LeakNix
How-To GuidesOctober 9, 2026•9 min read

Email Security Check: What It Can and Can't Tell You

An email security check has two halves: breach exposure and account control. Do both yourself in five minutes, and learn how to read the result.

By LeakNix

An email security check is two things wearing one name. The first is whether your address, and the password attached to it, has turned up in a known data breach. The second is whether anyone other than you can get into the mailbox right now. Lock the mailbox first, then check the breach index. You can do both yourself, today.

The short version

  1. Lock the mailbox before you research the breach. Your provider's security page shows recent sign-ins and recovery details in one place.
  2. Check the recovery phone and recovery email before you touch the password. If an attacker changed those, a new password buys you nothing, because the reset flow still goes to them.
  3. Then look at forwarding and filter rules. That is where someone who already had access leaves themselves a way to keep reading your mail.
  4. Then check the address against a free breach index. The LeakNix free check does this with no account and tells you whether your address turned up in a known breach.

Exposure is history and you cannot change it. Control is five minutes of work, so start there.

Exposure and control are different problems

Exposure means your address, and sometimes a password next to it, sits in a file that has been traded or dumped on a forum. That file might be from 2013. The password might be in plain text or it might be a hash somebody cracked later. Exposure is historical. You cannot undo it, and nobody can delete it for you.

Control means who can log into the mailbox today. That is not historical, and it is fixable in about five minutes.

The two connect in one specific way. If a password from an old breach is still in use on your email account, historical exposure becomes a live control problem. That is the whole mechanism behind credential stuffing: take a list of address and password pairs from an old breach, throw them at a login page, keep the ones that work. It is cheap, it is automated, and it works because people reuse passwords.

So an honest email security check works backwards from the damage. Lock the mailbox, then find out what is already out there.

The five-minute self-check, in order

Do these in the order printed. Each step assumes the one before it is done. Provider menus move, so if a label below has changed, search your provider's help for the phrase in quotes.

1. Recent activity

Every major provider shows recent sign-ins with a rough location and device. Start at Google's Security Checkup, Microsoft account security or Yahoo account security. Ignore the city. It is derived from your IP address, which resolves to wherever your ISP routes traffic, so a normal sign-in from your own sofa routinely shows a city you have never visited. Look instead for device types you do not own and sessions you cannot place at all.

2. Recovery phone and recovery email

If an attacker changed these, they own the account even after you change the password, because every reset you run lands in their hands. Remove anything you do not recognise, and make sure the recovery address is one you can still open. This is step two for a reason. Changing the password first, with a hostile reset path still attached, just tells the attacker you noticed.

3. Forwarding and filters

In Gmail, that is Settings, then "Forwarding and POP/IMAP", then separately "Filters and Blocked Addresses". Check both. A filter that forwards anything containing the word "invoice" or "bank" to an unfamiliar address, or that marks those messages as read and archives them, is the signature of someone who had access and wanted it to stay useful. In Outlook, the equivalent lives under Settings, Mail, Forwarding, and Settings, Mail, Rules.

If you find a rule you did not make, work through this list without stopping:

  • Note the address the rule was sending to, then delete the rule.
  • Evict the other devices. In Google, open myaccount.google.com/device-activity and sign out each device you do not recognise, one at a time. The "Sign out of all other Gmail web sessions" link at the bottom of the inbox is not enough on its own: as the label says, it ends web sessions, so a phone holding a saved token keeps syncing your mail. In Microsoft, use the Devices page and sign the device out there. The sign-in activity page is a log, not a control, and reading it evicts nobody.
  • Change the mailbox password to something you have never used anywhere else.
  • Revoke app passwords and connected apps, all of them if you are unsure.
  • Read your Sent and Trash folders. That tells you what went out in your name, and which of your other accounts may have had a reset run against them.

4. Connected apps and app passwords

Old app passwords bypass two-factor authentication by design. If you set one up for a mail client in 2019 and stopped using that client, it is still a working key. In Google, delete them at myaccount.google.com/apppasswords and review third-party access at myaccount.google.com/connections. In Microsoft, app passwords are under Security, then Advanced security options; connected apps are under Privacy, then Apps and services that can access your data. Remove anything you cannot name a current use for.

