Breach-Associated Domains Domain-level signal, not credential search
We ingest the Have I Been Pwned breach catalogue as a domain feed, so domains tied to publicly disclosed breaches appear as credential-leak indicators alongside the rest of our data. This is a domain-level signal — we do not index, store, or search individual credentials.
No credit card required · Free API key
risk score · threat categories · sources · age · confidence — in one request
Key features. Everything you need to protect your infrastructure and users.
Domain-Level Signal
Domains associated with disclosed breaches are flagged as credential-leak indicators.
Correlated With Everything Else
The signal sits alongside reputation, DNS, WHOIS and infrastructure data in the same report.
API Access
The indicator is returned by the standard check API — no separate breach endpoint.
Use cases. How security teams use this tool.
Vendor Assessment
See whether a supplier domain carries a breach association before onboarding.
Report Context
Read the breach signal next to the other indicators for the same domain.
Frequently asked questions.
Can I search for an email address?
Do you store passwords, hashed or otherwise?
What does a match actually tell me?
Can I get alerts when a new breach affects my domain?
Ready to get started?
Join thousands of security teams using isMalicious to protect their infrastructure.
No credit card required · Free API key