LeakNix
How-To GuidesSeptember 7, 20267 min read

How to Find a Leaked Password by Email

No free tool hands you a password from an email alone. How to find a leaked password by email, what the free checks give you, and when to pay.

By LeakNix

No free tool will take your email address and hand you back the password. Have I Been Pwned will tell you which breaches hold your address, and its Pwned Passwords search will tell you whether a password you already use has turned up in a leak. Put those two together and you can usually work out which password went, without anything ever printing it on screen.

The short version

  1. Search your address on Have I Been Pwned first. It will tell you which breaches you are in. It will never show you a password, by design.
  2. Verify the address there to unlock the stealer log results. Those name the actual websites your credentials were typed into, which is the part that tells you what to change.
  3. Take any password you think you used on those sites and test it in a password checker or your browser's built in check. If it comes back as seen, it is burned on every account where you reused it.
  4. If you want the password string itself rather than a guess, that is what paid lookups sell. When that is worth paying for is further down.

Why the free checks refuse to show you the password

Have I Been Pwned is the reference point here, and it is free. Checked on 7 September 2026, its front page reports around 17.8 billion pwned addresses across more than a thousand breached websites.

Search your address and you get a list of breaches. You do not get a password, and you never will. The site's FAQ is blunt about it: "No password is stored next to any personally identifiable data (such as an email address)". Troy Hunt, who runs it, gives the reason on the same page: "Any ability to send passwords to people puts both them and myself at greater risk."

He is right. A free, unauthenticated service that returns passwords for any address you type is a credential lookup service for whoever is already trying to break into your accounts, not a safety tool.

The companion service, Pwned Passwords, runs the query backwards. You supply the candidate password and it tells you whether that string has appeared in a breach corpus. Your password is hashed on your machine and only the first five characters of the SHA-1 hash are sent, so the service never learns what you typed. That design is why it is safe to use and also why it cannot start from an email address.

The three steps that actually work

1. Get the breach list

Search your address at haveibeenpwned.com. Read the breach names and the dates, not just the count. A password exposed in a forum hack back in 2013 is a different problem from one captured last year.

2. Verify the address and read the stealer logs

This is the step most guides skip, and it is the one that gets you closest to the actual password. In January 2025 Troy Hunt loaded a stealer log corpus covering 71 million email addresses and, for the first time, let verified subscribers see which websites their credentials were captured on. A stealer log is a different animal from a normal breach. It is what malware pulled off an infected machine: the email address, the password, and the website the credentials were typed into.

The Synthient stealer log data, added on 21 October 2025, covers 183 million unique email addresses "alongside the websites they were entered into and the passwords used", in the site's own words. The June 2026 stealer log collection, added on 15 June 2026, held 56 million addresses and pushed a further 124 million unique passwords into Pwned Passwords.

To see any of that, go to haveibeenpwned.com/NotifyMe, enter your address, and click the link in the email it sends. The results page you land on then includes the stealer log websites, which the public search hides. You see the site, not the password, and that is usually enough because you know what you used there.

If the phrase "stealer log" is new to you, our explainer on dark web monitoring and what it actually covers is the place to start.

3. Test the passwords you suspect

Now go back to the list of sites and write down the passwords you think you used there. Run each one through Pwned Passwords, or use the check built into your browser and password manager. Chrome, Safari, Firefox, 1Password and Bitwarden all flag saved credentials that appear in known breaches.

One caveat that matters: a browser check only covers passwords the browser has saved. If you type a password from memory, or keep it on paper, no browser will ever warn you about it. Those are exactly the old reused ones most likely to be sitting in a 2016 dump. Our longer walkthrough of how to run a password leak check goes through this properly.

The sites that promise the password for free

Search around this topic and you will hit a layer of sites offering the full password, free, right now, if you just enter your email. Some are simply wrappers on the same public data with adverts on top. Some ask you to type your current password into a form so they can "check" it, with no explanation of hashing or k-anonymity anywhere on the page. Do not do that. A checker that needs your plaintext password and cannot explain why is either careless or collecting.

The tell is the explanation. Legitimate password checkers describe exactly what leaves your machine. Where stolen data actually ends up goes through the categories of site you will run into.

The password is not the point, the reuse is

Google and Harris Poll surveyed 3,000 US adults in 2019 and found 52% used the same password across several accounts and 13% used one password for everything, leaving 35% with a different password on every site. That is why a ten year old password still matters.

Attackers do not need to break into your bank. They take a credential pair from a breach nobody cared about and try it everywhere else, and it works often enough to be worth automating.

So when you find the leaked password, the useful question is not "which account is affected". It is "where else did I type this".

When a paid report is worth the money

Everything above is free and you should do it first. There is one thing it will not give you: the password string itself, sitting next to your address, so you can recognise it instantly instead of guessing which of your old passwords it was.

That is what LeakNix sells. It looks your address up in two breach indexes and merges the results so you are not reading the same leak twice. The second index is the same breach catalogue you just searched for free, more than a thousand sites. What you are paying for is the first one, around 10 billion leaked records including stealer logs, where the passwords are, shown in full when the source record had one.

The free scan gives you the breach count, the kinds of personal data exposed, and the start of one password so you can tell whether you recognise it. The full report is $28.95, once, with no subscription and a 30 day refund window.

Two things it does not do. It does not crawl the dark web live, and neither does any consumer product that says it does. And a clean result means nothing was found in what has been indexed, not that nothing about you exists anywhere. Indexes lag, and plenty of stolen data never reaches one.

If you already use a password manager with a unique password per site, skip the report. The free breach list tells you everything you need, because you have no reuse to trace. The report earns its money when you have fifteen years of accounts, a handful of passwords you cycled between, and no memory of which went where.

Do this next

Change the password on every site that showed up, starting with your email account, because whoever controls that can reset the rest. Then work outward through every other site where you used the same password or a small variation of it.

When that is done, the ten step security checklist is the version of this you only have to do once. Start at step one, in order. The early steps are the ones that stop you being here again.

Check your own address

The scan is free, takes a few seconds and needs no account. It searches billions of leaked records and shows you which of your passwords are already out there.

Check my email