Use Have I Been Pwned’s official email lookup to see whether your address appears in the breach records loaded into the service. A match is a reason to review the breach details and secure affected accounts; a no-match is not proof the address has never been exposed.
Check your email address with Have I Been Pwned
- Open Have I Been Pwned and enter the email address you want to check in its email lookup.
- Review the result. A match is labeled “Oh no — pwned!” and shows breach history. A no-match may appear as “Good news — no pwnage found!”
- If a breach is listed, read its details and the data classes reported as exposed. Use those details to decide which accounts or personal information need attention.
What a match or no-match means
A match
A match means the address appears in breach data available to Have I Been Pwned. It does not, on its own, mean that anyone has accessed your current email account. The service says it stores email addresses with metadata about the types of data involved, not the actual compromised content. Password hashes are handled in a separate service. Read Have I Been Pwned’s explanation of its data.
No match
A no-match means the address was not found in the breaches loaded into the service. It cannot establish that the address has never appeared in a breach: the service does not claim complete coverage or guarantee that every breach is represented.
Secure accounts if a breach affects you
Focus on accounts that used the exposed address, particularly if a password may have been reused or the breach details indicate credentials were exposed. An inbox is especially important to protect because access to it can let someone use password-reset links to reach other accounts.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
- Change a compromised password to a strong, unique one. If you reused it elsewhere, change it on those accounts too.
- Sign out of all devices on an account you believe was compromised, then sign back in using the new password.
- Turn on two-factor authentication (2FA) wherever it is available, especially for your email account.
- Check that recovery email addresses and phone numbers are yours and up to date.
- Review email settings for forwarding rules you did not create.
These steps follow the Federal Trade Commission’s guidance for hacked email and social media accounts. A breach-list match alone does not mean every account needs a password change; prioritize accounts whose credentials were exposed or whose passwords you reused.
Use the API only if you need a programmatic check
For an ordinary personal check, use the web lookup. If you are building an application or otherwise querying the service programmatically, be aware of the privacy tradeoff described in Have I Been Pwned’s API documentation: a direct email query discloses the full address to the service. Its documented k-anonymity method instead sends a partial hash prefix, then checks returned suffixes locally. This is a technical alternative, not a required extra step for the consumer lookup.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Escalate if more sensitive identity data was exposed
If the breach details or a separate breach notice says that information such as your Social Security number was exposed, follow the FTC’s IdentityTheft.gov data-breach guidance. Depending on what was exposed, that may include ordering credit reports or considering a credit freeze or fraud alert. An email-address match by itself does not establish that these identity-theft measures are necessary.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




