How to Check if Your Email Was in a Data Breach

The short answer
Go to haveibeenpwned.com, enter your email address, and review the breach list. If your email appeared alongside a password, change that password on every site where you reused it, then enable two-factor authentication on your email account. The spam increase is real but secondary — the password is the emergency.
Check if your email was in a data breach in under a minute. Learn what a breach result means and what to do first — credentials before inbox.
On this page
If your email address was in a data breach, you can confirm it in under a minute. The harder part is knowing what to do with the result, and in what order. A breached email address explains a sudden rise in spam and unsolicited mail — but if the breach also exposed a password you reuse, that is the real emergency, and it needs to be dealt with before you touch anything else in your inbox.
This guide walks you through how to check if your email was in a data breach, how to read the result honestly, and how to respond — starting with the things that protect your account rather than just your inbox.
Before you start: what a breach result does and does not tell you#
A breach database records that a dataset containing your email address leaked from a third-party service — a retailer, a forum, a data broker, a loyalty programme. Finding your address in a breach confirms it was in that leak. It does not mean your inbox was accessed, your email provider was compromised, or that someone is actively using your account. What determines your next move is what type of data the breach included alongside your address.
An email-address-only breach means your address has entered circulation. Expect more spam, more phishing attempts, and more cold outreach — your address is now on lists being traded between bulk senders. That is a genuine nuisance, but it is not an account security problem. A breach that also listed passwords is a different situation: if you used the same password on that site as you do on your email account or anywhere else, you need to change it immediately. That is the actual risk a breach creates.
One rule before you start: do not enter your password anywhere to check whether it has been exposed. Several tools let you do exactly that, some using a cryptographic technique called k-anonymity that means the full password never leaves your device. We are still not recommending them here. Entering a real password into any form other than the login page it belongs to is a habit that causes breaches — the technique may be sound, but the reflex is not. Check your email address. Leave your password out of it.
Do not enter your password to check if it has been breached
How to check if your email was in a data breach#
Everything you need is your email address and a browser. The check takes under a minute. What you do after depends on what you find.
- 1
Open Have I Been Pwned
Go to haveibeenpwned.com in your browser. The site is a free public service run by security researcher Troy Hunt. It indexes breach data from thousands of reported incidents and is used as a data source by Google, Mozilla, and 1Password. No account or payment is required to run a single address check.
- 2
Enter your email address — not a password
Type the email address you want to check into the search field and press Enter. Results appear immediately. The site shows either a green banner confirming the address was not found, or a red result listing every breach the address appeared in. If you have more than one address, run each separately — work or alias addresses often appear in more breaches than a primary personal address.
- 3
Read the breach list carefully
For each breach entry, note the name of the service, the date the breach occurred, and the data types listed. Common data types include email, password, IP address, name, phone number, and physical address. Focus on the data types column: a breach that listed only email addresses is low urgency. A breach that listed passwords is not.
- 4
Change the password on any site that exposed yours
For each breach that listed passwords, go to that site and change your password. Use a password manager to generate a long, unique password you do not use anywhere else. If you used the same password on your email account as on any breached site, change your email account password before anything else.
- 5
Enable two-factor authentication on your email account
Two-factor authentication means an attacker with your password still cannot sign in without a second code sent to your phone or generated by an authenticator app. Enable it on your email account first — it is your highest-value account because password resets for everything else go through it. Then enable it on any other account that appeared in a breach.
- 6
Check your other addresses
Most people have two to four active email addresses. An older address from a job, a university, or a service you stopped using may have appeared in more breaches than your current primary — and may share a password you still rely on. Run the same check for each address you own.
What should you do after a breach, by email provider?#
The steps above apply regardless of which email service you use. The specific pages for changing your password, enabling two-factor authentication, and reviewing active sessions differ by provider. Use the table below to go directly to the right settings.

| Provider | Change your password | Enable two-factor authentication | Review and end active sessions |
|---|---|---|---|
| Gmail | myaccount.google.com, then Security, then Password | Security, then 2-Step Verification. Choose an authenticator app or a hardware security key over SMS where possible. | Security, then Manage devices. Remove any device you do not recognise. |
| Outlook / Microsoft 365 | account.microsoft.com, then Security, then Password security | account.microsoft.com, then Security, then Advanced security options. The Microsoft Authenticator app is the recommended method. | Recent activity at account.microsoft.com. Sign out sessions you do not recognise. |
| iCloud Mail | appleid.apple.com, then Sign-In and Security, then Change Password | Sign-In and Security, then Two-Factor Authentication. Uses trusted Apple devices or SMS as a fallback. | Sign-In and Security, then Devices. Remove anything unfamiliar. |
| Yahoo Mail | login.yahoo.com, then Account security, then Change password | Account security, then Two-step verification. SMS or an authenticator app. | Account security, then Recent activity. End sessions you do not recognise. |
What if the check comes back clean but the spam keeps arriving?#
Have I Been Pwned only indexes breaches that have been publicly reported and processed. A breach that happened recently may not appear for days or weeks. One that circulated privately — sold between data brokers rather than dumped on a public forum — may never appear at all. A clean result rules out a known, indexed breach. It does not rule out exposure.
If the check comes back clean and the spam volume is still rising, the more likely explanations are that your address was sold by a data broker, scraped from a public page or directory, or picked up through co-registration when you signed up at a site that shares its list with partners. Those are inbox problems rather than account security problems, and they have different solutions.
Regardless of the result, consider signing up for Have I Been Pwned's free notification feature. It sends you an alert if your address appears in a newly indexed breach — so you hear about future incidents without having to run a manual check.
A faster way to manage the inbox fallout#
After a breach, the spam increase is often permanent. Your address is in circulation now, and circulation compounds — addresses get traded and re-traded between bulk senders for years. The phishing attempts, cold outreach, and newsletters you never subscribed to do not stop when the breach becomes old news.
We build AI Emaily, an AI email client that handles the triage layer: it filters cold outreach, auto-files newsletters, and flags suspicious messages that look like phishing attempts. To be plain about the limit: AI Emaily does not monitor breaches, cannot remove your address from leaked datasets, and is not a replacement for changing your passwords and enabling two-factor authentication. What it does is manage the inbox volume that follows a breach, so your real correspondence stays visible. If a breach just made your inbox unusable and you have already handled the credential steps above, that is the specific problem it is built to solve. Try it at app.aiemaily.com.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.