Docuboxer

Check if Your Password Leaked

Check breaches via k-anonymity and measure real strength: your password never leaves the browser.

100% local — your files are never uploaded to any serverNo signupFree
How this lookup works (k-anonymity)
  1. Your password is turned into a SHA-1 hash inside your browser, using WebCrypto. The plain text never leaves your device.
  2. Only the first 5 characters of that hash are sent to the Have I Been Pwned API — never the full hash, and never the password.
  3. The server replies with every hash suffix that shares those 5 characters: usually several hundred of them.
  4. Your browser compares those suffixes against yours locally. Have I Been Pwned never learns which password, or even which exact hash, was checked.

Analyzed in your browser. Only 5 characters of its hash leave your device for the breach lookup — never the password itself.

How do I check if my password has been in a data breach?

You check it against the Have I Been Pwned (HIBP) Pwned Passwords database without ever sending the actual password: your browser hashes it with SHA-1 locally, sends only the first 5 characters of that hash, and compares the rest locally against the roughly 800 suffixes the server returns. This is called k-anonymity, and it means neither HIBP nor anyone intercepting the connection ever learns which password you checked. This tool runs entirely in your browser, is free, and requires no signup — alongside the breach check, it measures real password strength with zxcvbn, the same engine behind well-known password managers, complete with estimated crack times and concrete suggestions. If your password shows up in a breach, change it everywhere you use it, not just on the service that leaked — breached password lists get replayed against dozens of unrelated sites in credential-stuffing attacks.

How to use Check if Your Password Leaked

  1. Type the password you want to check into the field — use the eye icon if you need to see it while typing.
  2. Click "Check". Nothing runs automatically as you type: the breach lookup is a network request and only fires on the button click.
  3. Read the breach result: how many times that exact password shows up in known leaked databases, or that it doesn't appear at all.
  4. Read the strength analysis: score, estimated crack time under an offline and an online attack, and suggestions to improve it.
  5. If the password is breached or weak, change it. Docuboxer's password generator creates a new one with secure cryptography.

Common use cases

Before reusing an old password

Plenty of accounts still run on passwords created years ago. Checking whether they show up in known breaches before reactivating an account or reusing one elsewhere avoids exposure you didn't know about.

Personal audit after a breach headline

When a major breach makes the news (a social network, an email provider, a forum), checking whether your usual passwords are in the lists that start circulating helps you decide which ones to change urgently.

Setting a password policy for a small team

Before mandating "at least 12 characters" as a rule, an IT lead can use the strength analysis to see which combinations actually resist an offline attack and which only look strong.

Double-checking a freshly generated password

After creating a password with a manager or generator, checking its real strength here and confirming it doesn't coincidentally match a known breach adds a second layer of confidence.

Teaching the risk of credential stuffing

Showing live how many times a typical weak password (a dictionary word plus a trailing number) shows up in HIBP's database is a direct way to explain why attackers try breached passwords against unrelated accounts.

Frequently asked questions

Is it safe to type my real password into this tool?

Yes, and here's exactly how: the password is hashed with SHA-1 inside your browser and is never transmitted. Only 5 characters of that hash are sent to the Have I Been Pwned API, which replies with hundreds of possible suffixes; the final comparison to decide if it matches also happens in your browser. It's the same k-anonymity protocol password managers like 1Password or Bitwarden use for this exact check.

What does it actually mean if my password "appears" in a breach?

It means that exact character combination is already in one or more databases of stolen passwords circulating among attackers, along with a count of how many times it's been seen. It doesn't say which service it came from or when — just that it exists in lists used to test credentials against other accounts automatically.

If it doesn't show up in a breach, is my password safe?

Not necessarily. Have I Been Pwned doesn't cover every breach that exists or will happen in the future, so "not found" is a positive signal, not a guarantee. That's why this tool also measures real strength with zxcvbn: a password can be un-breached today and still be trivial to guess.

What is k-anonymity and why is it used here instead of sending the password?

K-anonymity is a technique that lets you make a useful query while revealing only part of the information — here, 5 characters of a 40-character hash — so the server can't identify what was actually looked up among the hundreds of possibilities that share that prefix. Sending the full password, even over HTTPS, would require trusting that the server doesn't log it; k-anonymity removes the need for that trust.

Why use SHA-1 if it's considered a broken algorithm?

SHA-1 isn't protecting the password itself here — it's only used as an identifier for the k-anonymity protocol, exactly as Have I Been Pwned's own API defines it. SHA-1's known collision weaknesses don't matter for this use case: nothing is being signed and no secret is protected by the hash, it's just a prefix comparison.

How is this different from Docuboxer's password generator?

The password generator creates brand-new passwords using cryptographic randomness. This tool does the opposite: it analyzes a password you already have (or just generated) to tell you whether it's breached and how strong it really is. They're complementary — generate there, check here, or the other way around.