Your email address is the closest thing most people have to a universal ID. You give it to every shop, app and newsletter, and you use it to sign in almost everywhere. That makes it the most useful single thing to look up if you want to see what the open web knows about you.
Here is a self-audit that takes about ten minutes, and what to do with each result. Do it for your main address first, then for any old address you still receive mail on.
1. Which breaches included it
Start with Have I Been Pwned, a free service run by security researcher Troy Hunt. Enter your address and it lists the known data breaches that contained it, and what each one exposed: passwords, phone numbers, dates of birth, home addresses.
What to do: for every breach that included a password, change that password everywhere you used it. Start with your email account, because whoever controls your inbox can reset everything else. Then sign up for breach notifications so you hear about the next one.
2. Where you have accounts
The list of services tied to your address is longer than you remember. The quickest way to rebuild it is your own inbox: search for "welcome", "verify your email" and "confirm your account". The results are a near-complete record of every sign-up.
What to do: close the accounts you no longer use. A forgotten account with an old, reused password is exactly what breach lists are made of. If a service won't let you delete the account, change its password to a unique one and remove what personal details you can.
3. What search engines show
Search for your address in quotes, for example "name@example.com", in two or three search engines. Then do the same with the username you use most. Things that commonly turn up: old forum posts, a CV saved as a PDF, a mailing-list archive, public code with your address in it, a profile on a site you had forgotten.
What to do: delete what you control. For the rest, ask the site's owner. In the EU and the UK you have a right to erasure under the GDPR, with exceptions. Google also runs a tool to find and remove personal information, such as your phone number, home address or email address, from its search results. Removing a result from Google does not remove the page itself.
4. Public profiles tied to it
Some services publish a profile for an email address by design. Gravatar shows the same picture next to your address on every site that uses it. Code-hosting sites can expose your address in the history of public projects. GitHub, for example, lets you commit with a private no-reply address instead of your real one.
What to do: check the profiles you have, make private what doesn't need to be public, and switch to no-reply or alias addresses where the service allows it.
5. Make the next leak smaller
You can't prevent every breach, but you can make each one expose less.
- Give sites an alias instead of your real address. Firefox Relay, DuckDuckGo Email Protection and Apple's Hide My Email create forwarding addresses you can switch off one by one. Plus-addressing (name+shop@example.com) helps you sort mail, but anyone can strip the part after the plus sign.
- Use a password manager, a different password for every site, and a second factor. Our guide to passwords covers the details.
- Repeat this audit once a year. It gets faster each time.
Doing it at scale
Checking by hand works, but it is slow, and it gets slower when you're responsible for more than your own address, as a security team checking a company's exposure is. Our partner OsintCat runs email and username lookups across many sources at once. Whatever tool you use, use it on addresses that are yours or that you're responsible for.
No comments yet