Yorba
  • Privacy & Data

How to check if your email has been leaked on the dark web

October 5, 2026
Hero image
15 min read
Copy Link

Quick answer. A dark web scan checks your email address against a database of breaches that security researchers have already collected and indexed. You can run one for free, with no signup, using Yorba's Breach Beacon. The result tells you which companies lost your data and roughly when. It cannot remove anything, because nothing can. The useful work starts after the result, and that is the part this article spends most of its time on.

What does it mean if my email is on the dark web?

It means a company that held your email address lost control of it, and a copy is now circulating somewhere ordinary search engines do not reach. Depending on what the company stored, your address may be sitting next to a password, your name, a phone number, a home address or a date of birth.

It does not mean someone is targeting you. Breached databases are traded in bulk, by the million, and your row is one of them. If you have used the internet for more than a few years, the answer to "is my email on the dark web?" is almost certainly yes, at least once. The more useful question is which companies lost it, and whether they still have it.

How do dark web scans actually work?

The dark web has no index and no search box, so no consumer tool is crawling it for your address in real time.

When a company's customer database leaks, security researchers get hold of a copy, verify that it is real, and load it into a searchable index. A "scan" queries that index. The best-known public version is Have I Been Pwned, run by the security researcher Troy Hunt, which as of today lists 1,039 breached websites and 17,837,635,527 exposed addresses. Most other checkers, free or paid, draw on this kind of data. Some query Have I Been Pwned directly and some maintain their own corpus, but the mechanism is the same.

Have I Been Pwned's FAQ describes what the record means once you are in it: "The fact the email address was in the breach is an immutable historic fact." Changing your password afterwards does not alter it.

So a scan can tell you which known breaches include your address and approximately when each happened. It cannot tell you about a breach nobody has found yet, and it cannot pull anything back. Most of the bad advice on this subject comes from forgetting that second part.

How do I check if my email has been leaked?

Go to Breach Beacon, type in an email address, and press Check. It queries known data breach databases and shows you which breaches exposed that address. You can enter several addresses at once. There is no signup, nothing to install, and the data is encrypted and never shared.

Check every address you have ever used, not only the one you read today. That means the address from university, the work email from two jobs ago, the one you made for shopping, and the one that only receives newsletters. Older addresses usually have longer breach histories because they have had more years to be handed out.

Run Have I Been Pwned as well. It is free for individuals, and if you sign up for its notifications it will email you when your address turns up in a future breach. Use both.

Are free dark web scans accurate?

They are as accurate as the breach data behind them, which is the same data the paid services use.

Paid dark web monitoring sells alerting, which has real value if you would rather be told than remember to check. It does not sell access to a better list. There is no premium index of breaches that the free tools cannot see. You are paying for a notification and a dashboard.

Google found this out. Its dark web report, which it opened to every Google account in July 2024, stopped monitoring on 15 January 2026. Google's explanation: "While the report offered general information, feedback showed that it did not provide helpful next steps." Google now points people at Password Checkup and two-step verification instead.

That sentence describes the whole category. The scan is easy. Knowing what to do with the result is harder, and almost every tool leaves it to you.

What should I do if my email shows up in a breach?

Do these in this order. The reasoning for the order is in each step.

  1. Change your email account's password before you touch anything else. Your email is the recovery address for nearly everything you own, so it is the one credential that unlocks the rest. If that password is shared with any account on your breach list, assume it is already known.
  2. Turn on two-factor authentication for that email account. An authenticator app or a hardware key is stronger than a text message code, and a text message code is still far better than nothing.
  3. Now deal with the breached account. If you still use it, give it a unique password. If you reused the old one anywhere, change it there too. Leaked email and password pairs get fed into automated tools that try the same combination against hundreds of other sites, a technique called credential stuffing, and it is the main way one breach becomes several.
  4. Ask whether you need the account at all. The breach checkers skip this step, and it is the only one that changes your exposure going forward. The next two sections explain why.

Yorba has a longer version with timings in its checklist for the week after a data breach.

Does changing my password fix it?

