes".
Any breach that included passwords means rotating that password and anywhere you reused it. That's the one item on this whole audit with immediate security consequence. Reading the result correctly
3. Search your name on people-search sites
Search your full name in quotes with your city. Open the people-search results and record which sites list you and what they show โ address, age, relatives, phone.
This is a separate problem from email and often a more consequential one. Write the list down with the date; it's your baseline for any removal work. What these sites are
4. Check WHOIS on any domain you own
Run a WHOIS lookup. If your name, postal address or phone number appears, privacy protection is off โ turn it on today. Registrant records are a standard harvesting source. How
5. Check your public code repositories
If you write code, your commit metadata contains an email address and it's indexed. Check what address your commits carry. Technical recruiters and harvesters both mine this systematically, and most people have no idea it's there.
6. List the accounts using your address
Password manager, a search of your own mail archive for signup phrases, breach records, and your sign-in-with providers. This is the longest step and the most surprising โ most people guess forty accounts and find two hundred. The four methods
What to do with the results
| What you found | Action | Priority |
|---|---|---|
| A breach that included passwords | Rotate that password and every reuse | Today |
| Address published on a public page | Remove at source, then ask the index to refresh | This week |
| WHOIS exposing your details | Enable privacy protection | This week |
| People-search listings | DROP if eligible, else opt out manually | This month |
| Accounts you'd forgotten | Close the ones you're finished with | This month |
| Everything on one address | Start per-service addresses from today | Ongoing |
How often to repeat it
Once properly, then let free breach alerting handle the monitoring. Re-run the people-search check every few months if you found listings, because removal doesn't stay done. Why
Repeating the whole audit frequently achieves little โ the actions it produces are the same ones you can take now regardless of what any specific check says.
More: the checklist ยท the complete guide