iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Check your email address for breach records and check each password separately against a known exposed-password corpus. Those checks answer different questions: an email appearing in a breach does not prove your current password is compromised, and a password search with no match does not prove the password is safe. If a password matches, replace it everywhere you used it and secure those accounts—starting with email.
Check your email address and passwords separately
- Search your email address for breach records. Use the breach-search feature in the Have I Been Pwned (HIBP) dashboard. HIBP says its dashboard also offers searches for sensitive breaches and stealer-log entries after email verification. A result means the address appeared in data HIBP has indexed; it does not by itself show that someone has taken over an account or that a particular current password was exposed. HIBP FAQ
- Check a password with Pwned Passwords. Use HIBP’s Pwned Passwords feature to find out whether the password appears in its known corpus. HIBP describes a k-anonymity design: the password is hashed in your browser, only the first five characters of its SHA-1 hash are sent, and your browser compares the full hash locally against returned matches. This explains how HIBP says its own check works; it is not a blanket guarantee about other sites, devices, or tools. Do not paste passwords into unfamiliar third-party checkers.
A match means the password has appeared in the corpus and should not be used. A no-match means only that HIBP found no match in the data loaded for that lookup; it does not establish that the password is strong, has never been exposed, or is absent from all breach data.
What to do when a password or account is exposed
Replace the password everywhere it was used
Change the password on the affected service and on every other account where you reused it, including accounts using a slightly changed version. Create a new, unique password rather than modifying the old one. If it protected your email account, prioritize changing it: access to an inbox can let someone request password resets for other services. FTC guidance on hacked email and social media accounts; FTC advice on protecting personal information
Recommended Free Tools
Close off access and check recovery settings
If you suspect someone has accessed an account, use its security settings to sign out of other sessions, then enable multifactor authentication (MFA). Check that the recovery email address and phone number are yours. For email accounts, inspect forwarding rules, sent messages, and deleted messages for activity or changes you did not make. If you cannot sign in, follow the provider’s account-recovery process, then complete these security checks after you regain access. FTC guidance on hacked accounts
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Create stronger passwords that are unique to each account
A password manager or your browser’s password-saving and generation features can help create and store a different password for each service. FTC guidance published in October 2024 recommends aiming for 12 to 15 characters; CISA’s 2024 Secure Our World password sheet specifies 16 characters. These are attributed recommendations, not a single agreed universal threshold. Both sources emphasize long, unique passwords. FTC also describes a passphrase made from random words as an option and warns against familiar phrases. FTC password advice; CISA Secure Our World password tip sheet
Choose MFA with recovery in mind
Enable MFA on email, financial, social, tax, and payment accounts. When a service offers a choice, consider both how easily a phisher or phone-number takeover could capture a factor and how you would recover access if you lost a device.
Rank #2
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
- Security key: FTC describes a security key as the strongest 2FA method in its guidance. It is a physical device, so check that the service and your devices support it, and set up a safe recovery method before relying on it. FTC two-factor authentication guidance
- Authenticator app: A practical alternative when a security key is not supported. Keep any recovery codes or backup factors somewhere safe and follow the service’s own enrollment and recovery instructions. FTC advice on protecting personal information
- Text-message or email codes: Use these when stronger options are unavailable, understanding that FTC guidance considers them less secure than an authenticator app or security key. A SIM-swap can expose codes sent by text. FTC advice on protecting personal information; FTC two-factor authentication guidance
What an exposure check cannot tell you
HIBP’s breach search checks whether an email address appears in data it has indexed; Pwned Passwords checks whether a password appears in its known corpus. Neither result is a complete assessment of an account’s current security. In particular, a clean password lookup is not a strength test, and an address match is not proof of account takeover. HIBP describes checking passwords against a blocklist of known compromised passwords as a way to avoid using them, but a lookup’s coverage is limited to the data available to that service. HIBP FAQ; Pwned Passwords
Quick Recap
Rank #4
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

