Skip to content

Domain credential exposure reports

Explore public reports on credentials associated with a domain. See the scale of exposure, understand how records relate to the domain, then investigate your organization's accounts in LeakRadar.

Explore the public reports
Your organization's exposure

Start with your domain.

Paste a domain or website URL. Subdomains are kept as entered.

Public overview. No account required.

Explore the public reports

Browse the existing directory or filter it by domain name. Public reports show aggregate figures; account details are available in the member area.

Page 41

  1. daraz.pk
  2. darkaim.com
  3. darkbeam.com
  4. darknetsearch.com
  5. darkorbit.com
  6. darkowl.com
  7. darkwebid.com
  8. darkwebinformer.com
  9. darkwebreport.io
  10. darty.com
  11. darwinbox.in
  12. dasa.com.br
  13. dat.com
  14. databreach.com
  15. datacamp.com
  16. dataprev.gov.br
  17. datastreamer.io
  18. datemyage.com
  19. dating.com
  20. daum.net
  21. davivienda.com
  22. daybreakgames.com
  23. dayforcehcm.com
  24. daz3d.com
  25. dazn.com
  26. dbd.go.th
  27. dboglobal.to
  28. dcinside.com
  29. dcuniverseinfinite.com
  30. dcuniverseonline.com
  31. ddns.me
  32. ddns.net
  33. ddo.com
  34. ddtech.mx
  35. deadfrontier.com
  36. deascuola.it
  37. debrid-link.com
  38. decathlon.com.tr
  39. decathlon.es
  40. decathlon.fr
  41. decathlon.it
  42. decathlon.net
  43. decidir.com
  44. declaranet.gob.mx
  45. decolar.com
  46. decomaniacos.es
  47. dedbit.com
  48. dedeman.ro
  49. deepl.com
  50. deepmotion.com
Understand the signal

How to read a domain report

Stealer Log records are grouped by the domain in the service URL and the email address. These groups describe matches, not verified employees or customers.

01

URL + email domain

Both the service URL and the email address match the domain. Review these records to identify potentially exposed access to your own services.

02

Email domain only

The email address matches the domain, while the service URL belongs elsewhere. Review where organization addresses appear in external services.

03

URL domain only

The service URL matches the domain, while the account identifier does not match its email domain. Investigate exposure associated with users of that service.

Data methodology
The data behind LeakRadar

Investigate the exposed records, with the data to act.

641,680,817,914lines across indexed leak files

File lines, not a count of unique accounts.

Updated

Plaintext passwords, with their account context

Inspect the exposed password alongside the account and, for stealer logs, its service URL. When the source includes plaintext, that detail helps your team scope password resets and investigate exposed access.

Compare plans for plaintext access and included unlock points.

  • Stealer logs

    Connect a captured login to its service URL, username and password to understand which access is exposed.

    url:user:pass
  • Combolists

    Find email/password and username/password pairs, including records without a service URL.

    email:passuser:pass
  • Raw leak files

    Search the text of leaked files, database dumps and unstructured records beyond normalized credential fields.

  • Dark web forums

    Search indexed forum posts for mentions of your organization and examine the discussion's source context.

Get notified via Email, Slack, Discord, Telegram or Webhook when new exposed credentials match your monitored domains or email addresses.

Explore our data coverage
FAQ

About domain reports

What can I see in a public report?

Public reports show aggregate credential exposure associated with a domain. Stealer Logs use estimated counts and domain-based groups. Combolist figures, when available, appear separately. The two totals are not combined.

Can I check a domain that is not listed?

Yes. Enter a domain in the directory to open its public report, when available, without an account. The member area is used to investigate account details. Start with your domain.

Does a report mean the website was breached?

No. A domain can appear in credentials captured from an infected device or reused across services. A match alone does not prove a breach of the website's servers or that a password still works.

Can my team inspect the exposed passwords?

LeakRadar provides account-linked plaintext when it is present in the source. An account is required; visibility and unlocking depend on your plan and preferences. Public reports never display the passwords.

Domain credential exposure reports | Page 41 | LeakRadar