Breach Lookup
Breach Lookup checks a single email address or domain against known breach data on demand, returning one card per breach the address appears in. Use it to investigate a specific account, or as the follow-up when an address turns up in a tenant-wide search.
Nothing on this page is tenant-scoped. Any address or domain can be checked, whether or not it belongs to a tenant you manage.
This page is in beta and may not always give expected results.
Breach Lookup
Enter an Email address or domain name and select Check.
The two inputs are answered differently. An address containing @ is checked against Have I Been Pwned directly and returns the full breach record for each breach the account appears in. A bare domain is checked against CIPP's breach service instead, which returns the breaches associated with that domain.
Results
Where breaches are found, each one is shown as its own card headed with the breach name and the breached service's logo. An export button above the results downloads the full set as a CSV.
Partial Password Available
Whether the breach data includes a password for this account. Where one is available, a copy button places it on the clipboard without displaying it on screen.
Description
The breach's published description, explaining what happened and when.
Domain
The domain of the breached service, linked so you can read more about it.
Leaked Data classes
The categories of information exposed in the breach, such as email addresses, passwords, or physical addresses. Each is shown as its own chip.
Breach Information
Chips describing the nature of the breach, such as whether it is verified, sensitive, fabricated, retired, a spam list, sourced from malware, or drawn from a stealer log. Only the characteristics that apply are shown, so a card with few chips is not missing information.
Where nothing is found, a No breaches detected card is shown in place of the results. This is a genuine answer rather than a failure: an account with no breach history returns no results.
Where the lookup could not be completed, an Error card reports that the connection to the breach service failed, along with the underlying error where one was returned.
Feature Requests / Ideas
We value your feedback and ideas. Please raise any feature requests on GitHub.
Last updated
Was this helpful?

