Short answer is yes, because it never sends your password anywhere. It makes a SHA1 hash of your password, sends the first few characters of that hash, and receives a list of all the hashes which match those characters (which will generally be a few hundred matches), and then your browser picks out the correct one and shows it to you. If you don't trust the website, you can do the same process yourself: Use an open source tool you trust to create a SHA1 hash of the password you want to test. In a web browser, go to https://api.pwnedpasswords.com/range/(first 5 characters of your hash) Find the rest of your hash in the list, the number after the colon is the number of instances found. If it's not in the list, that's good news! You haven't been pwned. Example: Using a command line tool, the SHA1 hash of 'password' is 5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8 So we navigate to: https://api.pwnedpasswords.com/range/5baa6 And in that list we find the entry that starts with 1e4c9b...., and look after the colon to find that it's been used 3645804 times and is therefore probably not a very good password. Answer from Traches on reddit.com
🌐
Reddit
reddit.com › r/privacy › is it safe to check my passwords using have i been pawned?
r/privacy on Reddit: Is it safe to check my passwords using Have I Been Pawned?
April 19, 2019 - The military changes it's passwords often for various reasons, often to prevent sabotage and betrayal. Continue this thread Continue this thread Continue this thread Continue this thread Continue this thread Continue this thread ... No fucking way. ... YSK there is a website called haveibeenpwned.com that lets you see if your email has been involved in any data breaches across any website.
🌐
Have I Been Pwned
haveibeenpwned.com › Passwords
Have I Been Pwned: Pwned Passwords
Password reuse is extremely common and puts your accounts at risk.
🌐
Vertex Cyber Security
vertexcybersecurity.com.au › should-i-use-have-i-been-pwned-hibps
Should I use Have I been pwned (HIBP) ? - Vertex Cyber Security
August 15, 2024 - So, you might have heard of a website “Have I been pwned” (HIBP) which contains a list of hacked user emails and passwords that you can check to see if your email or password has been hacked. Now, before I talk about “Have I been pwned”, it is worth highlighting there are many sites out there that offer the ability to search for breached data or hacked user details, so this information could also be potentially applied to those too.
Short answer is yes, because it never sends your password anywhere. It makes a SHA1 hash of your password, sends the first few characters of that hash, and receives a list of all the hashes which match those characters (which will generally be a few hundred matches), and then your browser picks out the correct one and shows it to you. If you don't trust the website, you can do the same process yourself: Use an open source tool you trust to create a SHA1 hash of the password you want to test. In a web browser, go to https://api.pwnedpasswords.com/range/(first 5 characters of your hash) Find the rest of your hash in the list, the number after the colon is the number of instances found. If it's not in the list, that's good news! You haven't been pwned. Example: Using a command line tool, the SHA1 hash of 'password' is 5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8 So we navigate to: https://api.pwnedpasswords.com/range/5baa6 And in that list we find the entry that starts with 1e4c9b...., and look after the colon to find that it's been used 3645804 times and is therefore probably not a very good password. Answer from Traches on reddit.com
🌐
Have I Been Pwned
haveibeenpwned.com › FAQs
Have I Been Pwned: Frequently Asked Questions
The risk posed to individuals in these incidents is different (their personal device may be compromised) hence the presence of this flag in HIBP. Stealer logs are the result of malicious software running on infected machines that collect email addresses, passwords and the website they're entered into at login...
🌐
Have I Been Pwned
haveibeenpwned.com
Have I Been Pwned: Check if your email address has been exposed in a data breach
Have I Been Pwned allows you to check whether your email address has been exposed in a data breach.
Top answer
1 of 7
97

This question was explained by Troy Hunt several times on his blog, on Twitter and in the FAQ of haveibeenpwned.com

See here:

When you search for an email address

Searching for an email address only ever retrieves the address from storage then returns it in the response, the searched address is never explicitly stored anywhere. See the Logging section below for situations in which it may be implicitly stored.

