The short version
- Email leak detection tells you which of your addresses was exposed — not just that you were in a breach, but which service leaked or sold your details.
- Aliases make it work. Each alias is used with one service, so a strange sender on it is a clear sign the address has escaped.
- EmailAlias watches this for you and flags odd senders and leak patterns on each alias — an early warning so you can switch off the leaked alias before the spam starts.
Email leak detection tells you when an email address you use has been exposed. Most people only find out when spam and scams start rolling in. The goal here is to find out sooner — and to know exactly which service leaked you. A normal inbox can’t do that, because everyone emails your one real address. EmailAlias can, because you give each service its own alias, so the mail arriving at each one is a clue. This guide explains what email leak detection is, how EmailAlias does it, and how to use it every day.
What Email Leak Detection Is (and What It Isn’t)
Email leak detection is any tool that watches for signs that one of your email addresses has been exposed — leaked, scraped, sold, or caught in a data breach — so you can act before it turns into spam or fraud. There are two main kinds, and it helps to know which one you’re using.
- Breach-database checks. Tools like Have I Been Pwned check if your address shows up in a known, published breach. This is useful, but it only works after a breach goes public — and since it watches your one real address, it can’t tell you which service leaked it.
- Per-alias detection. This kind watches the mail arriving at each of your addresses and flags anything odd. Because it’s tied to one alias, it can point straight at the service that leaked. This is what EmailAlias does.
One thing to be clear about: EmailAlias’s leak detection is not a breach database or a dark-web scan. It doesn’t prove a company was hacked. It’s an early warning based on who is emailing your aliases — a signal to go and look, not a final verdict. EmailAlias says exactly this in its own alerts, and so does this guide.
Why Aliases Make Leak Detection Possible
The whole idea rests on one simple fact about aliases. When you sign up somewhere with a dedicated alias, only that one service should ever email that address. So a stranger showing up on it is a real clue: the address has ended up somewhere it shouldn’t have.
Your real inbox can’t give you that clue. Everyone emails your real address, so an unknown sender there means nothing. An email alias has just one expected sender, which turns it into a quiet tripwire — the moment the wrong mail arrives, you learn something about the service you gave it to. For the basics of how the forwarding works, see how email aliases work.
How EmailAlias Does Email Leak Detection
EmailAlias checks every message as it arrives, and it looks for two things. Both run automatically, in real time, on the alias the mail was sent to.
1. Suspicious senders. For each message, EmailAlias gives the sender’s domain a risk score from 0 to 100. Well-known senders like the big mail providers score near zero. The score goes up when a domain looks dodgy: a risky top-level domain like .xyz, .top, or .tk; long or random-looking subdomains; scam words in the name; or a domain stuffed with digits and hyphens. A high enough score is logged as an exposure event on that alias.
2. Leak detection. EmailAlias also counts how many different senders hit one alias in a short time. An alias should only hear from one service, so if a dozen or more strangers suddenly email the same alias within about an hour, that’s what a leaked or sold address looks like. EmailAlias flags that alias as compromised so it stands out.

Both checks feed the same exposure log, and repeat mail from the same sender on the same alias is grouped for a day so one noisy sender doesn’t flood your view. And remember: a flag is a prompt to look, not proof. EmailAlias says so in its own alerts — “a heuristic signal, not a confirmed breach — review the sender before acting.” It shows you something worth a quick look, fast, without pretending to be certain.
How to Use Email Leak Detection in EmailAlias
The best part is how little you have to do. Leak detection is on for every alias by default — nothing to set up. You just read what it shows and act when something looks wrong. Here’s the routine:
- Let it run. Every message to every alias is scored the moment it arrives. You don’t tag senders or train anything.
- Check your dashboard. It shows a running count of exposure alerts across all your aliases — a quick sense of how much has been flagged.
- Open the exposure list. On the monitoring & analytics page, each event shows four things: the alias, the sender’s domain, a 0–100 risk score, and the time. That’s enough to see which service and how serious.
- Watch for email alerts. Higher-risk events also email you, so you don’t have to watch the dashboard. Alerts are rate-limited so a bad day doesn’t bury you.
