Skip to main content
POST
Email Breaches

Overview

Email Breaches tells you whether an address has been exposed in known data breaches, which services leaked it, and what kinds of data were exposed (passwords, email addresses, usernames, and more). It returns a canonical breach object shared with the dashboard, so this endpoint, the CLI, and the app all report identical fields. Use it to flag risky accounts or enrich a contact with exposure signal. Check a single address here (1 credit), or run a whole list through the bulk job pipeline below.
Only need a yes/no answer? POST /api/lookup/email/breaches/check returns whether the address is breached for 0 credits. It does not return the breach detail documented on this page.

Authentication

Requires an API key in the Authorization header.

Request

string
required
The email address to check for data breaches.

Example request

Response

Returns the canonical breach shape shared with the dashboard, so the CLI and this endpoint all return identical fields.
string
The email address that was checked.
boolean
Whether the email appears in one or more known breaches.
object
The canonical breach detail object. Can serialize as null when no breach record was produced.
number
Credits charged for this request. 1 on a fresh charge, or 0 when you were already charged for this address within the billing window (a free repeat).

Errors

Errors return a JSON body of the form {"error": "<message>", "code": "<code>"} with the matching HTTP status code.

Credits

Each check costs 1 credit. Billing is per-customer: 1 on the first check of an address, 0 for repeats within the billing window. See Credits.

Bulk jobs

To check a whole list, submit it as a bulk job instead of looping this endpoint. One entrypoint handles every lookup - set type=email-breaches - and a webhook delivers the finished file when it’s done.
  • Up to 1,000,000 emails per job, charged 1 credit per email (with free repeats).
  • download_link=true returns a download_url in the bulk.completed webhook; fetch it with your API key.
  • Export filters: all, breached.
See the Bulk Operations guide for the webhook payload, status checks, and download options.