5. Two-factor authentication

An app code or a passkey beats SMS, because SMS can be redirected by a SIM swap. But SMS is far better than nothing. Google, NYU and the University of California San Diego published joint research in May 2019 finding that an SMS code on the account blocked 100% of automated bot attacks, 96% of bulk phishing attacks and 76% of targeted attacks. If the choice is SMS today or an authenticator app at the weekend, take SMS today. This is the step that breaks credential stuffing, because a password from a 2014 dump stops being enough on its own.

That is the control half done, and none of it cost anything.

Reading the exposure half without panicking

Run the address through a breach index. The LeakNix free check takes a few seconds, needs no account, and tells you whether your address has turned up in a known breach. It draws on Have I Been Pwned among its sources, so you are not giving anything up by starting here.

Two things to know about whatever result comes back.

A clean result means nothing was found in what has been indexed. It does not mean nothing exists. Breach data reaches public indexes slowly and unevenly. Plenty of breaches are never disclosed at all. Others get sold privately for years before a copy leaks wide enough to be parsed, and when a dump does get indexed it is often only a subset of the records. "Not found" is a real data point, but it is a statement about the index, not about the world.

A hit on an old breach is not an emergency by itself. If your address appeared in a 2016 forum breach, ask a narrower question: was a password included, and do you still use that password anywhere? If the answer to the second part is no, you are looking at a historical footnote. If it is yes, that is the thing to fix this afternoon.

How to read a hit, breach by breach, is in what a password leak check actually tells you.

"Is my email on the dark web?"

A dark web scan is a search over indexed breach data: collections that researchers and indexes have already obtained, parsed and made searchable. The question to ask any checker is which indexes it searches and whether it shows you the password itself, because that is the detail that tells you whether an old breach is still a live problem.

That matters for what you should expect. When a monitoring product alerts you that "your data was found on the dark web", it is telling you your address turned up in a dataset that reached its index, possibly years after the breach happened. It is a record of the past, not a warning about the present. Dark web monitoring, explained without the marketing goes through what those alerts are actually derived from.

One thing genuinely cannot be bought: nothing removes your data from a breach. Once a file has been copied and traded it exists in an unknown number of places, so any service promising deletion of breached data is describing something that cannot be done. Data brokers and breaches are separate pipelines too, and paying a personal info removal service to file broker opt-outs does not touch breach data at all.

When a paid report earns its money

Free checkers tell you which breach. They will not show you the password, and that is the right call, because an anonymous query about somebody else's address should never hand back that person's credentials.

What changes is who the password is shown to. LeakNix releases it to the owner of the mailbox. Before any report goes out, we send a confirmation link to the address you entered, so a report can only be pulled by somebody who can open that inbox.

Then we look the address up in two breach indexes and merge them, so you are not cross-referencing two sites by hand. One is Have I Been Pwned, which tells us which breaches the address appears in. The second carries the credential pairs, which is where the leaked password itself comes from. The full report shows that password and puts up to 5 addresses under real-time monitoring, for one payment of $28.95.

Seeing the actual string is what turns a vague worry into a finite task. You recognise it, and you know instantly which other accounts still use it or a close variant. It is a one-off report at $28.95 USD with nothing to cancel later. If both indexes come back empty for your address, the report says so and the refund is issued automatically to your original payment method. A thin result does not qualify, only a double empty.

Buy it if the free result was thin and you want to know which password was exposed, not just where. If you already know which old password was in that breach, you have the answer, and the next ten minutes are better spent changing it.

Start with the mailbox

Open your provider's security page and read the forwarding and filter rules. That takes about ninety seconds, and it is the check most likely to find somebody who is still there.

After that, work down the account cleanup checklist in order: email first, then anything that can move money, then everything else.

Check your own address

The scan is free, takes a few seconds and needs no account. It searches 500+ data breaches and shows you what was leaked.

Check my email