Check your email against the breach list
Six conversations say put your email into a breach-checking site and see what has leaked. Then change every password you reused, and add the second step.
Built from seventeen conversations about finding out what of yours is already online, 359 accounts, 2012 to 2026. From the six conversations that name the same breach-checking service, the four that say search your own name, the three that say set an alert, the three that say a unique password per site is the whole defence, and the three-to-three exchange across conversations on whether the checker is safe.
An email has arrived saying your details may have been involved in a security incident at a company you barely remember signing up to, and it reads like a form letter, and you cannot tell whether it is one — and if you are honest, the password you used there is the password you use for everything. The people in these conversations — seventeen of them, 359 accounts, 2012 to 2026 — are the source here.
Put your email address into a breach-checking site tonight, and see which of your passwords are already public.
The check takes a minute
Six separate conversations say the same first thing: a breach-checking service will tell you which known leaks your email address appears in, and often which password went with it. The site all six name is a free one run by a security researcher; this page does not name it, because the accounts also argue, three to three across conversations, about the safety of typing an address into any such site, and the fork above carries that argument with its decider — an established service everyone can name is one thing, an unknown one another. One account adds the paste sites where dumps are posted as a second place to search, and one caution says that searching your own username can bring up the dumps themselves, passwords and all, which is exactly what you are checking for. Two conversations add the check your mail provider already gives you: the account’s recent-activity page, listing where and when it was opened, which one account says shows a sign-in from a place you were not.
What the answer is for
Three separate conversations say the leak is not the danger; the reuse is. A leaked address-and-password pair is tried against every other site, and the accounts whose one password opened everything are in these conversations. So the answer to the check is an order of work, which the second question below carries in full: the email account first, because one account says whoever holds your mail can reset the rest; then every account that shared the leaked password, each given its own; then the second step of verification on the email account, which four single accounts call the defence a stolen password cannot pass. The national cyber-security centre’s tips, read for this page, say the same three things — the email account is the route to identity theft, a password manager helps you keep the passwords apart, two-step verification is recommended — and one correction in these conversations says a text telling you someone has signed in is not two-step verification, because the second step has to be required to get in.
Your name, and the name you use
Four separate conversations say search your own name and usernames from time to time, because it shows you what a stranger digging would find and where your writing has been copied — ten accounts in one note found their content on other sites. Three conversations say set a standing alert so new mentions reach you, and one account caught a false review within two days that way. The third question below carries the half of these conversations that says when this does not work: for a common name, or a footballer’s or a politician’s, one exchange across conversations runs two accounts to three against it, seven accounts in one caution call the alerts useless, and the repair the accounts give is to narrow the alert with your town or your trade. Three corrections explain what an alert does and does not do — new pages only, not searches, not history — and this page carries them as the accounts’.
Two lives, two names
Two separate conversations say a username should not hint at who you are, two say different usernames on different sites stop a stranger joining your accounts into one person, and two say an encrypted password manager is what makes that many identities possible. The fourth question below carries the rest of the accounts’ method — separate email addresses or aliases, closing the old profiles you have forgotten, not posting the room or the pet or the document that places you — and the correction that a private setting is not a hiding place. It also carries the account who says that much of what a search finds comes from data-broker sites rather than from anything you posted, and that opting out of them is the work that actually shrinks the trail.
Who this page is not for
If your name is common, or you share it with someone famous, the alert half of this page is not for you — one exchange across conversations and seven accounts in one caution say so — and the breach check still is, because it works on an address, not a name. If what worries you is a partner reading your email, the accounts’ counsel on that is about the relationship rather than the password, and this page does not carry it; this page is about strangers and leaks. If you have already been exposed and someone is using it against you, legal recourse is a gap in these conversations, and the police and the platform are the places, not this page. And if you are hoping for anonymity against a state or a determined investigator, two cautions say plainly that none of this is that: it raises the price of a casual search by an employer, a peer or a stranger with a grudge, which is what the accounts were guarding against.
The community disagrees on this one
Is it safe to type your email address into a site that checks for breaches? One exchange that crosses conversations runs three accounts to three, and the accounts call it context-dependent: the site decides. This page names no site and prints both sides.
Use the known checker — it is a tool
Three accounts in the crossing exchange say the widely known breach-checking service is a genuine and useful tool that shows which of your addresses and passwords appear in leaked datasets; six separate conversations name that one service; one account uses paste sites as a second check.
3 independent accounts
Never hand your address to a site you cannot vouch for
Three accounts in the same exchange say submitting your email or username to a checker can feed a marketing list or a phishing page dressed as a tool, and that lesser-known sites carry that risk; one caution says searching yourself can surface the dumps themselves.
3 independent accounts
The number on each side is the crossing exchange, three accounts to three. What both sides name as the decider is the site’s standing: an established, widely known service is treated as safe by the accounts, an unknown one is not. This page adds one line of its own: type an address into a checker, never a password.
Common questions
Is it safe to type my email address into one of these sites?
