SNSTOOLS
Free · No sign-upPassword is never sent

Has that password leaked?

Type a password and press Check. If it appears in publicly known breach data, you’ll see how many times. The password itself never leaves your browser.

Input

LocalYour password is processed inside this browser only. The matching server receives just the first 5 characters of its hash, and nothing is sent to our servers. Nothing is stored.

Sent
5 hash chars
Server storage
None
Login
Not needed
Price
Free

NoteThis tool never touches our servers. Hashing and matching happen in your browser, and the password you type is stored nowhere.

How it works

How it works

  1. 01

    Your password is converted inside the browser into a one-way hash (SHA-1, 40 characters). It can’t be turned back into the password.

  2. 02

    Only the first 5 characters of that hash are sent to the matching server, which returns a list of a few hundred candidates sharing the same prefix.

  3. 03

    Your browser compares the remaining 35 characters against that list. The server only ever sees 5 characters, so it can’t know your password either.

The Password Leak Checker tells you on the spot whether a password you use appears in data exposed by past breaches. Type it in, press Check, and that’s it: no account, no login, and it works in any browser on iPhone, Android or PC.

Matching happens inside your browser. The password never leaves it and is never sent to our servers. The matching server receives only the first 5 characters of a one-way hash of the password, and returns a list of candidates sharing that prefix; your browser compares the rest locally. Neither that server nor this site ever holds the password itself.

A leaked password is dangerous because attackers feed breach lists straight into automated login attempts. If the result says Found, change that password now on every service where you use it. Reusing one password across services means a single breach spreads to all of them (credential stuffing). Use a different password per service and let a password manager remember the ones you can’t.

Not found does not mean safe. Breaches that were never made public, or that haven’t been added to the matching data yet, can’t be detected. A short or guessable password, or one built from your name or birthday, stays weak even if it never leaked. Use 12 characters or more, don’t reuse it, and turn on two-factor authentication so a leak alone can’t take over the account.

FAQ

FAQ

QIs it safe to type my password here?
AThe password never leaves your browser. Only the first 5 characters of its hash are used for matching; neither the password nor its full hash is sent to our servers or the matching server, and nothing is stored.
QIf it’s not found, is my password safe?
ANo. Breaches that were never published, or not yet included in the data, can’t be detected. A guessable password stays weak even if it never leaked. Make it long and unique, and turn on two-factor authentication.
QWhat does the count mean?
AHow many times that exact password appeared in publicly known breach data. The higher the count, the more likely it sits in attackers’ wordlists and gets tried first. Even one hit means you should change it.
QCan I check an email address or username?
AThis tool checks passwords only. Email addresses and usernames are not supported.
QWhat should I enter?
AJust the password you want to check, exactly as you use it: case and symbols matter. No username or email is needed. If you use several passwords, check them one at a time.

Up next

Up next

Breach data: Pwned Passwords (CC BY 4.0)