Free tool · Runs entirely in your browser
Has this password already leaked?
Check it against billions of credentials exposed in real breaches. Your password never leaves this page; only a short hash prefix is sent. How it stays private is spelled out below.
Run the check
How this stays private
This tool uses the k-anonymity model of the Pwned Passwords API from Have I Been Pwned. When you click Check, your browser computes a SHA-1 hash of the password and sends only the first five characters of that hash to the service. The service returns every breached hash that shares those five characters (hundreds of them), and the match is completed locally, in your browser. Your actual password, and even its full hash, never leave this page. The service never learns which password you checked.
01
Your browser SHA-1 hashes the password.
02
Only the first 5 hash characters are sent.
03
The match happens on your device.
What this checks, and what it doesn't
- Does tell you if this exact password string appears in known breach corpora.
- Doesn't check your email address or scan dark-web marketplaces for your accounts. That's a separate, deeper service.
- Doesn't mean a "0 results" password is strong, only that it hasn't been seen in these breaches yet.
Want a full dark-web credential scan for your whole domain?
Book the free assessment