Data breaches flagged as sensitive are not returned in public searches, they can only be viewed by using the notification service and verifying ownership of the email address first. Sensitive breaches are also searchable by domain owners who prove they control the domain using the domain search feature. Read about why non-sensitive breaches are publicly searchable.

See also the Logging paragraph

And from the FAQ:

How do I know the site isn't just harvesting searched email addresses?

You don't, but it's not. The site is simply intended to be a free service for people to assess risk in relation to their account being caught up in a breach. As with any website, if you're concerned about the intent or security, don't use it.

Of course we have to trust Troy Hunt on his claims, as we have no way of proving that he is not doing something else, when handling your specific request.
But I think it is more than fair to say, that haveibeenpwned is a valuable service and Troy Hunt himself is a respected member of the infosec community.

But let's suppose we don't trust Troy: what do you have to lose? You might disclose your email address to him. How big of a risk is that to you, when you can just enter any email address you want?

At the end of the day, HIBP is a free service for you(!) that costs Troy Hunt money. You can choose to search through all the password databases of the world yourself if you don't want to take the risk that maybe a lot of people are wrong about Troy Hunt, just because then you would disclose your email address.

2 of 7
16

Troy Hunt is a very respected Information Security professional and this service is being used by millions of people worldwide, even by some password managers to verify if the passwords selected by the users have been involved in a data breach.

See for example, https://1password.com/haveibeenpwned/

As per the website, 1Password integrates with the popular site Have I Been Pwned to keep an eye on your logins for any potential security breaches or vulnerabilities.

Entering your email address on this site will tell you which data breaches involve this email address, so that you can go back to the affected website and change your password. This is esp. important if you have used the same password for multiple websites, where credentials stolen from one site can be used to attack other sites in a technique also called Credential Stuffing attack.

The following StackExchange post has a response from Troy himself with further clarification on this service: Is "Have I Been Pwned's" Pwned Passwords List really that useful?

🌐
1Password
1password.com › haveibeenpwned
Have I Been Pwned | 1Password
Discovered your data was breached? Learn about Have I Been Pwned and how 1Password can secure your online accounts and sensitive information.
Find elsewhere
🌐
SlashGear
slashgear.com › 1826787 › have-i-been-pwned-legit-safety-concerns-explained
Is 'Have I Been Pwned' Legit? Here's How The Website Works - SlashGear
April 8, 2025 - How it handles the data is what makes Have I Been Pwned so legit: The site doesn't even log search queries, and everything is transmitted over encrypted connections. Even passwords that appear in the site's Pwned Passwords database are stored ...
🌐
Wikipedia
en.wikipedia.org › wiki › Have_I_Been_Pwned
Have I Been Pwned? - Wikipedia
1 month ago - In February 2018, British computer scientist Junade Ali created a communication protocol (using k-anonymity and cryptographic hashing) to anonymously verify if a password was leaked without fully disclosing the searched password. This protocol was implemented as a public API in Hunt's service and is now consumed by multiple websites and services including password managers and browser extensions.
🌐
Opensource.com
opensource.com › article › 19 › 6 › check-passwords
Check your password security with Have I Been Pwned? and pass | Opensource.com
HIBP supports this via a password-checking feature that is exposed via an API, so it is easy to use. Now, it would be a bad idea to send the website a full list of your passwords. While I trust HaveIBeenPwned.com, it could be compromised one day.
🌐
YouTube
youtube.com › watch
Can You Trust HaveIBeenPwned Password Checker? - YouTube
See how HaveIBeenPwned checks your password without knowing what your password is - crazy I know, but it works!
Published   November 24, 2019
🌐
Trustpilot
trustpilot.com › home › electronics & technology › internet & software › software company › have i been pwned reviews
Have I Been Pwned Reviews | Read Customer Service Reviews of haveibeenpwned.com
5 days ago - There is nothing to complain about a free service helping guide you about breaches and protect from using weak passwords. ... Amazing service. So glad this service exists to make people more aware of their relation to breaches ... An incredible tool that has provided me with a huge amount of value over the years. It has informed me of multiple breaches that have affected my personal data. Very useful, would highly recommend. ... It is fine to know but better is to know who did it and what measures you can take to be more safe.
Address   4217, Surfers Paradise, AU
(3.6)
🌐
Quora
quora.com › How-safe-is-it-to-check-my-password-on-the-Have-I-Been-Pwned-password-Checker-Why-is-it-safe
How safe is it to check my password on the Have I Been Pwned password Checker? Why is it safe? - Quora
Answer (1 of 5): It’s safe. It doesn’t rely on passwords - you put in your email address and it checks against a database of email addresses associated with known breaches. It doesn’t actually reveal (or even search) passwords. So you’re not putting a password into the search, you’re putting an e...
🌐
Reddit
reddit.com › r/privacy › how safe is haveibeenpwned.com?
r/privacy on Reddit: How safe is haveibeenpwned.com?
April 7, 2023 -

