PRIVACY & SAFETY CENTER

How to Check Whether Your Email Was Exposed in a Data Breach

Learn how to check whether your email address appears in known data breaches, understand what the results mean, and take practical steps to protect your accounts.

What Is a Data Breach?

A data breach happens when information held by a company, website, or organization is accessed or exposed without authorization.

Depending on the breach, exposed information could include your email address, username, password, phone number, address, date of birth, or other personal information.

Finding your email address in a breach does not automatically mean someone has access to your email account. It means information associated with that email address appeared in a known breach.

What matters next is understanding what information was exposed and taking the appropriate steps to protect yourself.

Step 1 — Check Your Email With Have I Been Pwned

One useful place to start is Have I Been Pwned, commonly called HIBP.

Check your email with Have I Been Pwned

Enter the email address you want to check and select Check.

HIBP will compare the address against data from breaches contained in its database. If the address appears in one or more breaches, review the results to see which organizations were involved and what types of information may have been exposed.

Important: Digital Family Shield does not need your email password to perform this type of check. Never enter your email password into an unfamiliar breach-checking website.

Step 2 — Review What Was Exposed

Don’t stop when you see that your email was found.

Review the breach information and determine what data was exposed.

For example, exposure involving only an email address may require different action than a breach involving an email address and password.

Pay particular attention if the breach involved passwords or other sensitive personal information.

A breach record is also historical. Changing your password does not remove the historical record showing that the email address appeared in that breach.

Step 3 — Change Passwords When Necessary

If a breach exposed your password, change the password for that account.

If you used the same or a similar password on another account, change it there too.

Each important account should have its own strong, unique password. A password manager can make this much easier because you don’t have to remember every password yourself.

The FTC specifically recommends changing a password if a company reports that it was exposed and changing reused or similar passwords on other services as well.

Step 4 — Turn On Multi-Factor Authentication (MFA)

A password shouldn’t be your account’s only protection.

Multi-factor authentication—also called MFA, two-factor authentication, 2FA, or two-step verification—requires another method of verification in addition to your password.

Depending on the account, that could be an authenticator app, security key, passkey, approval prompt, text message, or another method.

If your account offers several choices, stronger methods such as an authenticator app or security key are generally preferable to receiving codes only through text or email. The FTC notes that text/email one-time codes are less secure than authenticator apps or security keys when those stronger options are available.

Where do I turn MFA on?

For most services, sign into your account and look for an area named:

Security → Sign-In Security → Account Security → Two-Step Verification → Two-Factor Authentication

Microsoft, Google, Apple, and other major providers each have their own setup process.

Digital Family Shield is preparing a separate step-by-step guide showing beginners exactly how to set up MFA on Microsoft, Google, Apple, and other common accounts.

Never give another person your MFA verification code, approval prompt, backup code, or account-recovery code.

Also make sure the recovery email address and phone number on your accounts are current. The FTC specifically recommends checking account recovery information after an account compromise.

Step 5 — Check Your Email Account for Suspicious Activity

If you believe your email account itself may have been accessed, look for signs you don’t recognize.

Check for unfamiliar sign-ins or devices, password or recovery-information changes you didn’t make, messages you didn’t send, deleted messages you don’t recognize, and email-forwarding rules you didn’t create.

An attacker who gains access to an email account may create a forwarding rule so copies of incoming messages are silently sent somewhere else. The FTC specifically recommends checking for unauthorized forwarding rules after recovering a compromised email account.

If you believe someone accessed the account, change the password, sign out other sessions or devices when your provider allows it, enable MFA, and review your recovery information.

What If Have I Been Pwned Says “No Pwnage Found”?

That’s a good result—but don’t interpret it as a guarantee that your email address has never been exposed.

HIBP describes this result as meaning the email address wasn’t found in the data breaches loaded into Have I Been Pwned. Some sensitive breach information also isn’t returned through a normal public email search.

Continue using strong, unique passwords and MFA even when your email doesn’t appear in the results.

Get Notified About Future Breaches

HIBP also provides free breach notifications.

You enter your email address, verify ownership through a message sent to that address, and HIBP can notify you if the address later appears in newly added breach data.

Set up free HIBP breach notifications

This can be especially helpful because a breach involving one of your accounts might not become publicly known immediately.

What If Someone Is Already Using My Personal Information?

A breach and identity theft are not necessarily the same thing.

However, if you discover that someone is actually using your personal information, the Federal Trade Commission provides a recovery service that can help you report identity theft and create a personalized recovery plan.

Visit IdentityTheft.gov

Quick Checklist

If your email appears in a breach:

☐ Review which company or service was breached.

☐ Check what type of information was exposed.

☐ Change an exposed password.

☐ Change that password anywhere else you reused it.

☐ Use strong, unique passwords for important accounts.

☐ Turn on MFA or 2FA.

☐ Check your email account’s recovery information.

☐ Look for unfamiliar logins, forwarding rules, or messages.

☐ Consider enabling future breach notifications.

☐ If someone is using your identity, visit IdentityTheft.gov.

Digital Family Shield Tip

Your email account deserves extra protection because many of your other accounts use email for password resets.

Someone who gains control of your email may be able to request password-reset links for your other accounts. That’s one reason the FTC emphasizes protecting email with a strong password and two-factor authentication.

Checking for breaches is useful, but it’s only one part of protecting your digital identity. Strong unique passwords, MFA, updated recovery information, and periodic exposure checks work together to reduce your risk.


Privacy reminder: Only use reputable services when checking personal information. Never enter passwords, MFA codes, Social Security numbers, financial account numbers, or account-recovery codes into an unfamiliar breach-checking website.

General information: This guide provides general educational information and is not legal, financial, or credit advice. Third-party services and their procedures can change; use the linked official sources for current information.

Keep control of your information. When a guide links to an outside service, review that service's privacy practices and enter personal information only when you are comfortable doing so.