The accounts argue this across conversations, three accounts to three, and the fork above renders it. The three for say the well-known breach-checking service is a genuine tool that tells you which of your addresses and passwords appear in known leaks; the three against say handing your address to a site is itself a risk — a lesser-known one may harvest addresses for marketers or be a phishing page dressed as a checker. The accounts’ own decider is the site, not the idea: an established service everyone in these conversations can name is treated as safe, and an unknown one is not. This page names none and takes that decider as its own: use the one your own searching and asking turns up as widely used, type nothing but the email address, and never a password into a page that asks for one. One account searches paste sites for their address as a second check, and one caution says searching your own username can turn up the dumps themselves, passwords included — which is the answer, not a reason to stop. Two conversations add a check that costs nothing: your mail account’s own recent-activity page, which lists the places and times it was opened; one account says a sign-in from a place you were not is your answer, and two cautions say it is less use if the suspected person shares your home connection, or if a network tool hides where they were.
It says my password leaked. What exactly do I change?
The order the accounts give, one item at a time. First the email account, because one account says the mail account is the master key — every other service sends its password reset there — and one says a changed password is the one immediate action that stops whoever is inside. Then every account where you used the leaked password, because three separate conversations say the danger after a breach is not the breach but the reuse: the leaked pair is tried against every other site, and a unique password per site is what makes the leak end where it started; the national cyber-security centre’s tips say a password manager helps you create and remember them, and two conversations say an encrypted manager is what makes several identities with strong separate passwords possible at all. One exchange of one account to one argues whether a manager is a risk of its own if the device is taken, against memorised rules; one caution says the manager’s master password becomes the single door, and two say copying and pasting passwords on some phones exposes them to other apps. Then the second step: four single accounts say two-step verification is the defence that a stolen password cannot get past, and the centre recommends it; one correction says a text message telling you someone signed in is not two-step verification — the second step has to be required to finish the login — and one caution says a code by app beats a code by text. One contraindication says do not tie the second step to a phone alone without printing the backup codes, and two cautions say a phone as the only key is a single point of failure; two accounts print the codes and keep them somewhere safe, and one objection says the codes are for emergencies, not for every login. Two single accounts say the security questions are the weak door — the answers are on your own profile — and give false or random answers stored in the manager. How to recover an account that is already taken is a gap in these conversations; the provider’s recovery page is the place, and the sooner the better.
Should I set an alert on my own name?
Four separate conversations say search your own full name and usernames now and then, because it shows you where your writing has been copied, what someone digging would find, and pages about you that you did not know existed; three conversations say set a standing alert with a search engine so that new mentions reach you as they appear, and one account caught a false review of their business within two days that way and had it taken down. Then the accounts say when it does not work. One exchange that crosses conversations runs two accounts to three: the two say alerts and searches catch problems early; the three say that for a common name they are useless, because the results are other people — seven accounts in one caution say the same, and single accounts who share a name with a footballer, a politician or a crime victim describe a stream of notifications about strangers. Two objections offer the repair: add your town, your trade or your employer to the alert so it narrows, and one account says alerts for your email address and for common misspellings of your name catch things a name alone does not. Three corrections say how the alert behaves: it fires on new pages containing your term, not when someone searches for you; it does not go back through old pages, so search by hand first; and one search-related notification feature the accounts relied on was discontinued in 2024. Two cautions say alerts are slow and miss things, and one account says theirs missed a news appearance and an obituary. One account says the searching turned up old, embarrassing writing they had forgotten; one account learned of a sibling’s death from an alert, and this page carries that as the weight the tool can have. One exchange of one account to one argues whether knowing is worth it at all — the one says early knowledge saved a career, the other says for the rest of us the knowledge brings stress and no remedy, because reputation firms cost money and months. What to do once you find something — a takedown, a legal route — is a gap in these conversations, and this page has no law for it.
Do I really need a different username everywhere?
The accounts who have been found say yes, and the page carries their reasoning. Two separate conversations say the username should not hint at your real name or details, two say different usernames on different platforms stop someone joining your accounts into one profile, and two say an encrypted password manager is what makes that many identities possible. Single accounts add: one email address across social networks and everything else is the link that joins them — use aliases or separate addresses, and one caution says the plus-sign alias trick fails on providers that strip it and on forms that reject it; search your old usernames too, and close or lock the profiles you had forgotten; do not put up photos of things that place you — a room, a pet, a document — or the small facts that add up, which one account says is how anonymous people are found; and one account keeps the accounts for one kind of life entirely separate from the accounts for another and rotates them. One correction says a private profile is not a hiding place: platforms reset settings, address-book imports reveal you, and the indexing sites may have cached you already. On the indexing sites, one account says much of what a search turns up about a person comes from data brokers rather than from anything the person posted, and that opting out of them — by hand, or through a removal service — is the work that actually shrinks the trail; one caution says the opting out is slow and the brokers repost. Two cautions say plainly that none of this is anonymity against a determined and well-resourced adversary, only a higher cost of finding you; the accounts’ own line is that it raises the price of a casual search by an employer, a peer or a stranger with a grudge, which is what they were guarding against. Which removal services exist now, and how to get something taken down once found, are gaps in these conversations.
Full tip: https://findangel.org/tips/check-your-email-against-the-breach-list · FindAngel.org — free, always.