What we can actually look up

14 lookup types, served from several external data sources. Every result row names the module it came from, so you can trace a finding back to its origin instead of trusting a black box.

Lookup types

Email

detail

Exposure history for an address across every source we query.

Username

detail

Where a handle has been seen and what it was attached to.

Phone

detail

Digits are normalized before matching across collected dumps.

Domain

detail

Credential records tied to a domain or host.

IP address

detail

Address history including last seen and origin fields.

Password

detail

Reverse lookup on a secret to find the identities attached to it.

Full name

detail

Name matches with the identifiers attached to them.

Steam ID

detail

Gaming account records and adjacent identifiers.

Discord ID

detail

Numeric ID matches across collected datasets.

Machine UUID

detail

Hardware identifier matches from stealer logs.

MAC address

detail

Registered hardware vendor behind an adapter's OUI prefix.

Crypto address

detail

On-chain balance, transfers and counterparties for a wallet.

Company

detail

Registry records, legal entity identifiers and entity status.

File hash

detail

Provenance for a known file, from hash to the product build it belongs to.

Where records come from

These are the modules behind each result. We do not claim every module is queried on every search, because a given identifier is often only present in one or two of them.

Breach and credential data

  • Snusbase
  • IntelX
  • LeakCheck
  • HackCheck
  • BreachBase
  • IntelVault
  • Stealer logs
  • Discord dumps

Credential and session data drawn from breach corpora. Some modules carry sets that are years old while others are refreshed continuously, which is why a match can look stale next to a fresh one.

Registries and network data

  • MACLookup
  • IEEE OUI registry
  • Blockscout
  • crt.sh
  • RDAP
  • GLEIF
  • Team Cymru
  • Spamhaus DROP
  • Tor Project

Public registries and network allocations. These are queried live against the authority that holds the record, so a finding carries that authority behind it rather than our own copy.

Identity and reference

  • Maigret
  • Sherlock
  • GitHub
  • Wikidata
  • Gravatar
  • CIRCL hashlookup

Account enumeration and reference data used to establish whether an identifier exists at all, and where it is registered.

Distinct modules queried across the platform: 25. Counting is done on distinct module names, so a module reached by more than one path is only counted once.

Honest limits

Coverage is a property of the underlying sources, not of our interface. A clean result means the identifier was not found in the modules that were queried, which is not the same as the identifier being absent from every breach that exists.

Freshness varies by module. Some sources carry data that is years old and others are updated continuously, and rows carry the date the source recorded where one is available.

We do not publish a total record count. Competitor pages quote very large numbers and we cannot verify how those are measured, so we would rather publish nothing than a figure we cannot stand behind.

Try a lookup