What Is Have I Been Pwned? Used For: Features, Reviews & Alternatives
Check if your email was in data breaches.
Editorially updated Oct 25, 2025

The overview
What Have I Been Pwned? is for
1Core Capabilitie
- Email address breach query panel
- Phone number breach query panel
- Pwned Passwords hash lookup API
- Consolidated breach incident display
2Specialized Workflow
- Domain breach monitoring registration
- Breach notification subscription service
- Public API endpoint for programmatic check
- Attributed breach source listing
Who it helps
Useful ways to use Have I Been Pwned?
A practical path
Querying an Email Address for Breache
Navigate to the Have I Been Pwned? homepage. Locate the prominent input field labeled 'email address or phone number' and enter the specific email you wish to check. Click the 'pwned?' button to initiate the search against the breach database
External signals
Reviews & reputation
Aggregated review score
Highly regarded as an essential public service in cybersecurity, HIBP is praised for its reliability, extensive breach database, and straightforward interface. It's a critical tool for individuals and organizations to quickly assess credential exposure and take proactive security measures.
Quick answers
Frequently asked questions
1How does HIBP acquire its breach data, and how current is it?⌄
HIBP aggregates data from publicly disclosed breaches, paste sites, and information shared by law enforcement and security researchers. The database is continuously updated as new breach data becomes available, often within hours or days of public disclosure, ensuring a highly current assessment.
2Is it safe to enter my email address on HIBP? What about privacy?⌄
Yes, it is safe. HIBP is a trusted service run by Troy Hunt. Your email address is not stored or logged for any purpose beyond the immediate query. The site uses HTTPS, and the query itself is designed to only return a binary 'pwned/not pwned' status or a list of breaches, without exposing your email to third parties.
3Can HIBP tell me *which* specific password was compromised?⌄
No, HIBP does not store or display actual passwords. When an email is found in a breach, it indicates that a password *associated* with that email was part of the compromise. The 'Pwned Passwords' service allows you to check if a *specific* password (hashed) has appeared in breaches, but it never reveals the plaintext password.
4What should I do if my email address is found in a breach?⌄
Immediately change your password for all accounts associated with that email address, especially for the services listed in the breach. If you've reused that password on other sites, change it there too. Enable multi-factor authentication (MFA) wherever possible, and be vigilant for phishing attempts targeting that email.
5Does HIBP offer an API for developers or businesses?⌄
Yes, HIBP provides a public API that allows developers and organizations to programmatically query email addresses, phone numbers, and password hashes against the breach database. This enables integration into custom applications, security tools, and internal systems for automated breach detection and monitoring.
Keep exploring
