Help center
Dark web and breach exposure
Watch mailboxes on your domain for appearances in breach data, read what was exposed, mark what you did about it, and watch a whole domain once it is cleared.
Updated · 3 articles
A breach is the one risk you cannot discover by looking at your own systems. DomainGuard checks the addresses you name against a breach index (XposedOrNot), re-checks them on a schedule, and pushes an alert to the app when a new breach lists one. Addresses are stored as hashes.
Articles
- Mailbox exposure monitoring - adding an address, cadences, the limits per plan, manual checks, and how addresses are stored.
- Reading an exposure - source, date, data classes, how passwords were stored, the next action, and marking it reviewed.
- Whole-domain monitoring - every mailbox at a cleared domain, and the waitlist.
Where
- Web: Security, Dark web.
- iOS: the Exposure tab.
- API/MCP:
/api/darkweb/*; toolsget_dark_web_status,run_dark_web_scan,get_dark_web_breach,add_dark_web_email,remove_dark_web_email,list_dark_web_domain_monitors,add_dark_web_domain_monitor,run_dark_web_domain_scan,get_dark_web_alert_delivery,update_dark_web_alert_delivery.
Plans at a glance
| Free | Starter | Pro | Enterprise | |
|---|---|---|---|---|
| Addresses watched | 1 | 5 | 10 | 50 |
| Scheduled re-checks (daily or weekly) | Yes | Yes | Yes | Yes |
| Manual checks | 1 a day | 5 a day | 10 a day | 50 a day |
| Push on a new hit | Yes | Yes | Yes | Yes |
| Email on a new hit | No | Yes | Yes | Yes |
What "exposure" means here
An exposure is a monitored address appearing in a dump the breach index knows about, with the breach's name, date and the classes of data it contained. It does not mean the mailbox itself was compromised; it means a service that held the address (and, often, a password used there) was. The next action is always the same shape: change the password anywhere it was reused, turn on two-factor on the mailbox, and expect phishing that quotes the leaked details.
What it is not
DomainGuard does not scan the dark web itself, buy dumps, or read mailboxes. It queries a public breach index by the hash of each address and caches the answer. "Nothing found" means the index has no record of the address, not that no breach exists.
Common questions
Why is a personal Gmail refused? Addresses must be at a domain on the account, or be the account's own sign-in address, so the feature watches your organisation's mailboxes.
Does a hit alert me by email? Push on every plan; email on paid plans, switched under Exposure, Email alerts.
In reading order
Articles in Dark web
- Mailbox exposure monitoringAdd an address at your own domain, choose a cadence, run a check now, and understand the plan limits, the upstream rate limit, and hashed storage.Updated
- Reading an exposureWhat an exposure detail shows (source, breach date, data classes, password storage), the plain next action, marking it reviewed, and asking for help.Updated
- Whole-domain breach monitoringWatch every mailbox at a domain, not just the ones you name. Needs scan clearance and the paid breach index; the waitlist while a domain is being enabled.Updated
Still stuck?
Ask the people who run the scanner.
Send the domain and what you expected to see. We look at the same scan you are looking at and write back with what it means and what to change.
