How to Check If Your Email Was in a Data Breach

Checking takes a minute. Interpreting the result correctly is the part people get wrong.


Enter your address into a reputable breach-notification service and it will list the known breaches containing it, with dates. Checking takes a minute; interpreting it is where people go wrong. A hit does not mean your account was accessed, and no result does not mean you're clean — it means no known, catalogued breach contains your address. Either way, the action is the same: unique passwords everywhere, and stop giving the same address to every service.

How these services work

Breach-notification services collect datasets that have appeared publicly after a breach, index the addresses in them, and let you query whether yours appears. The reputable ones tell you which breach, roughly when, and what categories of data were included — addresses only, addresses plus hashed passwords, addresses plus full profiles, and so on.

That last detail is the one worth reading. "Email addresses and password hashes" is a very different situation from "email addresses only", and the difference determines what you should do next.

Reading the result correctly

ResultWhat it meansWhat it doesn't mean
Several hitsYour address is in circulation and will keep attracting spamThat any account was accessed, or that you did anything wrong
A hit including passwordsChange that password, and anywhere you reused itThat the password was necessarily cracked — but assume it was
No hitsNo catalogued public breach contains itThat your address hasn't leaked. Sales and sharing aren't breaches, and not every breach becomes public
A very old hitDates roughly when the address entered circulationThat it's stale. Leaked data stays in use for years

That third row is the one people misread. A clean result is genuinely good news about breaches specifically, and says nothing about the largest source of exposure — companies lawfully sharing or selling addresses they were given. As the FTC puts it, when you give a company your address "it might share or sell it to third parties." No breach service will ever show you that. Source: FTC. Checked: 2026-08-19.

Is paid "dark web monitoring" worth it?

Usually not, on its own

Paid monitoring products typically do what a free breach service does, plus alerting when your address appears in something new. That alerting has some value — knowing early is better than knowing late.

What they can't do is remove anything. Once a dataset circulates it cannot be recalled, by any service at any price. A monitoring product that implies otherwise is overselling. And the correct response to an alert is nearly always the same thing you should have done anyway: change the password, and make sure it wasn't reused.

If monitoring is bundled with something you already want — a password manager, for instance — it's a reasonable inclusion. As a standalone subscription, it's paying for notification of a problem you can't fix reactively.

What to do about a hit

  1. Change the password for that service, and anywhere you reused it. This is the step that actually reduces risk; everything else is housekeeping.
  2. Turn on two-factor authentication where the account matters.
  3. Expect spam at that address, indefinitely. That's the consequence you can't reverse.
  4. Don't change your address in a panic. It's a large migration that doesn't fix the structural issue — see how to stop spam after a data breach.
  5. Change what happens next. If that company had an address nothing else used, the breach would have been contained to one relationship. That's the setup.

How often to check

Once, properly, and then let a free alerting service tell you about new appearances. Repeated manual checking doesn't achieve anything — the meaningful action after any hit is the same, and you can take it now regardless of what any specific check says.

The honest framing: checking is diagnostic, not remedial. It tells you where you stand. What changes your position is unique passwords and per-service addresses, and neither of those requires you to wait for a breach notification first.

More: the complete guide to email privacy · how to find out who leaked your email

Part of the Email Privacy guides.

The full picture: The Complete Guide to Email Privacy

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started — free

Keep reading