Skip to content

Have I Been Pwned

Check if your email or password has appeared in data breaches.

Not yet verified
Demo online
MIT

Open the official app on haveibeenpwned.com

This tool is hosted by its maintainers. Click below to open haveibeenpwned.com in a new tab — it's their official demo.

Browse validators tools →

What's next with Have I Been Pwned?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Have I Been Pwned?

Have I Been Pwned is an open-source web tool developed by Troy Hunt to help users identify if their email address has been involved in data breaches. The tool queries a database of compromised credentials from past breaches, providing users with visibility into how their personal data may have been exposed. It serves individuals, businesses, and cybersecurity professionals by offering insights into breach history and potential risks. The primary problem it addresses is the lack of transparency around data breaches, enabling users to take proactive steps to secure their accounts. By highlighting breaches linked to specific email addresses, the tool users to assess their exposure and mitigate risks such as phishing attacks or identity theft. Its simplicity and reliance on public breach data make it accessible for non-technical users while still offering actionable information for those with technical expertise.

How it works

Have I Been Pwned is a free, open-source web service that checks if an email address has been part of a known data breach. It aggregates breach data from public sources, including leaked databases and security incidents, to provide users with a historical record of compromises. The tool’s primary purpose is to inform users about the exposure of their personal information, enabling them to take steps like changing passwords or enabling two-factor authentication. The service is designed for individuals concerned about their online security, IT professionals monitoring organizational risks, and researchers studying breach patterns. By offering a straightforward interface, it bridges the gap between technical breach data and user-friendly insights, making cybersecurity awareness more accessible. The tool allows users to input an email address and receive a report indicating whether it has been found in any breaches. It provides details such as the number of breaches, dates, and the source of the data. Users can also opt to receive notifications if their email appears in future breaches, though this requires linking to a password manager like 1Password. Additionally, it includes a 'Paste Records' feature to search for exposed data in text-sharing sites or public dumps.

How to use it

  1. 1Open the Have I Been Pwned page
  2. 2Use the tool directly in your browser
  3. 3Results appear instantly — no waiting, no downloads

What it can do

  • breach check

Use cases

Assumptions and limitations

Assumptions

  • source: https://haveibeenpwned.com/
  • license: Open source
  • privacy: Opens an external demo

Limitations

  • The tool only checks breaches tied to email addresses, not other forms of personal data.
  • It does not include all breaches, as some data sources may not be publicly available.
  • There is no built-in password strength check or encryption verification.
  • Real-time breach alerts are limited to notifications via linked password managers.
  • The tool cannot prevent breaches or secure user accounts directly.

Understanding the result

Check if your email or password has appeared in data breaches.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(https://haveibeenpwned.com/)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with https://haveibeenpwned.com/. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What does Have I Been Pwned do?

Have I Been Pwned checks if an email address has been part of a data breach by querying a database of compromised credentials. It provides a historical record of breaches linked to the email, including the number of incidents, dates, and sources. The tool helps users assess their exposure to cyberattacks and take steps to secure their accounts.

How does Have I Been Pwned work technically?

The tool uses a database of breaches compiled from public sources, such as leaked databases and security incident reports. When a user inputs an email, it hashes the address and compares it against the breach data. This hashing method protects user privacy by not storing plaintext emails. The tool also leverages a 'Paste Records' feature to search for exposed data in text-sharing sites or public dumps.

How do I check if my email has been pwned?

Visit the Have I Been Pwned website, navigate to the 'Check Email' section, and enter your email address. Click 'Check' to retrieve results. If breaches are found, review the details for breach dates and sources. To stay updated, link your email to a password manager like 1Password for breach notifications.

How does Have I Been Pwned compare to alternatives like Privacy Badger or Have I Been Pwned's API?

Have I Been Pwned focuses on email-based breach checks and provides detailed breach history, while Privacy Badger is a browser extension that blocks tracking scripts. The Have I Been Pwned API allows developers to integrate breach data into custom applications, offering more flexibility than standalone tools like Privacy Badger.

What should I do if my email is found in a breach?

Change passwords for affected accounts, enable two-factor authentication, and monitor financial statements for unauthorized activity. Use a password manager to generate unique passwords for each account. If the breach involves a service you no longer use, consider closing the account and requesting a data deletion.

Spotted something wrong with Have I Been Pwned, or want to maintain it? See how to help.