That are often saved in plaintext by websites that don’t know any better.


This is a cool idea.

Sadly I have a catch all on my domain so I can’t use this service.

(Ex:, - every retailer gets their own email)

As an aside, apparently this also frustrates data brokers since a common method to correlate people is to hash the email.

Interesting. Does it take a lot of time to manage, though?

I do the same. If you own the domain? Go to the source and set yourself up for domain-wide breach notifications:

I’ve been subscribed for a few years now. It hasn’t turned up much for personal domains, but the work ones? I’ve had to chat to executive management a few times about breaches.

That’s the comment I was about to make.

A search would be useful.

Not really. * redirects to one inbox (“catch all”)

I maintain a list of important addies in case I move to a provider that doesn’t allow catch alls, but for now it’s fairly painless.

Thanks, this is useful.

Luckily nothing surprising - all the the breaches are from after I started using a password manager and for low value accounts. :tada:

