Enter any email address for deep intelligence: breach database check (k-anonymity — password never sent), MX record validation, disposable email detection, email provider identification, plus-address analysis, and permutation generation for OSINT investigations.
🔒 Breach check uses k-anonymity — only first 5 characters of the SHA-1 hash are sent to HIBP. Your full email is never transmitted.
The breach check uses Have I Been Pwned's k-anonymity model. Your browser computes a SHA-1 hash of the email, then only the first 5 characters are sent to HIBP. The server returns all hashes starting with those 5 characters and matching happens locally — your full email is never transmitted to any external service.
The OSINT Email Investigator performs comprehensive open-source intelligence (OSINT) analysis on any email address. Enter an email and the tool queries multiple public databases to determine whether the address has appeared in known data breaches, checks the domain's mail server configuration, verifies whether the mailbox exists without sending a message, and maps any public digital footprint associated with the address.
Data breach lookups use the k-anonymity model to query the Have I Been Pwned (HIBP) database without ever transmitting the full email address — only a SHA-1 prefix is sent, protecting the privacy of your query. If the address appears in known breaches, the tool lists which breaches and what data was exposed (passwords, phone numbers, physical addresses, etc.).
The domain analysis module examines MX records, SPF configuration, and SMTP server characteristics to determine whether the domain is a legitimate business, a disposable email provider, or a known spam infrastructure. This intelligence helps distinguish real contacts from throwaway accounts.