Has your password been leaked?
Criminals don't guess passwords letter by letter; they replay the billion-plus passwords already exposed in data breaches. Find out in one second whether yours is on that list.
How this stays private: your password is scrambled into a cryptographic fingerprint (SHA-1 hash) inside your browser, and only the first 5 characters of that fingerprint are sent to the breach database (Have I Been Pwned's k-anonymity API). That prefix matches hundreds of different passwords, so the service can't know which one you checked, and the password itself never leaves your device. Nothing is stored anywhere.
Why breached passwords matter more than "strong" ones
Attackers take the giant lists of passwords leaked from hacked websites and try them against everything: your email, your bank, your work accounts. This is called credential stuffing, and it works because most people reuse passwords. A password that looks strong but appears in a breach list is effectively public knowledge.
The fixes are unglamorous and effective: use a different password for every account (a password manager makes this effortless), make them long, and turn on two-factor authentication for anything important. Do those three things and password leaks mostly stop being your problem.
More free checks
Can your business be spoofed? Check any domain's email security in ten seconds.
Is this email fake? Paste a suspicious email's headers for a plain-English verdict.