Check your email against the breach list
Many conversations say put your email into a breach-checking site and see what has leaked. Then change every password you reused, and add the second step.
Built from seventeen conversations about finding out what of yours is already online, 359 accounts, 2012 to 2026. From the six conversations that name the same breach-checking service, the four that say search your own name, the three that say set an alert, the three that say a unique password per site is the whole defence, and the three-to-three exchange across conversations on whether the checker is safe.
An email has arrived saying your details may have been involved in a security incident at a company you barely remember signing up to, and it reads like a form letter, and you cannot tell whether it is one — and if you are honest, the password you used there is the password you use for everything. The people in these conversations are the source here.
Put your email address into a breach-checking site tonight, and see which of your passwords are already public.
The check takes a minute
Many separate conversations say the same first thing: a breach-checking service will tell you which known leaks your email address appears in, and often which password went with it. The site they all name is a free one run by a security researcher; this page does not name it, because the accounts also argue, evenly split across conversations, about the safety of typing an address into any such site, and the fork above carries that argument with its decider — an established service everyone can name is one thing, an unknown one another. One account adds the paste sites where dumps are posted as a second place to search, and one caution says that searching your own username can bring up the dumps themselves, passwords and all, which is exactly what you are checking for. More than one conversation adds the check your mail provider already gives you: the account’s recent-activity page, listing where and when it was opened, which one account says shows a sign-in from a place you were not.
What the answer is for
Several separate conversations say the leak is not the danger; the reuse is. A leaked address-and-password pair is tried against every other site, and the accounts whose one password opened everything are in these conversations. So the answer to the check is an order of work, which the second question below carries in full: the email account first, because one account says whoever holds your mail can reset the rest; then every account that shared the leaked password, each given its own; then the second step of verification on the email account, which several single accounts call the defence a stolen password cannot pass. The national cyber-security centre’s tips, read for this page, say the same three things — the email account is the route to identity theft, a password manager helps you keep the passwords apart, two-step verification is recommended — and one correction in these conversations says a text telling you someone has signed in is not two-step verification, because the second step has to be required to get in.
Your name, and the name you use
Several separate conversations say search your own name and usernames from time to time, because it shows you what a stranger digging would find and where your writing has been copied — many accounts in one note found their content on other sites. Several conversations say set a standing alert so new mentions reach you, and one account caught a false review within two days that way. The third question below carries the half of these conversations that says when this does not work: for a common name, or a footballer’s or a politician’s, one exchange across conversations splits with more against it, many accounts in one caution call the alerts useless, and the repair the accounts give is to narrow the alert with your town or your trade. Several corrections explain what an alert does and does not do — new pages only, not searches, not history — and this page carries them as the accounts’.
Two lives, two names
More than one conversation says a username should not hint at who you are, more than one says different usernames on different sites stop a stranger joining your accounts into one person, and more than one says an encrypted password manager is what makes that many identities possible. The fourth question below carries the rest of the accounts’ method — separate email addresses or aliases, closing the old profiles you have forgotten, not posting the room or the pet or the document that places you — and the correction that a private setting is not a hiding place. It also carries the account who says that much of what a search finds comes from data-broker sites rather than from anything you posted, and that opting out of them is the work that actually shrinks the trail.
Who this page is not for
If your name is common, or you share it with someone famous, the alert half of this page is not for you — one exchange across conversations and many accounts in one caution say so — and the breach check still is, because it works on an address, not a name. If what worries you is a partner reading your email, the accounts’ counsel on that is about the relationship rather than the password, and this page does not carry it; this page is about strangers and leaks. If you have already been exposed and someone is using it against you, legal recourse is a gap in these conversations, and the police and the platform are the places, not this page. And if you are hoping for anonymity against a state or a determined investigator, more than one caution says plainly that none of this is that: it raises the price of a casual search by an employer, a peer or a stranger with a grudge, which is what the accounts were guarding against.
The community disagrees on this one
Is it safe to type your email address into a site that checks for breaches? One exchange that crosses conversations splits evenly, and the accounts call it context-dependent: the site decides. This page names no site and prints both sides.
Use the known checker — it is a tool
Accounts in the crossing exchange say the widely known breach-checking service is a genuine and useful tool that shows which of your addresses and passwords appear in leaked datasets; many separate conversations name that one service; one account uses paste sites as a second check.
Never hand your address to a site you cannot vouch for
Accounts in the same exchange say submitting your email or username to a checker can feed a marketing list or a phishing page dressed as a tool, and that lesser-known sites carry that risk; one caution says searching yourself can surface the dumps themselves.
The number on each side is from the crossing exchange. What both sides name as the decider is the site’s standing: an established, widely known service is treated as safe by the accounts, an unknown one is not. This page adds one line of its own: type an address into a checker, never a password.
Common questions
Is it safe to type my email address into one of these sites?
