Toolkit
Domain Breach Exposure
Which known breaches involved services on your domain. This one asks you to prove you control the domain first, and the reason for that is the most interesting thing on this page.
Why we ask you to prove ownership. A tool where anyone types in any domain and sees its breach exposure is not a security check, it is a targeting tool. It tells a stranger which of your staff to approach and where else their credentials might work. Proving control of the DNS is the same bar as issuing a certificate, and it is the only reason this can exist responsibly.
Why this one is gated when the others are not
Every other tool in this kit tells you about your own configuration, and configuration is public: anyone can already read your DNS records and your response headers. Nothing is disclosed by putting a friendlier interface on it.
Breach data is different. Told to a stranger, it becomes reconnaissance. It says which organisation had credentials leak, roughly when, and what kind of data was involved, which is precisely the information you would want before attempting to phish someone there. Building that as an open lookup would be handing attackers a convenience.
So the bar is control of the domain, proved by publishing a DNS record only an administrator could publish. It is the same test a certificate authority applies before issuing for a hostname, and it is why Have I Been Pwned requires domain verification for its own equivalent.
What this can and cannot see
It reports breaches of services operating on the domain, drawn from the public breach catalogue. It does not list which of your individual accounts appeared in each breach, which requires a paid subscription to the underlying index.
It also cannot see staff accounts breached at unrelated third parties, which is the more common exposure by a wide margin. Someone using their work address on a hobby site that was breached will not appear here, and their password may still be the one protecting your email. The password check is the better tool for that question.