It protects the account from being logged into with the old password. That is all it does.

Everything else that leaked is still in circulation: your name, the address you lived at, your phone number, and the fact that you were a customer of that company. The company is also still holding a live copy of your details for whenever it gets breached again.

Most breach advice treats a breach as a password problem, so the remedy is a new password. If the account that leaked is one you last used in 2019, you have put a new lock on a door you never walk through.

How do I know if someone is already using my leaked email?

A breach result tells you the data is out, not whether anyone has used it. These are the signs that someone has, in roughly the order people tend to notice them.

  1. Password reset emails you did not request. One on its own is probably nothing. Several in a week, from different services, means someone is working through your breach list.
  2. Two-factor codes you did not ask for. Someone has your password and is stuck at the second step. Change that password today.
  3. Login alerts from devices or cities you do not recognise. Most major services send these. Read them before you delete them.
  4. Mail in your sent folder you did not write, or friends asking why you emailed them a link. This means your email account itself is compromised, not just an account that uses it.
  5. Forwarding rules or filters you did not create. Open your email settings and look. Attackers set up a quiet forward to a second address so they keep receiving your mail after you change the password. People miss this when they recover an account.
  6. Being locked out. If your password stops working and the recovery options have changed, someone has taken the account over. Use the provider's account recovery flow immediately, from a device you trust.
  7. Charges, orders or loyalty points you do not recognise. Retail and delivery accounts store cards. An old account with a saved card is worth more to an attacker than your inbox.

If you see any of items 4 through 6, stop reading and secure your email account first. Everything below assumes you still control it.

What should I watch out for after a breach?

After a breach, you become a target for a second round of attempts, and several of them look like help.

  1. Breach notification emails with a button in them. A real breach notice tells you what happened and asks you to log in through the site you already use. A fake one gives you a convenient link. Phishing volume rises after large breaches because attackers know you are expecting mail about it. Go to the site directly.
  2. Emails that quote one of your real passwords. These demand payment, usually in Bitcoin, and claim to have recorded you through your webcam. The FTC's description is that scammers "may really know one of your old – or recent – passwords, and they include it in the message to prove it," and that the password came from a data breach. The FTC's advice: "Stop. Don't pay anything." Change the password if you still use it anywhere, delete the message, and report it at ReportFraud.ftc.gov.
  3. Anyone selling dark web removal. Nothing can be removed from the dark web. A service that charges for it is either doing data broker opt-outs, which are a different and legitimate thing, or doing nothing.
  4. "Your email is on the dark web" pop-ups and ads. These are usually lead forms for a paid monitoring subscription. The free check gives you the same data.
  5. Unsolicited calls that reference details from the breach. A caller who knows your address, your phone provider or your last four digits has read the same leaked database you are worried about. Hang up and call the company back on the number from its own website.
  6. Password reuse you have forgotten about. If the leaked password is the one you also used for your email, your bank, your Apple or Google account, or your password manager, the breach is not contained to the site that lost it.

Can I get my data removed from the dark web?

No. Once a dataset has been copied and shared, there is no mechanism that recalls it. Have I Been Pwned will let you opt your address out of its search results, which hides the record from other people looking you up, but the leaked data itself is untouched. Any service claiming it can scrub your information from the dark web is describing something that does not exist.

What you can do is reduce what is available to leak next time.

Why does the same email keep appearing in new breaches?

Because you have more accounts than you think, and nearly all of them are still open.

Look at your breach list again. Most of the entries are not companies you deal with now. They are companies you dealt with once, for a discount code or a free trial, and then forgot about without closing the account. Each one is still holding your email and whatever else you typed in at signup, and each one is a row in whatever gets breached next.

You cannot be breached at a company you have left. That is not the whole answer, but it is the part you control. A closed account cannot appear in a future breach.

What does Yorba do with the result?

Breach Beacon's results page says the check is "just the start," so here is exactly what that means and what it costs.

The check itself is free and needs no account. Enter as many addresses as you want. The results show which breaches exposed each one.

