Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To check whether your email appears in known breach records, search it on Have I Been Pwned (HIBP), which describes its public lookup as free. For passwords, use HIBP’s separate Pwned Passwords check or a trusted password-check feature such as Google Password Checkup. A match means the information appears in that service’s data; it does not by itself mean someone is currently inside your account. If a password is exposed, replace it everywhere you used it.
How to check for leaked email addresses and passwords for free
- Check your email address. Open the official Have I Been Pwned site directly and search your address. HIBP says its service is free and is intended to help people assess breach risk. Avoid search-result ads and unsolicited breach-alert links, especially if they ask you to enter a password.
- Read what the result says was exposed. Review the breach names and data types listed. An email-address result does not identify which password, if any, was exposed; do not infer that from the address alone.
- Check passwords separately, if needed. Use HIBP’s Pwned Passwords service or Google’s Password Checkup for passwords saved in your Google account. Google says the feature can notify users if saved passwords are found compromised. Do not submit an email-and-password combination to an unfamiliar checker.
- Keep a “not found” result in perspective. It means the information was not found in that service’s indexed data, not that it has never been exposed. Keep account alerts enabled and protect important accounts regardless of the lookup result.
What a match does—and does not—tell you
An email match
An email match means the address appeared in breach data indexed by HIBP. The records may not include a username and password, and a match is evidence of exposure—not proof of a current account takeover.
A password match
A password match means that password has appeared in breach data before. HIBP advises against using it again: attackers may try exposed passwords on accounts where they are still in use. Change it on the breached service and anywhere else you reused it.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →No match
No match is limited to the data available to the service. A lookup cannot certify that an address or password has never been exposed.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Signs of an active account problem
Unexpected password or recovery-detail changes, unfamiliar sign-in alerts, loss of access, or messages you did not send warrant investigation. Those signs are different from an email address simply appearing in breach records; if you cannot get into an account, use the service’s official recovery process.
What to do after a password exposure or suspicious activity
- Replace the exposed password. Change it on the affected service. If you reused it—or used a similar password—change those accounts too. Use a different, unique password for every account. The U.S. Federal Trade Commission (FTC) advises: “If a company or website tells you it lost your password in a data breach, change your password right away.”
- Secure your email account if it may be affected. Email often receives password-reset links for other services, so access to it can help an attacker reach more accounts. If you are locked out, follow the email provider’s official recovery process.
- End other sessions. If the service offers a control to sign out of all devices or sessions, use it, then sign back in with the new password.
- Enable multifactor authentication (MFA). Use an authenticator app or security key when the service offers one. Options and strength vary by service; a security key is an optional factor for compatible accounts, not a leak detector or a substitute for changing a compromised password.
- Review account recovery and activity. Check that the recovery email and phone number are yours. Look for unfamiliar devices, email-forwarding rules, sent or deleted messages, social posts, or messages and contacts. Remove settings you did not create.
- Warn contacts if the account was used. If someone sent messages or posts without your permission, tell contacts not to open links or respond to requests for money from that account.
When leaked information may call for identity-theft steps
An exposed login does not automatically mean you need credit-related protections. If the breach involved a Social Security number or financial identity data—or you see evidence that such information is being misused—follow the breach notice and official guidance for your country. For U.S. readers, the FTC directs identity-theft victims to IdentityTheft.gov to report what happened and get a personalized recovery plan. FTC guidance does not make credit reports, fraud alerts, or freezes necessary for every email-and-password exposure.
Rank #2
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
Which free check should you use?
| Check | What it checks | Data and scope | What you get |
|---|---|---|---|
| HIBP email search | An email address | Breach records indexed by HIBP | A lookup result and reported breach details; a match is not proof of current account access |
| HIBP Pwned Passwords | A password | Passwords appearing in HIBP’s breach data | A match or no match for that password in the service’s data |
| Google Password Checkup | Passwords saved in a Google account | Saved-password checking within Google’s account ecosystem | Google says it can notify users if saved passwords are found compromised |
These checks answer different questions: an email search checks whether an identifier appears in indexed breach records, while password checkups assess passwords within their stated scope. Google’s feature applies to passwords saved in a Google account. The available service descriptions do not establish a comprehensive independent privacy comparison, so there is no basis here to rank one option as universally safer. Choose the official service whose scope fits what you want to check, and do not hand your credentials to an unfamiliar site.
Quick Recap
Rank #4
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

