SmallBizSecurityTipsBreach & credential monitoring
Home / Guides / 15-minute setup
How-to

How to set up leaked-credential monitoring in 15 minutes (free + paid)

Updated August 2026 · independent comparison · primary sources linked

You can set up leaked-credential monitoring for your business domain in about 15 minutes, mostly for free. The short version: (1) search your domain and staff emails on Have I Been Pwned and force resets on any hits; (2) turn on breached-password blocking in Google Workspace or Microsoft 365; (3) subscribe to breach notifications; (4) if you want continuous domain-wide alerts, add HIBP’s paid domain monitoring (from $4.39/mo). Here is the exact sequence.

Before you startYou’ll need admin access to your domain’s DNS (to verify domain ownership for domain search) and to your identity provider (Google Workspace or Microsoft 365). Total cost to complete the free path: $0.

Step 1, Check what’s already exposed (3 min)

Go to haveibeenpwned.com and search your own work email and a few key staff addresses (owner, finance, admin). Note every breach listed. This is your starting exposure. For a whole domain, use HIBP’s Domain search, you verify ownership via a DNS TXT record or a file, then see every breached address on the domain.

Step 2, Force resets on every hit (5 min)

For each exposed account, reset the password to a unique, long passphrase and, critically, change it anywhere the same password was reused. Reuse is what turns one old breach into a live break-in. If the account had no MFA, add it now.

Step 3, Turn on breached-password blocking (3 min)

Both major providers can reject known-compromised passwords automatically, this is exactly what NIST SP 800-63B recommends:

This stops staff from setting a password that’s already in a breach corpus, prevention that costs nothing.

Step 4, Subscribe to ongoing notifications (2 min)

On HIBP, use Notify me for individual addresses and, for a domain, opt into domain notifications so you’re emailed when a new breach includes your people. Free.

Step 5 (optional), Add continuous domain monitoring (2 min)

If checking manually isn’t enough and you want hands-off, domain-wide alerting across every mailbox, subscribe to HIBP’s Core 1 ($4.39/mo, 1 domain) or Core 3 ($36.99/mo, 5 domains). Larger MSPs step up from there. Compare on the pricing page.

What this does and doesn’t buy you

Set expectationsThis setup gives you early warning and prevention of reused/weak passwords. It does not remove leaked data from criminal markets (nothing does, why), and it doesn’t stop session-cookie theft by infostealer malware, for that you also need endpoint protection and to invalidate sessions after any device compromise (details).

Related toolBreachTrigger is the simplest way to get an early warning when a public-company vendor, cloud provider or partner you depend on discloses a breach: it watches U.S. SEC EDGAR every ~30 minutes and alerts you the moment a company files an Item 1.05 “material cybersecurity incident” 8-K. It does not scan dark-web dumps for your own passwords, so it is not a like-for-like HIBP alternative, it solves a different problem: vendor and third-party breach early warning. See BreachTrigger → (free weekly digest; instant alerts from $199/mo).
15-minute result: exposed passwords reset, reuse killed, weak/breached passwords blocked going forward, and alerts on for the future, almost entirely free, with an optional ~$4.39/mo upgrade for continuous domain monitoring.

Frequently asked questions

How do I set up dark web monitoring for my business domain?
Search your domain and staff emails on Have I Been Pwned and reset any exposed passwords; turn on breached-password blocking in Google Workspace or Microsoft 365; subscribe to HIBP notifications; and optionally add HIBP domain monitoring from about $4.39/month for continuous, domain-wide alerts. The free path takes roughly 15 minutes.
Can I monitor my whole domain for leaked credentials for free?
You can check your domain and get notified for free using Have I Been Pwned's domain search and notifications after verifying ownership. Continuous, automated domain-wide monitoring is a paid subscription starting around $4.39/month, but the initial check and future breach alerts cost nothing.
What should I do the moment a credential shows up as leaked?
Reset that password immediately, change it everywhere it was reused, and enable MFA on the account if it isn't already on. If the leak came from an infostealer infection, also invalidate active sessions and scan the affected device, because stolen session cookies can bypass MFA.
Do I need to pay to block breached passwords?
No. Breached- and weak-password blocking is built into Google Workspace (password policies and monitoring) and Microsoft 365 / Entra ID (Entra Password Protection). NIST SP 800-63B recommends checking new passwords against breach corpora, and both providers can do it at no extra cost.