Tool · Anonymous lookup
Is your password in a breach?
Millions of passwords circulate in public lists because of other people's security failures. Check whether yours is one of them without ever sending it.
Only 5 characters travel

This tool needs the internet. The normal auditor stays inside your browser.
Your password becomes a hash. Only 5 hash characters are sent; the rest is compared here.
How to look something up without saying what you are looking for
There is a fair question here: if I want to know whether my password is in a list, don't I have to send it so they can search? The answer is no, and the mechanism that prevents it is called k-anonymity.
It works in four steps, all but one inside your browser:
- Your browser computes a hash of the password: a 40-character digest that cannot be reversed.
- Only the first five characters of that hash are sent.
- The server returns every hash in its database beginning with those five characters. Usually several hundred.
- Your browser looks for yours inside that list, locally.
The server receives a fragment matching hundreds of different passwords, so it cannot know which one was yours. And since it never receives the complete hash, it cannot try to crack it either.
If you ever find a site asking for the whole password to check whether it has leaked, close it. There is no way to know what it does with it.
What each result means
It appears. That password is in lists used daily in automated attacks. It does not mean anyone has entered your accounts: it means that if you have it set anywhere, getting in is a matter of your turn coming up in the queue. Change it today, everywhere you use it.
It does not appear. Good sign, with an honest caveat: breach databases collect the known incidents, and some are never published. Not appearing does not certify that it is secure; it only rules out the most urgent problem.
Either way, two questions remain that this tool does not answer: whether the password is hard enough to guess — that is what thestrength checker measures — and whether you are reusing it across sites, which is what really decides the outcome.
Why a leaked password cannot be patched
The most common mistake on discovering a breach is changing Madrid2024 toMadrid2025. Attack tools automatically generate variants of every leaked password: incremented numbers, symbols appended, letters swapped. That "new" password gets tried in the first few attempts.
The replacement has to be completely different and, ideally, randomly generated.
How to find out sooner next time
- Turn on your browser or manager alerts. They compare your saved keys against breach lists continuously and warn you on their own.
- Use email aliases for minor sign-ups: when one starts receiving spam, you know exactly which service lost your data.
- Turn on two-factor authentication for email and banking. It turns a leaked password into a scare rather than a loss.
Frequently asked
Common questions
Is my password sent to a server?
No. Your browser computes a SHA-1 hash of the password and sends only the first five characters of that hash. The server returns every hash starting with those five characters — hundreds of them — and the final comparison happens on your machine.
What is k-anonymity?
It is the technique that lets you query a database without revealing what you are looking for. By sending only a fragment of the hash, the query matches hundreds of possible passwords, so the server cannot tell which one interested you.
My password appears in breaches. What does that mean?
That this exact combination of characters sits in public lists attackers use daily. It does not mean anyone has entered your accounts, but it does mean the password is finished and must be changed everywhere you use it.
It does not appear. Is it safe then?
It means it is not in the known breaches, which is not the same as all of them. Some breaches are never made public. Not appearing is a good sign, not a certificate.
Where to go next