Enter your address into a reputable breach-notification service and it will list the known breaches containing it, with dates. Checking takes a minute; interpreting it is where people go wrong. A hit does not mean your account was accessed, and no result does not mean you're clean — it means no known, catalogued breach contains your address. Either way, the action is the same: unique passwords everywhere, and stop giving the same address to every service.
How these services work
Breach-notification services collect datasets that have appeared publicly after a breach, index the addresses in them, and let you query whether yours appears. The reputable ones tell you which breach, roughly when, and what categories of data were included — addresses only, addresses plus hashed passwords, addresses plus full profiles, and so on.
That last detail is the one worth reading. "Email addresses and password hashes" is a very different situation from "email addresses only", and the difference determines what you should do next.
Reading the result correctly
| Result | What it means | What it doesn't mean |
|---|---|---|
| Several hits | Your address is in circulation and will keep attracting spam | That any account was accessed, or that you did anything wrong |
| A hit including passwords | Change that password, and anywhere you reused it | That the password was necessarily cracked — but assume it was |
| No hits | No catalogued public breach contains it | That your address hasn't leaked. Sales and sharing aren't breaches, and not every breach becomes public |
| A very old hit | Dates roughly when the address entered circulation | That it's stale. Leaked data stays in use for years |
That third row is the one people misread. A clean result is genuinely good news about breaches specifically, and says nothing about the largest source of exposure — companies lawfully sharing or selling addresses they were given. As the FTC puts it, when you give a company your address "it might share or sell it to third parties." No breach service will ever show you that. Source: FTC. Checked: 2026-08-19.
Is paid "dark web monitoring" worth it?
Paid monitoring products typically do what a free breach service does, plus alerting when your address appears in something new. That alerting has some value — knowing early is better than knowing late.
What they can't do is remove anything. Once a dataset circulates it cannot be recalled, by any service at any price. A monitoring product that implies otherwise is overselling. And the correct response to an alert is nearly always the same thing you should have done anyway: change the password, and make sure it wasn't reused.
If monitoring is bundled with something you already want — a password manager, for instance — it's a reasonable inclusion. As a standalone subscription, it's paying for notification of a problem you can't fix reactively.
What to do about a hit
- Change the password for that service, and anywhere you reused it. This is the step that actually reduces risk; everything else is housekeeping.
- Turn on two-factor authentication where the account matters.
- Expect spam at that address, indefinitely. That's the consequence you can't reverse.
- Don't change your address in a panic. It's a large migration that doesn't fix the structural issue — see how to stop spam after a data breach.
- Change what happens next. If that company had an address nothing else used, the breach would have been contained to one relationship. That's the setup.
How often to check
Once, properly, and then let a free alerting service tell you about new appearances. Repeated manual checking doesn't achieve anything — the meaningful action after any hit is the same, and you can take it now regardless of what any specific check says.
The honest framing: checking is diagnostic, not remedial. It tells you where you stand. What changes your position is unique passwords and per-service addresses, and neither of those requires you to wait for a breach notification first.
More: the complete guide to email privacy · how to find out who leaked your email