Is it safe to use haveibeenpwned.com? Do they store the e-mail/phone number you search? Those who understand back-end processing, please enlighten me on the site.

Top answer
1 of 6
26
The site is run by a white hat hacker, Troy Hunt. It allows you to search any email address, which is already in the database of hacked accounts. Nothing is stored, and even if it was, nothing particularly useful would come of it. The only exception is for sensitive breaches, like Ashley Madison for example. In that case, you need to verify the email address is yours before information is returned regarding it. I can't quite remember the details why. Signing up for breach alerts is another option, which many other services already offer. But that stuff is made very clear. It's a bit of a paradox, that a site like that looks much scarier than the initial sites that breached to the data to begin with. LinkedIn looks safer than HIBP. Looks can be deceiving.
2 of 6
15
Troy Hunt is a renowned security expert, working for Microsoft. He did consider to give someone else the responsibility for this site some years back. But he got cold feet when realising those willing to take that task didn't necessarily have the purest intentions with the site data, and it would not be in the best interest of its users. Not too long after, he started selling the API access to sites wanting to query if usernames, e-mail addresses, etc was comprised. I believe this service can also do API callbacks when their users is caught in a compromise. This service offering mostly funds HIBP, in addition to other donations. I have several of my own domains listed there, and occasionally I do get some warnings when new breaches are registered. That often explains quite well when an e-mail address is getting a lot more unexpected spam or phishing attempts.
🌐
Password Bits
passwordbits.com › trust-hibp
Can You Trust HaveIBeenPwned? - Password Bits
September 12, 2022 - I’ve listed off a few Reddit post that helps to back up the claim that HaveIBeenPwned is safe to use. ... YSK: HaveIBeenPwned will tell you if your email address and passwords have ever been compromised, so change them right now if they have!
🌐
Quora
quora.com › Is-it-safe-to-input-a-password-on-haveibeenpwned-website
Is it safe to input a password on haveibeenpwned website? - Quora
Answer (1 of 3): Well, I generally would not enter a password on a random site - but I do not reuse passwords and my passwords are long and randomly generated. That said, if your password is not entirely random then it does make some sense to check it against a database of more than half a billi...
🌐
Reddit
reddit.com › r/privacy › haveibeenpwned.com passwords
r/privacy on Reddit: HaveIBeenPwned.com Passwords
January 26, 2022 -

I know this website is safe to check your email addresses. I noticed that there is a 'Passwords' section and you can enter your passwords in there to see if they have been breached.

This might sound like a stupid question, but is it actually safe to enter your password here to check to see if it has been breached?

🌐
Consumer Reports
consumerreports.org › electronics & computers › how to use 'have i been pwned' to see if your data was compromised
How to Use 'Have I Been Pwned' to See If Your Data Was Compromised via @ConsumerReports
October 24, 2022 - Have I Been Pwned is a useful resource for finding out when you’ve been affected by a data breach, but it’s best to get ahead of the problem by making your accounts more secure. Two important steps, Hunt says, are enabling multifactor authentication and using a password manager to generate and save strong passwords.