Password Security
How to Check If a Password Was Exposed Without Sharing It
Your current password is an authentication secret and should not be sent to an unknown checker or person. If you suspect exposure, change it through the official account, replace every reused copy, and enable multifactor authentication.
Why should I avoid submitting my password?
A password can unlock an account even when it appears in a harmless-looking test. Sending it to an unverified service creates another place where the secret could be stored or misused.
If the password is old, reused, or connected to a suspicious event, changing it is safer than trying to prove its history.
- Never share a current password.
- Do not email a password.
- Avoid unknown checkers.
What makes a password high risk?
Risk is higher when a password is reused, short, predictable, based on personal information, or exposed in a breach. A password may be unsafe even when no known match is found.
- Reused password
- Common phrase
- Personal information
- Old credential
What can an exposure check tell me?
A permitted email check may provide context about known exposure sources. It cannot safely prove that a current password is secret or guarantee that no one knows it.
Change the password at the account
Open the official service directly and replace the password with a unique credential. Do not make a small variation of the old password.
- Use a unique password.
- Avoid predictable variations.
- Use a password manager.
Replace reused copies
If the password appeared on multiple services, change each account. Prioritize email, financial, work, and accounts that can reset other services.
- List reused accounts.
- Change high-value accounts first.
- Check recovery settings.
Add another protection layer
Enable multifactor authentication and store backup codes securely. Never give a one-time code to a caller who contacts you unexpectedly.
- Enable MFA.
- Protect backup codes.
- Review trusted devices.
Continue monitoring
Watch for login alerts and password-reset messages. A negative 4safer result means no known match was found in searched sources; it is not a guarantee that the password is safe.
Frequently asked questions
Can I safely type my password into a checker?
Do not submit a current password to an unverified service. Change it instead when exposure is suspected.
Should I change a password that was used only once?
Yes, if you suspect it was exposed. Replace it with a unique password through the official account.
Does a clean result prove the password is safe?
No. It only means no known match was found in the sources searched.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