- Act on the serious ones. If an alias is flagged for a service that shouldn’t be drawing strange mail, treat it as exposed and switch it off (how to, just below).
What you see depends on your plan. The free plan gives you basic leak detection: your most recent events and alerts for the highest-risk flags. Premium ($4/month) adds the full history, alerts for every event, and faster notifications. The detection runs the same on both — the difference is how much you can see and how often it emails you.
How to Read a Risk Score and What to Do
The 0–100 score is meant to be easy to read:
- Low (near zero). A known, trusted sender. The alias is fine — nothing to do.
- Moderate. Something’s slightly off about the sender. It may be harmless, but it’s worth a glance — especially if you didn’t expect a new sender on that alias.
- High, or a leak flag. A clearly suspicious sender, or lots of unknown senders on one alias. This is the one to act on.
When an alias is flagged high, acting is quick — because it’s an alias:
- Remember which service it belongs to. If you labelled the alias when you made it (always do), the source is obvious.
- Treat that service as having leaked your address. Breached, careless, or selling data — the result is the same for you.
- Switch off or replace the alias. Flip the kill switch and the problem stops at that one address, without touching your real inbox or your other aliases. Our guide on how to stop spam emails covers the switch-and-replace routine.
- Check anything you reused. If you reused a password or shared other details with that service, change them too. For the full checklist, see what to do after an email data breach.
Keep it simple: a flag means “go look,” not “you’ve been breached.” Check the sender first — a new but legitimate partner of the service can score moderate. The win is that you’re looking at all, at the right address, at the right time.
How You Benefit
Per-alias leak detection gives you four things a normal inbox can’t:
- Early warning. You often catch the odd sender or the burst of strangers before the full spam and phishing wave hits — time to shut the address first.
- You learn who leaked you. Over time you see which services respect your data and which don’t — and you can stop trusting the leakers with anything sensitive.
- An easy fix. The exposed address is just an alias, so reacting costs nothing: switch it off and move on. A leak of your real address, you can’t switch off.
- No effort. It runs on its own, on every alias, with no lists to keep. You get monitoring without doing any.
It also works well next to a breach-database check. Use EmailAlias to catch exposure as it happens and to know which service to blame, and keep something like Have I Been Pwned for confirmed public breaches. Between them you cover “which address is acting exposed right now” and “did my details show up in a known breach.” If you’re cleaning up existing exposure too, our guide to removing yourself from data brokers is a good next step.
Email Leak Detection Compared
Here’s how the common ways to spot an exposed address stack up.
| Approach | What it watches | Tells you which address leaked? | Real-time? | Needs the breach to be public? |
|---|---|---|---|---|
| Breach-database monitoring (e.g. HIBP) | Published breach dumps vs your real address | No | No — after the fact | Yes |
| Watching your own inbox for spam | Spam that reaches you | Rarely | No | No |
| Per-alias exposure intelligence (EmailAlias) | Senders arriving at each alias | Yes — the alias names the service | Yes | No |
None of these is simply “better” — they answer different questions. Breach-database checks are the go-to for confirmed public breaches. Per-alias detection is the only one that’s real-time and can name the exact service that leaked. The best setup uses both, which is why leak detection lives inside EmailAlias rather than trying to replace a breach scanner.
Honest Limitations
Email leak detection is worth having, but it’s fair to be straight about the edges:
- It’s a warning, not a verdict. A high score is a reason to look, and it can be a false alarm — a new but legitimate sender can score moderate. Always check before you act.
- It only sees mail that arrives. If a service leaks your address to a list that hasn’t emailed you yet, there’s nothing to detect until someone does. It catches exposure as it turns into mail.
- It’s not a breach database. It won’t tell you your details showed up in a specific public dump — that’s what a tool like Have I Been Pwned is for. Use both.
- Free plans see less. The free plan shows recent events and the worst alerts; the full history and alerts for every event are Premium.
