Check an email address with Have I Been Pwned (HIBP) or Mozilla Monitor. To check passwords, use Google Password Checkup for credentials saved in your Google Account, or HIBP’s Pwned Passwords checker for an individual password. A match means the address or password appears in the service’s collected breach data—not that someone currently has access to your account. If a password is exposed, change it anywhere you used it, review account activity, and turn on multifactor authentication where available.
What an email or password check can tell you
Email and password checks answer different questions. An email lookup finds known breach records associated with that address. A password checker tells you whether the password appears in a known compromised-password corpus; it does not identify the person or account that used it.
HIBP keeps email breach records and Pwned Passwords data separate and unlinked. It cannot use a password match to tell you which email address or account was involved, or use an email search to identify a password. HIBP explains the data it stores.
A match is historical exposure evidence, not proof of current account access or misuse. A result with no match is limited, too: the address or password could still have been exposed in an incident that the service has not indexed. A password missing from a breach corpus is not necessarily strong or safe.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
How to check whether an email address was exposed
Search Have I Been Pwned
- Open Have I Been Pwned and search the email address you want to check.
- Review any breach records shown, including the breach name, date, and exposed data categories. These indicate known exposure, not whether anyone has accessed the account since.
- If a result relates to a sensitive breach, HIBP does not make it publicly searchable. Verify that you own the address through the HIBP dashboard to see sensitive-breach results.
Use Mozilla Monitor
Mozilla Monitor checks addresses against known breaches using HIBP data and provides monitoring and recovery guidance. Sign in, open the dashboard, and add an address; Mozilla’s setup process uses an email verification link. Sensitive-breach exposure has additional controls: Mozilla says you must sign in or subscribe and verify the address to check it. See the Mozilla Monitor FAQ for details.
How to check whether a password was exposed
Check passwords saved to your Google Account
Open Google Password Manager and run Password Checkup on the web, in Chrome, or on Android. Google says the check can flag saved passwords that are exposed, weak, or reused. It only covers credentials saved to that Google Account, so it may not include passwords stored elsewhere or passwords you never saved there. Follow Google’s Password Checkup instructions for the current interface.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Check an individual password with HIBP
HIBP’s Pwned Passwords checker uses a privacy-preserving hash-prefix method called k-anonymity. The password is hashed on your device; the checker sends only the first five characters of its SHA-1 hash. HIBP returns possible matching hash suffixes, and the full comparison happens locally. The full password and full hash are not sent by this method. Use the official Pwned Passwords page, not an unknown website asking you to submit an active password.
If HIBP finds a match, treat that password as unsafe to use. If it finds none, that only means the password was not found in HIBP’s data; it is not a guarantee that the password is secure.
Rank #3
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
Which breach-checking option should you use?
| Option | What it checks | Important scope or limit |
|---|---|---|
| HIBP email search | Email address in indexed breach records | Sensitive breaches require verified access; no match does not prove no exposure. |
| Mozilla Monitor | Email exposure using HIBP breach data, with monitoring and recovery guidance | Email verification is required; sensitive-breach access has additional controls. |
| HIBP Pwned Passwords | Whether an individual password appears in known breached-password data | Uses a hash-prefix privacy method and does not link a password to an email identity. |
| Google Password Checkup | Exposed, weak, or reused passwords saved in a Google Account | Does not necessarily cover passwords saved elsewhere or not saved to that account. |
| Firefox breach alerts | Known breach signals about websites visited in Firefox | Mozilla says rollout began gradually with Firefox version 152; availability may vary, and alerts are not a complete account-level check. |
Mozilla documents Firefox breach alerts as a supplement to other checks, not a replacement for checking addresses and passwords directly. Browser features and service interfaces can change, so consult the linked official help pages for current availability.
Quick Recap
Best Value
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Rank #4
What to do if a check finds a match
- Go to the service directly. Open the affected provider’s official website or app yourself. Do not use sign-in links in unexpected breach or security emails, which could be phishing. Consumer guidance from the Associated Press also advises caution with unexpected messages.
- Change the affected password. If you reused the same or a similar password on other accounts, change those too. Choose a distinct replacement for each account; Mozilla recommends changing breached passwords and any reused copies in its breach-resolution guidance.
- Review account activity and recovery details. Check recent sign-ins, active sessions, connected services, recovery email addresses, and phone numbers. Sign out unfamiliar sessions and remove unrecognized devices. See Mozilla’s account-activity guidance.
- Enable multifactor authentication. Turn on two-step verification or another supported MFA method. An authenticator app or a hardware security key can serve as an additional factor where the account supports it.
- Make unique passwords easier to manage. A password manager can generate and store a different password for each account. It helps with the response, but it does not tell you whether an address or password appeared in a breach.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

