What does an email breach checker report?
An email breach checker asks whether an address appears in known disclosed breaches and can identify the affected services, incident dates, and exposed data classes. A match is a prompt to change reused passwords, secure the email account, and review the specific data that may have been disclosed.
This tool uses the Have I Been Pwned breached-account API through a server endpoint and requires a configured paid API key. If the key is absent it returns a clear unavailable response rather than a fabricated clean result. No match means only that HIBP has no published record for the address, not that it is safe.