Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use two separate checks: an email-address breach lookup to see whether your address appears in known breach records, and a password lookup to see whether a particular password has appeared in breach data. A match is a warning to act, not proof that someone has accessed your account. If a password is exposed, replace it with a unique one on every account where you used it, then enable multifactor authentication (MFA) where available.

What each exposure check tells you

Email and password checks answer different questions. Have I Been Pwned (HIBP) lets you look up an email address against known breach records and separately check whether an individual password has appeared in breach data. See the HIBP FAQ and Pwned Passwords.

  • Email-address lookup: identifies known breach records associated with the address and can show the affected service and reported categories of data. It does not establish that every account using the address is compromised.
  • Password lookup: checks whether a password has appeared in breach data. If it has, stop using it—even if you have not noticed suspicious account activity.

A positive result means the information appears in data known to the service; it does not by itself prove current account access, identity theft, or that a particular attacker has your details. A result with no match is not proof of safety: a lookup cannot cover data it does not know about or rule out phishing, malware, or an unreported exposure.

Check your email addresses and passwords safely

Look up email addresses first

  1. Open a trusted breach-notification service by typing its address yourself or using a saved bookmark. For example, visit Have I Been Pwned.
  2. Check the email addresses you use for important accounts, including the address used for password recovery.
  3. For each match, note the service and the data categories listed. Use that information to decide which accounts and credentials to review; a listing is not confirmation of a current login or takeover.

Check a password separately

Use a dedicated password lookup such as HIBP Pwned Passwords. HIBP says the password is hashed in your browser; only the first five characters of its SHA-1 hash are sent to the API, and the comparison is completed on your side. HIBP describes this password system as separate from its breach-account service: the password hashes are not linked there to an email address or identity. Its storage explanation was updated 22 March 2026. These details describe HIBP, not every checker.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Do not paste a current password into a search engine or an unknown checker.
  • Avoid unofficial breach-dump sites; they may expose you to stolen data or unsafe downloads.
  • If you do not trust a lookup’s handling of passwords, skip that check and replace any password you suspect may have been exposed.

Change an exposed password without creating a new risk

  1. Go to the official service. Open its known app or type its official web address. Do not use a password-reset link from an unexpected message.
  2. Change the password promptly. Use the service’s account or security settings. The Australian Cyber Security Centre advises changing affected passwords and any reused passwords, and enabling MFA where possible in its consumer guide.
  3. Replace every reuse. If the exposed password was used on other sites, change it on each of them too. Include predictable variations, such as the same base password with a different number or punctuation mark.
  4. Choose a unique replacement. A password manager can generate and store a different password for each account. If you must make one yourself, NIST recommends at least 15 characters; a long passphrase can be easier to remember. Do not make a predictable tweak to the exposed password. See NIST’s consumer guidance.
  5. Enable MFA. Turn it on for the affected account and, especially, the email account used for password recovery. NIST says MFA can help protect an account even if its password is compromised. Depending on what the service supports, options can include an authenticator app, a push prompt, a text code, or a USB security key. Methods differ in security; NIST notes that text codes are particularly vulnerable. Check the service’s supported options and device compatibility before choosing a method.

NIST’s current digital identity guideline, SP 800-63B-4, says verifiers processing a password change must compare the proposed password against a blocklist of known commonly used, expected, or compromised passwords. That requirement applies to services implementing the standard; it is not a reason to submit your password to an arbitrary website.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If you suspect someone has taken over an account

A breach-list match alone does not establish takeover. If you see signs of unauthorized access or cannot sign in, use the affected service’s official account-recovery channel and follow its support instructions. The recovery steps vary by service; do not rely on a breach lookup as a substitute for the service’s recovery process.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How to interpret the result

Result What it means What to do
Email address appears in a breach The address appears in a known breach record; the listed service and data categories can guide your review. Review the affected service and any credentials associated with it. Change passwords that are exposed or reused.
Password appears in breach data The password has appeared in breach data and should no longer be used. Change it on every account where it was used, including predictable variations.
No match appears The service found no match in the data it checks; this does not rule out unreported or unknown exposure, phishing, or malware. Continue using unique passwords and MFA where available, and respond to suspicious account activity through the service’s official channels.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.