How to set up leaked-credential monitoring in 15 minutes (free + paid)
Updated August 2026 · independent comparison · primary sources linked
You can set up leaked-credential monitoring for your business domain in about 15 minutes, mostly for free. The short version: (1) search your domain and staff emails on Have I Been Pwned and force resets on any hits; (2) turn on breached-password blocking in Google Workspace or Microsoft 365; (3) subscribe to breach notifications; (4) if you want continuous domain-wide alerts, add HIBP’s paid domain monitoring (from $4.39/mo). Here is the exact sequence.
Step 1, Check what’s already exposed (3 min)
Go to haveibeenpwned.com and search your own work email and a few key staff addresses (owner, finance, admin). Note every breach listed. This is your starting exposure. For a whole domain, use HIBP’s Domain search, you verify ownership via a DNS TXT record or a file, then see every breached address on the domain.
Step 2, Force resets on every hit (5 min)
For each exposed account, reset the password to a unique, long passphrase and, critically, change it anywhere the same password was reused. Reuse is what turns one old breach into a live break-in. If the account had no MFA, add it now.
Step 3, Turn on breached-password blocking (3 min)
Both major providers can reject known-compromised passwords automatically, this is exactly what NIST SP 800-63B recommends:
- Google Workspace: Admin console → Security → enforce password strength and length, enable password monitoring/alerts, and require 2-Step Verification.
- Microsoft 365 / Entra ID: enable Microsoft Entra Password Protection (blocks weak and banned passwords) and turn on security defaults or Conditional Access for MFA.
This stops staff from setting a password that’s already in a breach corpus, prevention that costs nothing.
Step 4, Subscribe to ongoing notifications (2 min)
On HIBP, use Notify me for individual addresses and, for a domain, opt into domain notifications so you’re emailed when a new breach includes your people. Free.
Step 5 (optional), Add continuous domain monitoring (2 min)
If checking manually isn’t enough and you want hands-off, domain-wide alerting across every mailbox, subscribe to HIBP’s Core 1 ($4.39/mo, 1 domain) or Core 3 ($36.99/mo, 5 domains). Larger MSPs step up from there. Compare on the pricing page.
What this does and doesn’t buy you
Frequently asked questions
How do I set up dark web monitoring for my business domain?
Can I monitor my whole domain for leaked credentials for free?
What should I do the moment a credential shows up as leaked?
Do I need to pay to block breached passwords?
Primary sources
- Have I Been Pwned: homepage breach counts & FAQ
- Have I Been Pwned: Domain search / subscriptions
- NIST SP 800-63B: Digital Identity Guidelines (Authentication)
- CISA & partners, Advisory AA22-137A: “Weak Security Controls and Practices Routinely Exploited for Initial Access”
- FTC: Cybersecurity for Small Business