Search for exposure, not a diagnosis
Have I Been Pwned, commonly shortened to HIBP, collects information about known breaches. A result means an address appears in that dataset; it does not prove an attacker is currently signed in. A negative result does not prove that every account is safe.
Use the free individual email-address lookup. Bulk domain monitoring and API products have separate rules and may have costs, so they are outside this workflow.
Check and interpret a result
- Type https://haveibeenpwned.com into your browser yourself. Check the spelling before entering your address.
- Search your own address. Do not enter a password into an email-search field or a site claiming it can retrieve your leaked password.
- Read the affected service, breach date and categories of exposed information. Email addresses alone call for different action from passwords or identity documents.
- Make a short action list: affected service, password changed, reused passwords replaced, MFA checked, suspicious activity reviewed.
For example, if an old forum leaked a password you also used for email, change the email password immediately from a trusted device. Replacing only the forum password leaves the more important account exposed.
Secure the affected account
Open the service directly, set a unique password and inspect recent sign-ins, recovery details and connected apps. Revoke unfamiliar access using the provider's controls. If personal information was exposed, expect more believable scams that quote it. Correct personal details in a message are not proof that the sender is legitimate.
Verify your work
Test the new sign-in and recovery method. Store the new credential in your password manager. Check related accounts where the old password was reused. Record actions without putting the old or new password in a spreadsheet.
Common mistakes
Searching repeatedly will not remove historical exposure. Breach dates may differ from the date HIBP added the record. A result for a service you do not recognise needs investigation: it may involve an acquired company, recycled data or an account you forgot.
Privacy and limitations
An email lookup sends the address to an external service. Decide whether that is appropriate for your situation. Some sensitive breaches require owner verification; public searches are intentionally incomplete. Use this as one signal alongside provider alerts and activity logs, never as a complete account-security audit.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.