The accounts argue this across conversations, evenly split, and the fork above renders it. Those for say the well-known breach-checking service is a genuine tool that tells you which of your addresses and passwords appear in known leaks; those against say handing your address to a site is itself a risk — a lesser-known one may harvest addresses for marketers or be a phishing page dressed as a checker. The accounts’ own decider is the site, not the idea: an established service everyone in these conversations can name is treated as safe, and an unknown one is not. This page names none and takes that decider as its own: use the one your own searching and asking turns up as widely used, type nothing but the email address, and never a password into a page that asks for one. One account searches paste sites for their address as a second check, and one caution says searching your own username can turn up the dumps themselves, passwords included — which is the answer, not a reason to stop. More than one conversation adds a check that costs nothing: your mail account’s own recent-activity page, which lists the places and times it was opened; one account says a sign-in from a place you were not is your answer, and more than one caution says it is less use if the suspected person shares your home connection, or if a network tool hides where they were.
It says my password leaked. What exactly do I change?
The order the accounts give, one item at a time. First the email account, because one account says the mail account is the master key — every other service sends its password reset there — and one says a changed password is the one immediate action that stops whoever is inside. Then every account where you used the leaked password, because several separate conversations say the danger after a breach is not the breach but the reuse: the leaked pair is tried against every other site, and a unique password per site is what makes the leak end where it started; the national cyber-security centre’s tips say a password manager helps you create and remember them, and more than one conversation says an encrypted manager is what makes several identities with strong separate passwords possible at all. One evenly split exchange argues whether a manager is a risk of its own if the device is taken, against memorised rules; one caution says the manager’s master password becomes the single door, and more than one says copying and pasting passwords on some phones exposes them to other apps. Then the second step: several single accounts say two-step verification is the defence that a stolen password cannot get past, and the centre recommends it; one correction says a text message telling you someone signed in is not two-step verification — the second step has to be required to finish the login — and one caution says a code by app beats a code by text. One contraindication says do not tie the second step to a phone alone without printing the backup codes, and more than one caution says a phone as the only key is a single point of failure; more than one account prints the codes and keeps them somewhere safe, and one objection says the codes are for emergencies, not for every login. Single accounts say the security questions are the weak door — the answers are on your own profile — and give false or random answers stored in the manager. How to recover an account that is already taken is a gap in these conversations; the provider’s recovery page is the place, and the sooner the better.
Should I set an alert on my own name?
Several separate conversations say search your own full name and usernames now and then, because it shows you where your writing has been copied, what someone digging would find, and pages about you that you did not know existed; several conversations say set a standing alert with a search engine so that new mentions reach you as they appear, and one account caught a false review of their business within two days that way and had it taken down. Then the accounts say when it does not work. One exchange that crosses conversations splits, with more on the side against: one side says alerts and searches catch problems early; the other says that for a common name they are useless, because the results are other people — many accounts in one caution say the same, and single accounts who share a name with a footballer, a politician or a crime victim describe a stream of notifications about strangers. More than one objection offers the repair: add your town, your trade or your employer to the alert so it narrows, and one account says alerts for your email address and for common misspellings of your name catch things a name alone does not. Several corrections say how the alert behaves: it fires on new pages containing your term, not when someone searches for you; it does not go back through old pages, so search by hand first; and one search-related notification feature the accounts relied on was discontinued in 2024. More than one caution says alerts are slow and miss things, and one account says theirs missed a news appearance and an obituary. One account says the searching turned up old, embarrassing writing they had forgotten; one account learned of a sibling’s death from an alert, and this page carries that as the weight the tool can have. One evenly split exchange argues whether knowing is worth it at all — one side says early knowledge saved a career, the other says for the rest of us the knowledge brings stress and no remedy, because reputation firms cost money and months. What to do once you find something — a takedown, a legal route — is a gap in these conversations, and this page has no law for it.
Do I really need a different username everywhere?
The accounts who have been found say yes, and the page carries their reasoning. More than one conversation says the username should not hint at your real name or details, more than one says different usernames on different platforms stop someone joining your accounts into one profile, and more than one says an encrypted password manager is what makes that many identities possible. Single accounts add: one email address across social networks and everything else is the link that joins them — use aliases or separate addresses, and one caution says the plus-sign alias trick fails on providers that strip it and on forms that reject it; search your old usernames too, and close or lock the profiles you had forgotten; do not put up photos of things that place you — a room, a pet, a document — or the small facts that add up, which one account says is how anonymous people are found; and one account keeps the accounts for one kind of life entirely separate from the accounts for another and rotates them. One correction says a private profile is not a hiding place: platforms reset settings, address-book imports reveal you, and the indexing sites may have cached you already. On the indexing sites, one account says much of what a search turns up about a person comes from data brokers rather than from anything the person posted, and that opting out of them — by hand, or through a removal service — is the work that actually shrinks the trail; one caution says the opting out is slow and the brokers repost. More than one caution says plainly that none of this is anonymity against a determined and well-resourced adversary, only a higher cost of finding you; the accounts’ own line is that it raises the price of a casual search by an employer, a peer or a stranger with a grudge, which is what they were guarding against. Which removal services exist now, and how to get something taken down once found, are gaps in these conversations.
Questions this step helps with
Same situation, another step
- Only the contract is the promisePaperwork
Full tip: https://findangel.org/tips/check-your-email-against-the-breach-list/ · FindAngel.org — free, always.