What we can actually look up
14 lookup types, served from several external data sources. Every result row names the module it came from, so you can trace a finding back to its origin instead of trusting a black box.
Lookup types
Exposure history for an address across every source we query.
Username
detailWhere a handle has been seen and what it was attached to.
Phone
detailDigits are normalized before matching across collected dumps.
Domain
detailCredential records tied to a domain or host.
IP address
detailAddress history including last seen and origin fields.
Password
detailReverse lookup on a secret to find the identities attached to it.
Full name
detailName matches with the identifiers attached to them.
Steam ID
detailGaming account records and adjacent identifiers.
Discord ID
detailNumeric ID matches across collected datasets.
Machine UUID
detailHardware identifier matches from stealer logs.
MAC address
detailRegistered hardware vendor behind an adapter's OUI prefix.
Crypto address
detailOn-chain balance, transfers and counterparties for a wallet.
Company
detailRegistry records, legal entity identifiers and entity status.
File hash
detailProvenance for a known file, from hash to the product build it belongs to.
Where records come from
These are the modules behind each result. We do not claim every module is queried on every search, because a given identifier is often only present in one or two of them.
Breach and credential data
- Snusbase
- IntelX
- LeakCheck
- HackCheck
- BreachBase
- IntelVault
- Stealer logs
- Discord dumps
Credential and session data drawn from breach corpora. Some modules carry sets that are years old while others are refreshed continuously, which is why a match can look stale next to a fresh one.
Registries and network data
- MACLookup
- IEEE OUI registry
- Blockscout
- crt.sh
- RDAP
- GLEIF
- Team Cymru
- Spamhaus DROP
- Tor Project
Public registries and network allocations. These are queried live against the authority that holds the record, so a finding carries that authority behind it rather than our own copy.
Identity and reference
- Maigret
- Sherlock
- GitHub
- Wikidata
- Gravatar
- CIRCL hashlookup
Account enumeration and reference data used to establish whether an identifier exists at all, and where it is registered.
Distinct modules queried across the platform: 25. Counting is done on distinct module names, so a module reached by more than one path is only counted once.
Honest limits
Coverage is a property of the underlying sources, not of our interface. A clean result means the identifier was not found in the modules that were queried, which is not the same as the identifier being absent from every breach that exists.
Freshness varies by module. Some sources carry data that is years old and others are updated continuously, and rows carry the date the source recorded where one is available.
We do not publish a total record count. Competitor pages quote very large numbers and we cannot verify how those are measured, so we would rather publish nothing than a figure we cannot stand behind.