Yes. I run AliasFleet, an email-alias service, and Have I Been Pwned is the first place I send anyone who suspects their address has leaked. It is safe to use, and the reasons are checkable: it stores no passwords next to your address, logs no searches, and its password checker never sees your password at all.
The hesitation makes sense. You just found your address in a breach dump, and now a website wants you to type it in again. That is exactly how the leak started, or so the instinct says. The difference is what the site keeps: a signup form keeps your address next to your name and your payment details, and HIBP keeps it next to a list of breaches. One of those is worth stealing. The other is the whole point of the site.
Who is behind it
Who runs Have I Been Pwned?
Troy Hunt, an Australian security researcher who has run the site since its launch on 4 December 2013. He is a Microsoft Regional Director, a title of recognition rather than employment, has testified before the US House Committee on Energy and Commerce in 2017, and wrote 47 security courses for Pluralsight.
The point is not the resume. It is that he is not anonymous. Nobody spends a decade building a public reputation, testifying to Congress, and putting their own name on the trademark as cover for a data grab. HIBP is a registered trademark of his company, Superlative Enterprises Pty Ltd, and his wife runs the operations side. There is a real business behind the box you type your address into, which is more than can be said for half the free breach checkers that turn up in search results.
The scale of who relies on it is part of the trust case. His own about page says more than half the Fortune 500 monitor domains through the service, dozens of national governments use it free of charge, and the FBI and Europol feed it compromised credentials from cybercrime investigations. A scam site does not get adopted by the people who arrest scammers.
What it does with your address
What does the site store about me?
The breached addresses sit in Azure table storage holding nothing more than the address or username and a list of the breach sites it appeared in. When email addresses from a breach are loaded, no corresponding passwords are loaded with them, and no password is stored next to any personal data. That is the site's own FAQ speaking.
Consider what that means in practice. A site built to tell you about stolen credentials deliberately refuses to hold the part that could hurt you. Every free breach checker that asks for your password alongside your email is doing the opposite of this.
Are my searches logged?
No. Searches are not logged and addresses are not collected; the only logging is analytics, performance monitoring, and error diagnostics, nothing more. Every search runs over an encrypted connection, so even in the worst case it is only an email address. Not enough to open anyone's accounts.
That last part is worth sitting with. An email address on its own unlocks nothing. Access needs the password, the session token, or the reset flow, and HIBP touches none of those.
If the very idea of your address sitting in the database bothers you, the site has an opt-out: it removes the address so no breach appears against it publicly. That is the opposite of a data trap, which would make leaving impossible.
Does the notification service keep my data?
Signing up for breach notifications is free: enter your address, click the verification link, and you get an email when the address turns up in a new breach. To track who to contact, the site stores only the address, the subscription date, and a random verification token, and it states plainly that it never shares your email with anyone else.
Two rules protect everyone else. The public search returns results for one address at a time, and the sensitive breaches stay hidden unless you verify the address is yours. You cannot sign someone else's address up for alerts either. Notifications go to the monitored address, nowhere else.
The password checker
How does the Pwned Passwords check keep my password private?
It uses k-anonymity. Your password is hashed with SHA-1 on your own device, and only the first 5 characters of that hash are sent to the service. It returns every matching hash suffix, and the full comparison happens on your side. The complete password, and even its complete hash, never leaves your device.
The Pwned Passwords page documents this openly and notes that NIST recommends checking passwords against breached datasets. The service itself is free and open source, and its database records only that a password has been seen before and how many times, never who it belonged to. The verdict is blunt. If your password shows up, it has appeared in a breach and should never be used again, and if you have ever used it anywhere, change it immediately. The check stays anonymous the other way too: searching for your email and a password together never hands the service a usable credential pair.
You can watch the whole exchange happen in your browser's dev tools if you run a check there. That is a rare kind of honest: a security feature that lets you audit it live.
The rest of the site
What is the domain search?
It lets an organisation check every address on a domain it owns, after proving ownership. Sign in, add the domain, verify control. Only then do results show. It exists because a company with 500 addresses cannot check them one by one.
Larger domains need a subscription for results, though some breaches are flagged subscription-free. The domain search now sits behind a sign-in, which is the right place for it.
Is it really free?
The checks that matter to you are. The email search, the password check, and the notifications cost nothing; Troy built the site as a free resource and says so on the about page. Paid tiers exist for heavy API use and large domain searches.
As of today the service lists 1,039 breached websites and 17.8 billion compromised addresses, according to the counter on its own homepage.
What it cannot promise
Are there breaches it will not show me?
Eighty-nine breaches are sensitive: they only appear for the verified owner of the address. Some are flagged unverified or fabricated when legitimacy cannot be established, and two have been retired. As the FAQ puts it, absence of evidence is not evidence of absence. A clean result rules out the known breaches. Nothing more.
One more limit that is actually reassuring: when your address shows up in a paste, HIBP stores the metadata, the date, title, and author, but not the paste itself. If the original is gone, there is nothing left to display.
One more honest admission. HIBP indexes new pastes within about 40 seconds of them appearing, but a fresh breach still has to be found, verified, and loaded before it shows up. If your address leaked last week, the site may not know yet. I do not know which of your signups will land there next, and neither does anyone. Check it, turn on the notifications, and move on to the part you control.
The part that matters more than the check
What should I do with what it finds?
Start with the passwords. Change the breached site's, then every other place you reused it, because the credential-stuffing runs start within days. A password manager turns forty resets into a twenty-minute job. Expect phishing that quotes the breach back at you; the dump is the raw material for it, and our breach response guide is the full order of operations.
The phishing deserves one more line. The classic is the extortion email: your real leaked password, a demand for payment. The password is real, but the threat is a bluff. Delete it, and do not engage.
Then fix the future. No check reaches back in time, so every site you sign up for tomorrow gets its own alias: one address per site, and the next breach exposes an address that belongs to that site alone. When spam or phishing lands on it, pause the alias and the leak dies there. The setup guide takes a few minutes, the free tier covers 10 aliases, and the docs explain how the forwarding works. Our leak-tracing guide explains how the To field names the source, and this honest answer covers where addresses actually go once you hand them out.
I have run my own address through HIBP more than once. The list was never short. That is exactly why the safety question is the wrong one to linger on. Check the site, then work on the part you control: what every site gets from you next.
Run the check and turn on the notifications, then change every password that needs it. Then start handing out addresses you can pause, and the next breach notice becomes a five-second fix instead of a bad week.
Top comments (0)