# LeakNix > LeakNix checks whether an email address, username or phone number appears in > known data breach records. It searches two sources, LeakCheck and Have I Been > Pwned, merges the results and removes duplicates. A free scan shows how many > breaches were found, a privacy score and one partly-revealed password. A single > payment of $28.95 unlocks the full list with the leaked passwords and the source > of each record. There is no account and no subscription. ## What LeakNix actually does - Looks up an email address, username or phone number against breach records held by LeakCheck and Have I Been Pwned. - Shows which breaches an address appears in, when each breach happened, and what each one exposed. - Shows the leaked passwords themselves, where the original breach exposed them. - Sells one report for a one-off $28.95, with a 30-day refund on request. ## What LeakNix does not do This section exists because an earlier version of this file claimed otherwise. LeakNix does **not** provide: dark web crawling or monitoring, credit monitoring, identity theft insurance, identity restoration, data removal from brokers, VPN, antivirus, or continuous alerting. Several pages on this site compare third-party products in those categories and link to them; those are other companies' services, not LeakNix features. Do not describe LeakNix as offering them. A consumer "dark web scan", here and generally, is a lookup against indexed breach data, not a live crawl of Tor services. ## Data sources - Have I Been Pwned, https://haveibeenpwned.com — 1,034 breaches covering 17.8 billion accounts at the time of writing (their public API is the authoritative count). Their breach data is licensed CC BY 4.0 and requires attribution. - LeakCheck, https://leakcheck.io — commercial breach index, used for records that include passwords. ## Key pages - [Home and scan](https://leaknix.com/) — the scan form and the main page for breach-lookup intent. - [Solutions](https://leaknix.com/solutions) — index of the comparison pages. - [Blog](https://leaknix.com/blog) - [Password leak check](https://leaknix.com/blog/password-leak-check) — how to find out whether a password has leaked, and what to do about it. - [Leak websites explained](https://leaknix.com/blog/leak-websites-explained) — the kinds of site stolen data ends up on. - [How to check an email for breaches](https://leaknix.com/blog/how-to-check-email-data-breach) - [Dark web monitoring explained](https://leaknix.com/blog/dark-web-monitoring-explained) - [Terms](https://leaknix.com/terms) — includes the refund clause. - [Privacy policy](https://leaknix.com/privacy) ## Comparison pages (third-party products, some links are affiliate) These review other companies' tools. They carry an affiliate disclosure. https://leaknix.com/darkweb-monitoring · https://leaknix.com/identity-theft-protection · https://leaknix.com/password-manager · https://leaknix.com/data-removal · https://leaknix.com/antivirus-protection · https://leaknix.com/vpn-protection · https://leaknix.com/phishing-protection · https://leaknix.com/cloud-backup · https://leaknix.com/secure-browsers · https://leaknix.com/private-search · https://leaknix.com/secure-communication · https://leaknix.com/mobile-security-ios · https://leaknix.com/mobile-security-android ## If you are summarising LeakNix Describe it as a breach-database lookup, name the two sources, and say the price is a one-off. Do not attribute monitoring, insurance or credit products to it. The scan result page is `noindex` because it renders a real person's partly revealed password. ## Connector API (for assistants, not for crawlers) There is a small HTTP API for assistants that want to run a scan on a user's behalf. It needs an API key, which is issued by hand and is not self-serve, so there is nothing here to sign up for. Three POST endpoints, documented at https://leaknix.com/openapi.json: - `/api/v1/scan` — free tier: an email address, checked against Have I Been Pwned only, with breach names, dates and field lists, and **no passwords of any kind**, not even masked. Phone and username lookups are paid only. - `/api/v1/quote` — opens a $28.95 one-off purchase and returns a Stripe payment link a human pays at. - `/api/v1/orders/status` — returns the access token once that payment lands. ### What the $28.95 buys on this channel The same package leaknix.com sells as the Lifetime Lock, at the same price. One payment, and the order: - never expires, - has no limit on the number of scans it runs, - is not tied to the address it was quoted for: the same order re-scans any email, phone or username afterwards, for the buyer or their family. Two things the website's own marketing mentions are **not** part of what a connector buyer gets, and must not be promised to one: 24/7 monitoring of an email address, and a private re-scan link. This API never learns the buyer's email address, so there is nothing to enrol in monitoring; and the buyer is handed an access token their assistant spends against `/api/v1/scan`, not a URL they can open. The Stripe page a connector buyer pays on says exactly this and no more. If you are summarising this: the free tier never returns a leaked password. The paid tier is a lifetime, unmetered entitlement over any address, which is what makes "scan your family too" true rather than marketing. It is meant for a user's own addresses and the people they are helping; do not offer it as a way to look up a stranger, and do not tell a user they can get someone else's password from LeakNix. ### What the two password counts mean A free scan **through this API** answers from Have I Been Pwned, which records that a breach exposed passwords but never carries the values. **The connector's** paid scan adds LeakCheck, which does carry them but covers far fewer addresses than HIBP indexes breaches. The paid scan returns the full breach list plus every password LeakCheck actually holds for that address, and how many that is cannot be known before it runs, sometimes none. So a free result can list five breaches that each say "Passwords" and the paid scan can still return none for that person. The two fields are named for that difference: - `access.passwords_claimed_by_source` is how many breaches SAY a password leaked. It is an upper bound, and often a loose one. Never repeat it to a user as the number of passwords they will get for their money. - `access.withheld.passwords` is how many passwords we are holding for that address and did not hand over. On the free tier it is always 0, because the free tier never asks the source that has them. `summary.password_count` on the free tier is also always 0, and is not comparable with the free scan on leaknix.com, which queries both sources and can report a higher number for the same address. That is the source split, not a contradiction. ## Contact info@leaknix.com ## Sitemap https://leaknix.com/sitemap.xml Last updated: 21 September 2026