Blog/ Unsubscribing & opting out

How to Check if Your Email Was in a Data Breach

Nafiul HasanNafiul Hasan· 10 min read
Search interface showing an email address being checked against a database of data breach records

The short answer

Go to haveibeenpwned.com, enter your email address, and review the breach list. If your email appeared alongside a password, change that password on every site where you reused it, then enable two-factor authentication on your email account. The spam increase is real but secondary — the password is the emergency.

Check if your email was in a data breach in under a minute. Learn what a breach result means and what to do first — credentials before inbox.

On this page
  1. 01Before you start: what a breach result does and does not tell you
  2. 02How to check if your email was in a data breach
  3. 03What should you do after a breach, by email provider?
  4. 04What if the check comes back clean but the spam keeps arriving?
  5. 05A faster way to manage the inbox fallout

If your email address was in a data breach, you can confirm it in under a minute. The harder part is knowing what to do with the result, and in what order. A breached email address explains a sudden rise in spam and unsolicited mail — but if the breach also exposed a password you reuse, that is the real emergency, and it needs to be dealt with before you touch anything else in your inbox.

This guide walks you through how to check if your email was in a data breach, how to read the result honestly, and how to respond — starting with the things that protect your account rather than just your inbox.

Before you start: what a breach result does and does not tell you#

A breach database records that a dataset containing your email address leaked from a third-party service — a retailer, a forum, a data broker, a loyalty programme. Finding your address in a breach confirms it was in that leak. It does not mean your inbox was accessed, your email provider was compromised, or that someone is actively using your account. What determines your next move is what type of data the breach included alongside your address.

An email-address-only breach means your address has entered circulation. Expect more spam, more phishing attempts, and more cold outreach — your address is now on lists being traded between bulk senders. That is a genuine nuisance, but it is not an account security problem. A breach that also listed passwords is a different situation: if you used the same password on that site as you do on your email account or anywhere else, you need to change it immediately. That is the actual risk a breach creates.

One rule before you start: do not enter your password anywhere to check whether it has been exposed. Several tools let you do exactly that, some using a cryptographic technique called k-anonymity that means the full password never leaves your device. We are still not recommending them here. Entering a real password into any form other than the login page it belongs to is a habit that causes breaches — the technique may be sound, but the reflex is not. Check your email address. Leave your password out of it.

Do not enter your password to check if it has been breached

The Pwned Passwords section of Have I Been Pwned uses k-anonymity so your full password never leaves your device. The technique is legitimate, but we are recommending against using it. Entering a real password into an external form is a habit worth avoiding entirely. If a breach listed passwords, assume yours was included and change it on that site. You do not need to confirm the value of a password you are about to replace.

How to check if your email was in a data breach#

Everything you need is your email address and a browser. The check takes under a minute. What you do after depends on what you find.

  1. 1

    Open Have I Been Pwned

    Go to haveibeenpwned.com in your browser. The site is a free public service run by security researcher Troy Hunt. It indexes breach data from thousands of reported incidents and is used as a data source by Google, Mozilla, and 1Password. No account or payment is required to run a single address check.

  2. 2

    Enter your email address — not a password

    Type the email address you want to check into the search field and press Enter. Results appear immediately. The site shows either a green banner confirming the address was not found, or a red result listing every breach the address appeared in. If you have more than one address, run each separately — work or alias addresses often appear in more breaches than a primary personal address.

  3. 3

    Read the breach list carefully

    For each breach entry, note the name of the service, the date the breach occurred, and the data types listed. Common data types include email, password, IP address, name, phone number, and physical address. Focus on the data types column: a breach that listed only email addresses is low urgency. A breach that listed passwords is not.

  4. 4

    Change the password on any site that exposed yours

    For each breach that listed passwords, go to that site and change your password. Use a password manager to generate a long, unique password you do not use anywhere else. If you used the same password on your email account as on any breached site, change your email account password before anything else.

  5. 5

    Enable two-factor authentication on your email account

    Two-factor authentication means an attacker with your password still cannot sign in without a second code sent to your phone or generated by an authenticator app. Enable it on your email account first — it is your highest-value account because password resets for everything else go through it. Then enable it on any other account that appeared in a breach.

  6. 6

    Check your other addresses

    Most people have two to four active email addresses. An older address from a job, a university, or a service you stopped using may have appeared in more breaches than your current primary — and may share a password you still rely on. Run the same check for each address you own.

What should you do after a breach, by email provider?#

The steps above apply regardless of which email service you use. The specific pages for changing your password, enabling two-factor authentication, and reviewing active sessions differ by provider. Use the table below to go directly to the right settings.

Magnifying glass examining a breach record showing data type categories including email, password, and IP address — illustrating how to read which types of personal data were exposed in each incident
The data types column is the one that matters. A breach listing passwords requires immediate action on any site where you reused that password. A breach listing only email addresses means your address is in circulation, not that your account was accessed.
ProviderChange your passwordEnable two-factor authenticationReview and end active sessions
Gmailmyaccount.google.com, then Security, then PasswordSecurity, then 2-Step Verification. Choose an authenticator app or a hardware security key over SMS where possible.Security, then Manage devices. Remove any device you do not recognise.
Outlook / Microsoft 365account.microsoft.com, then Security, then Password securityaccount.microsoft.com, then Security, then Advanced security options. The Microsoft Authenticator app is the recommended method.Recent activity at account.microsoft.com. Sign out sessions you do not recognise.
iCloud Mailappleid.apple.com, then Sign-In and Security, then Change PasswordSign-In and Security, then Two-Factor Authentication. Uses trusted Apple devices or SMS as a fallback.Sign-In and Security, then Devices. Remove anything unfamiliar.
Yahoo Maillogin.yahoo.com, then Account security, then Change passwordAccount security, then Two-step verification. SMS or an authenticator app.Account security, then Recent activity. End sessions you do not recognise.

What if the check comes back clean but the spam keeps arriving?#

Have I Been Pwned only indexes breaches that have been publicly reported and processed. A breach that happened recently may not appear for days or weeks. One that circulated privately — sold between data brokers rather than dumped on a public forum — may never appear at all. A clean result rules out a known, indexed breach. It does not rule out exposure.

If the check comes back clean and the spam volume is still rising, the more likely explanations are that your address was sold by a data broker, scraped from a public page or directory, or picked up through co-registration when you signed up at a site that shares its list with partners. Those are inbox problems rather than account security problems, and they have different solutions.

Regardless of the result, consider signing up for Have I Been Pwned's free notification feature. It sends you an alert if your address appears in a newly indexed breach — so you hear about future incidents without having to run a manual check.

A faster way to manage the inbox fallout#

After a breach, the spam increase is often permanent. Your address is in circulation now, and circulation compounds — addresses get traded and re-traded between bulk senders for years. The phishing attempts, cold outreach, and newsletters you never subscribed to do not stop when the breach becomes old news.

We build AI Emaily, an AI email client that handles the triage layer: it filters cold outreach, auto-files newsletters, and flags suspicious messages that look like phishing attempts. To be plain about the limit: AI Emaily does not monitor breaches, cannot remove your address from leaked datasets, and is not a replacement for changing your passwords and enabling two-factor authentication. What it does is manage the inbox volume that follows a breach, so your real correspondence stays visible. If a breach just made your inbox unusable and you have already handled the credential steps above, that is the specific problem it is built to solve. Try it at app.aiemaily.com.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Your inbox after a breach is a triage problem

AI Emaily filters the phishing attempts, cold outreach, and spam that follow a breached address — so the email that actually matters stays visible.

  • 7-day free trial
  • Cancel anytime
  • Every provider