Domain credential exposure reports
Explore public reports on credentials associated with a domain. See the scale of exposure, understand how records relate to the domain, then investigate your organization's accounts in LeakRadar.
Explore the public reportsStart with your domain.
Public overview. No account required.
Explore the public reports
Browse the existing directory or filter it by domain name. Public reports show aggregate figures; account details are available in the member area.
- square-enix.com
- squarespace.com
- squareup.com
- srcei.cl
- sre.gob.mx
- sri.gob.ec
- sribu.com
- sribulancer.com
- srmist.edu.in
- srmuniv.ac.in
- ssa.gov
- ssbjk.org.in
- ssc.gov.in
- ssc.gov.jo
- ssc.nic.in
- sslforfree.com
- ssm.com.my
- sso.go.th
- ssoidp.gov.ps
- ssportplus.com
- ssru.ac.th
- sss.gov.ph
- st.com
- stackoverflow.com
- stackry.com
- stake.com
- stamps.com
- stan.com.au
- standardbank.co.za
- standardchartered.com
- stanford.edu
- stanleybet.ro
- staples.com
- star-clicks.com
- star7arab.com
- starbreeze.com
- starbucks.com
- stardix.com
- stardock.com
- stardoll.com
- stargames.com
- stargames.net
- starhealth.in
- starlink.com
- starpets.gg
- starplus.com
- starstable.com
- startech.com.bd
- startimes.com
- startupindia.gov.in
How to read a domain report
Stealer Log records are grouped by the domain in the service URL and the email address. These groups describe matches, not verified employees or customers.
URL + email domain
Both the service URL and the email address match the domain. Review these records to identify potentially exposed access to your own services.
Email domain only
The email address matches the domain, while the service URL belongs elsewhere. Review where organization addresses appear in external services.
URL domain only
The service URL matches the domain, while the account identifier does not match its email domain. Investigate exposure associated with users of that service.
Investigate the exposed records, with the data to act.
File lines, not a count of unique accounts.
UpdatedPlaintext passwords, with their account context
Inspect the exposed password alongside the account and, for stealer logs, its service URL. When the source includes plaintext, that detail helps your team scope password resets and investigate exposed access.
Compare plans for plaintext access and included unlock points.
Stealer logs
Connect a captured login to its service URL, username and password to understand which access is exposed.
url:user:passCombolists
Find email/password and username/password pairs, including records without a service URL.
email:passuser:passRaw leak files
Search the text of leaked files, database dumps and unstructured records beyond normalized credential fields.
Dark web forums
Search indexed forum posts for mentions of your organization and examine the discussion's source context.
Get notified via Email, Slack, Discord, Telegram or Webhook when new exposed credentials match your monitored domains or email addresses.
About domain reports
What can I see in a public report?
Public reports show aggregate credential exposure associated with a domain. Stealer Logs use estimated counts and domain-based groups. Combolist figures, when available, appear separately. The two totals are not combined.
Can I check a domain that is not listed?
Yes. Enter a domain in the directory to open its public report, when available, without an account. The member area is used to investigate account details. Start with your domain.
Does a report mean the website was breached?
No. A domain can appear in credentials captured from an infected device or reused across services. A match alone does not prove a breach of the website's servers or that a password still works.
Can my team inspect the exposed passwords?
LeakRadar provides account-linked plaintext when it is present in the source. An account is required; visibility and unlocking depend on your plan and preferences. Public reports never display the passwords.