Kasspar kasspar.com
TOOL / Leak checker

Is this password already on the list?

Cracking tools start with passwords people have actually used, taken from past breaches. This checks yours against the most common ones, offline.

Before trying anything clever, cracking software tries what has already worked: real passwords from real breaches, most common first. This checker holds the 1,500 most frequent entries from the public RockYou list and tests your password against them, including symbol-swapped and padded variants, entirely inside your browser. It tells you exactly what it can and cannot prove, and links to a complete breach check for the rest.

The list is bundled inside this site's script and the comparison happens in your browser. Nothing you type is sent, logged or stored anywhere, and the page makes no network requests.

Waiting for a password

The result appears as you type. Try one you have used in the past, or a guess at what a family member might use.

Bundled list1,500 entries
Match type—
Position in list—
Lab rating—
Try:
What this checks

A bundled list, not the whole internet

The page carries the 1,500 most common entries from the RockYou breach list, the most widely used public collection of real passwords, ordered by how often each one appeared. A password is flagged if it matches exactly, matches after undoing letter-for-symbol swaps (m0nkey), or is one of those entries with digits or symbols bolted on (Soccer2019!).

A "not found" result is not proof of safety. Real cracking lists hold hundreds of millions of entries and rules. The Password lab's pattern checks and a generated password from a manager are the stronger guarantee.

A complete check, done properly

How a real breach check stays private

The full service at haveibeenpwned.com holds hundreds of millions of breached passwords, and it never receives your password either. It uses a technique called k-anonymity:

  1. Your browser hashes the password (a one-way scramble, SHA-1).
  2. Only the first five characters of that hash are sent to the service.
  3. The service returns every known hash starting with those five characters, typically several hundred.
  4. Your browser checks locally whether the rest of your hash is in that list. The service never learns which one, if any, you were looking for.

To find out whether your email address has appeared in a known breach, and which ones, use the main search at haveibeenpwned.com. If it has, change that password wherever you used it and turn on two-factor sign-in.

Why this matters

When a website is breached, the email-and-password pairs are collected, shared and tried automatically against every major service. This is called credential stuffing, and it is why a password you used once on a forum years ago can open your email today. Any password that has ever appeared in a leak should be treated as public, whoever it belonged to.

Common questions

Does this send my password anywhere?

No. The list of common passwords is bundled inside the site's script and the comparison runs in your browser. The page makes no network requests while you type, and nothing is logged or stored.

Is a "not found" result proof that my password is safe?

No. The bundled list holds 1,500 entries; real cracking lists hold hundreds of millions, plus pattern rules. Treat "not found" as "not among the very worst". The Password lab's pattern checks, or better still a generated password from a password manager, are the stronger guarantee.

How does a full breach check stay private?

The service at haveibeenpwned.com uses k-anonymity: your browser hashes the password with SHA-1, sends only the first five characters of that hash, receives every known hash that starts with them, and checks locally whether the rest of your hash is in that list. The service never learns which one, if any, you were looking for.

How do I find out whether my email address was in a breach?

Use the main search at haveibeenpwned.com, which lists the known breaches an email address appears in. If it has been exposed, change the password on that account and anywhere else you reused it, and turn on two-factor sign-in.