MyRecon vs Have I Been Pwned

This comparison comes with a disclosure: MyRecon depends on Have I Been Pwned. Our password check uses its Pwned Passwords service, and our breach archive is built on its catalogue. So this is less a rivalry than a map of who does what.

Checked against Have I Been Pwned's own documentation on 25 September 2026

Short answer

For checking an email against breaches, and being alerted to new ones, Have I Been Pwned is the reference service and you should use it. MyRecon is for everything around that check: combining several breach sources in one answer, then moving on to the usernames, domains, DNS and IPs connected to the same person or company.

MyRecon compared with Have I Been Pwned
FeatureMyReconHave I Been Pwned
Primary jobOSINT across usernames, email, domains, DNS, IPBreach search and notification
Email breach searchYes, via LeakCheck and XposedOrNotYes, the reference dataset
Breach alerts by emailAndroid app, compared on-deviceYes, free notifications
Password checkYes, uses Pwned Passwords (k-anonymity)Yes, Pwned Passwords
Domain-wide breach searchNoYes, for verified domain owners
Username searchYes, 123 platforms on the webNo
WHOIS / DNS / IPYesNo
Email APINot offeredYes, paid API key required
Breach catalogueRepublished with written analysis, CC BY credit to HIBPOriginal source, CC BY 4.0

What Have I Been Pwned is

Have I Been Pwned (HIBP), created by Troy Hunt, is the best-known service for checking whether an email address appears in a data breach. It maintains a catalogue of breaches with descriptions, dates and the data types exposed, offers free email notifications when your address turns up in a new one, and lets organisations search breaches across a domain they have verified. Its Pwned Passwords service lets anyone check a password against hundreds of millions of breached passwords without sending the password, using a technique called k-anonymity. According to its API documentation, searching by email through the API requires a paid key, while the breach catalogue and Pwned Passwords are free to use, with breach data licensed CC BY 4.0.

How MyRecon uses HIBP

For email searches we do not currently use HIBP's paid API. MyRecon combines two free sources, LeakCheck's public API and XposedOrNot, and reports distinct named breaches rather than raw leaked-row counts, so a single breach that leaked your address ten times is counted once.

Where Have I Been Pwned beats MyRecon

Where MyRecon goes further

"Unchecked is not clean"

One principle we hold everywhere applies here too. If a breach source fails to answer, MyRecon says the check was incomplete rather than showing a clean result. A green tick you did not earn is the most dangerous output a breach checker can give, because it is the one that stops you changing a password.

Which one should you use?

Sign up for Have I Been Pwned's free notifications. That is the single most useful thing on this page. Then use MyRecon when you want a second breach source, a password check with nothing sent, or when a breached address turns into a wider question about the accounts and infrastructure around it.

Questions people ask

Is MyRecon affiliated with Have I Been Pwned?

No. MyRecon uses HIBP's free Pwned Passwords service and republishes its CC BY licensed breach catalogue with attribution. We are an independent project.

Why doesn't MyRecon search HIBP for my email?

HIBP's email search API requires a paid key. MyRecon's email check uses two free sources, LeakCheck and XposedOrNot, and you can always search HIBP directly on its own site.

Is it safe to type my password into MyRecon's checker?

It is hashed in your browser and only the first five characters of the hash are sent to Pwned Passwords. That prefix is shared by many thousands of passwords, and the password itself never leaves your device.

Other comparisons

Run the test yourself

Search a handle you own, then one that cannot exist, like zq-no-such-user-8841. A tool worth trusting reports nothing for the second.

Open the username search Six tests for any tool