Somewhere on a criminal forum, there is very likely a file with your email address in it. That sentence is true for almost every adult who has used the internet for more than a few years, which is exactly why it should not panic you. The useful question is not whether your email is out there. It is what else is sitting in the same row of the spreadsheet.
This guide explains how breach lookups actually work, what a result means, and, just as important, what it does not mean.
Why your email address is the thing you search
When a company gets breached, the stolen data usually ends up structured like a spreadsheet: one row per customer, one column per data type. Your email address is almost always one of the columns, because almost every service uses it as your login.
That makes your email address the index key of your digital life. It is the one identifier that appears in your bank login, your shopping accounts, your subscriptions, and your old forum registrations from fifteen years ago. Searching for it is how you find out which rows, in which stolen spreadsheets, belong to you.
How lookup services work
Breach lookup services collect copies of stolen datasets after they surface publicly, catalog what each one contains, and let you search your own email against the collection. The best known is Have I Been Pwned, a research project whose database is referenced by browsers and security teams worldwide. Our own free scan is built on the same data.
A lookup does not check whether someone is using your data right now. It answers a narrower, more factual question: which known breaches contained your email address, and what other data types were taken alongside it in each one.
How to read a match
Suppose your result says your email appeared in a breach of a company you barely remember signing up for. Before dismissing it, look at two things.
First, the data types. A breach that exposed only email addresses is a phishing risk and little more. A breach that exposed passwords is a different animal, especially if you reused that password anywhere. A breach that included phone numbers, dates of birth, or home addresses matters most of all, because those cannot be changed the way a password can.
Second, the reuse question. The password you used on that forgotten site in 2016: did you also use it, or something close to it, on accounts you actually care about? Attackers assume you did, and they check automatically. That single assumption is behind most account takeovers, and it is why the number of breaches you appear in matters less than what you reused across them.
What a clean result does not mean
If your email comes back with no matches, that is good news, but read it precisely: it means your email has not appeared in any publicly known breach. Breaches routinely take months or years to be discovered and disclosed. Some are traded privately and never surface at all. A clean result is a snapshot, not a certificate.
This is also why checking once and never again misses the point. The list of known breaches grows constantly, and a breach that happened three years ago might only enter the databases next month.
- A match tells you which stolen datasets include you and what was taken. It does not mean you are being actively targeted.
- The data types matter more than the breach count. Passwords are urgent. Birth dates and addresses are permanent.
- A clean result means "not in any known breach," not "safe."
What to do with your results
If a breach exposed a password, change it on that site and anywhere you reused it, starting with your email account itself, since every password reset on every other service flows through your inbox. If a breach exposed your phone number or date of birth, the response is different: those feed SIM swap attacks and identity fraud, and the defenses are stronger authentication and a credit freeze rather than a password change.
We cover the exact sequence in the next guide. The only wrong move is checking, wincing, and doing nothing.
See which breaches contain your email
Our free scan checks your address against known breach data and shows what was exposed in each one. Takes about 10 seconds, no account required.
Run the Free Breach Scan →