Checking whether an email address has appeared in a known data breach, without needing to know or guess a real password.
A breach exposure check looks up common role-based addresses on a domain — typically things like info@yourdomain.com or admin@yourdomain.com — against a public database of known data breaches, such as Have I Been Pwned. If one of those addresses has appeared in a breach that's been publicly catalogued, the check flags it. This only reveals that an email address existed in a leaked dataset somewhere — it says nothing about the specific password used, and doesn't attempt to log in anywhere.
A breach listing usually includes an email address alongside a password (often hashed, sometimes not) from whatever site was actually breached — not necessarily your website. The real risk is credential reuse: if that email address used the same or a similar password on other accounts, including ones tied to your business (email hosting, domain registrar, banking, admin panels), a leaked password from an unrelated breach becomes a working key elsewhere.
If a business address shows up in a breach: change the password on any account that uses that email address with a password that might be reused elsewhere, turn on two-factor authentication wherever it's offered (especially your domain registrar and email hosting — the two accounts that, if compromised, let someone take over everything else), and consider whether that role address needs to be a real inbox at all, or could forward to something less guessable.
Role addresses like info@ and admin@ are the first thing anyone guesses when targeting a domain, precisely because they're predictable and almost every business has one. They're also disproportionately likely to show up in old breaches, simply because they've existed publicly, unchanged, for years.
Want to know where your own domain stands? CBWatch checks this — and eight other categories — in about ten seconds, free, no signup.
Run a free scan →Want CBWatch to catch this automatically going forward? See what monitoring includes →