None of this changes the core value. Per-alias detection is the only signal that’s both real-time and able to point at one service — and since the flagged address is an alias you can switch off (never your real inbox), acting on it is nearly free. For more on when to give out your real address at all, see whether you should use your real email online, and for the scams that follow a leak, the common types of phishing attacks.
Final Thoughts
Most people learn an address leaked only once the spam is already rolling in. Email leak detection moves that moment earlier and makes it specific: instead of “my email gets spam,” you get a real-time signal that names the service and lets you shut it off at a single address. EmailAlias builds this into every plan — automatically, with no setup — and keeps it honest: it’s an early warning, a nudge to look and act, not a claim that a breach happened. Give each new service its own alias, check your exposure view now and then, and when an alias lights up, switch it off. That’s the whole habit — and it makes your inbox the first place you hear about a leak instead of the last.
Frequently Asked Questions
What is email leak detection?
Email leak detection is any system that watches for signs an address you use has been exposed — leaked, scraped, sold, or breached — so you can react before it turns into spam or fraud. It comes in two forms: breach-database monitoring, which checks whether your real address appears in published breach dumps, and behavioural per-alias detection, which watches the mail arriving at each of your addresses and flags anomalies. EmailAlias does the second: it scores senders and spots leak patterns on each individual alias.
Does EmailAlias check breach databases like Have I Been Pwned?
No. EmailAlias’s exposure intelligence is not a breach database or a dark-web scan, and it doesn’t claim to confirm that a company was hacked. It’s a heuristic signal built from who is emailing your aliases — it scores sender domains for risk and flags when many unknown senders hit one alias. For confirmed public breaches, use a breach-database service like Have I Been Pwned alongside it; the two answer different questions and work well together.
How does EmailAlias know an alias has leaked?
Two ways. First, it scores the domain of every sender that reaches an alias from 0 to 100, raising the score for high-risk top-level domains, scam-like keywords, and machine-generated-looking domain names. Second, it watches how many different senders hit a single alias in a short window — if a dozen or more distinct, unfamiliar senders arrive within about an hour, that burst looks like a leaked or sold address, and the alias is flagged as compromised. Both run automatically as mail arrives.
What is a risk score?
It’s a 0–100 number EmailAlias assigns to the sender of each message that reaches an alias, based on heuristics about the sender’s domain. Known, reputable senders score near zero. The score rises for suspicious signals like risky top-level domains (.xyz, .top, .tk), deeply nested or randomised subdomains, scam-associated words in the domain, or names stuffed with digits and hyphens. A low score is normal, a moderate score is worth a glance, and a high score is a prompt to investigate that alias.
What should I do when an alias is flagged?
Recall which service the alias belongs to (labelling aliases at creation makes this instant), treat that service as having leaked or sold your address, and disable or rotate the alias. Because it’s an alias, that single switch stops the exposure at that address without affecting your real inbox or any other alias. If you reused a password or shared other details with that service, rotate them too. Remember the flag is a heuristic prompt to look — review the sender before acting.
Does email leak detection cost extra?
No — it’s built into every plan, including the free tier, and runs automatically with no setup. The difference is visibility: the free plan gives you basic leak detection with your most recent exposure events and alerts for the highest-risk flags, while Premium ($4/month) unlocks the full exposure history, email alerts for every recorded event, and tighter notification timing. The detection engine itself is the same on both plans.
Can email leak detection give false alarms?
Yes, and the product is upfront about it. The signals are heuristics, not confirmations, so a brand-new but legitimate sender on an alias can score moderate and a flag doesn’t prove a breach occurred. That’s why EmailAlias frames each alert as a heuristic signal to review rather than a verdict. In practice false alarms are cheap to handle: you glance at the sender, and if it’s fine you ignore it — no harm done, and the genuine signals still surface early.
Is email leak detection the same as spam filtering?
No. Spam filtering decides whether an individual message is junk and where to put it. Email leak detection asks a different question: has this address been exposed, and which service is responsible? It looks at patterns across the senders reaching each alias — sender reputation and sudden volume from unknown senders — to warn you that an address has leaked, so you can shut it down. The two are complementary: filtering handles individual junk mail, leak detection handles the exposure behind it.