The free account builds the list the breach check cannot. Connect a Google or Microsoft inbox and Yorba scans it for the signup confirmations, receipts, password resets and other automated emails that indicate an account exists, including the ones you have no memory of creating. It reads header data rather than message content, covers two years of history on the first pass, then re-scans weekly. The free tier covers one inbox, unlimited unsubscribes from mailing lists, the breach check, and deletion instructions for every account it finds through Delete Desk, which Yorba describes as the largest free database of account deletion instructions with more than 10,000 records.

Premium does the deleting. For $60 a year, Yorba connects unlimited inboxes, runs ongoing breach monitoring so new breaches reach you without a manual check, finds recurring subscriptions, cancels the ones you tell it to, and sends the account deletion requests for you. Companies are bad at honoring deletion requests, which is why this is the paid part. Yorba analyzed nearly 22,000 formal deletion submissions in 2025, and only 48% resulted in verified deletion by the end of the year. The other 52% ran into repeated identity and document checks, or companies that refused outright to deal with an authorized representative.

What Yorba does not do. It does not connect Yahoo or iCloud mailboxes. It does not remove anything from the dark web, because nothing does. It does not run data broker opt-outs.

Yorba is a Public Benefit Corporation, takes no outside funding, and its privacy policy says it will never sell user data. For a product that asks for inbox access, that is worth knowing before you connect one.

The checklist, start to finish

If you want the whole article as a list to work through, this is it, in order.

  1. Run Breach Beacon on every email address you have ever used, including the ones you no longer read.
  2. Change your main email account's password to something unique, before touching any other account.
  3. Turn on two-factor authentication for that email account, using an authenticator app or hardware key where offered.
  4. Open your email settings and check for forwarding rules, filters, recovery addresses or recovery phone numbers you did not set.
  5. For each breach in your results, decide whether you still use the account. If yes, give it a unique password and turn on two-factor if it exists. If no, close it instead of changing the password.
  6. Change the leaked password anywhere else you reused it.
  7. Sign up for breach notifications so the next one comes to you.
  8. Connect your inbox to a free Yorba account and let it find the accounts the breach check did not, because they have not leaked yet.
  9. Work through the account list. Delete what you do not use, starting with anything holding a saved card or your home address.
  10. Set a reminder for three months from now. Instead of asking whether your email has leaked, ask how many companies still have it.

How often should I check?

Run the full check once now, across every address. After that, breach notifications handle the alerting, and the quarterly question is the one at the bottom of the checklist. If the number of companies holding your data is going down, you are reducing your exposure. If it is going up, you are back where you started.

Frequently asked questions

Is a dark web scan the same as a breach check? In practice, yes. Both query databases of known breaches that researchers have collected and indexed. "Dark web scan" is the marketing term for it.

Are paid dark web monitoring services worth it? They are worth it if you want ongoing alerts and do not want to check manually. They do not have access to better breach data than the free tools. Have I Been Pwned's free notifications cover the alerting job for most people.

Can data be deleted from the dark web? No. Once leaked data has been copied, nothing recalls it. The only lever you have is reducing the number of companies holding your data, so there is less to leak next time.

How did my email get on the dark web? A company you gave it to was breached. That could be a retailer, a forum, an app you tried once, or a service that was later acquired by a company you have never heard of. The breach check shows you which one.

Should I change my email address after a breach? Usually not. An address appearing in a breach is not, by itself, a reason to abandon it. Change the passwords that matter and close the accounts you no longer use. A new address without those steps just moves the problem.

What is credential stuffing? Attackers take a leaked email and password pair and automatically try it on hundreds of other websites, betting that you reused the password. It is why a breach at one small site can lead to a login at a site that was never breached at all.

How often should I check if my email has been leaked? Run a full check across all your addresses now. Then turn on breach notifications so you hear about new breaches automatically, and review your list of open accounts every few months.

Is Breach Beacon free? Yes. It requires no signup and lets you check several addresses in one go. The next step, scanning your inbox for the accounts behind the breaches, is also free with a Yorba account.

Resources