Check yourself

Monitor Every Domain You Own for Breaches, at Zero Cost

August 10, 2026
Free domain breach monitoring: three monitored domains, one showing a new breach alert

Your company almost certainly has breach exposure right now.

Not because your systems were hacked. Because your people signed up for things. Vendor portals. Conference apps. That project tool someone trialed in 2019 and forgot about. Each signup used a work email, and some of those services have since been breached.

I index 772 breaches holding 11.58 billion records, and company domains run all the way through them.

Here is the part that still surprises people: you can see your entire company’s exposure, across every domain you own, for free. No trial period. No credit card. No “talk to sales.” This post walks through the whole setup, start to finish, in about ten minutes.

What domain monitoring actually does

Checking one email tells you about one inbox. Domain monitoring answers the question a security lead actually has: across everyone who has ever used an @yourcompany.com address, what has leaked, from where, and how bad is it?

Once your domain is verified, XposedOrNot gives you two views of the answer. My Dashboard is home base, your own email’s exposure and all your verified domains side by side. The CxO dashboard goes deep on the company: every known breach touching your domains, how exposure has trended year by year, which breaches hit you hardest, and a per-email breakdown you can hand to whoever runs your resets. When a new breach lands in the index and your domain is in it, an email tells you.

An attacker doing reconnaissance on your company can already assemble this exact picture from public breach data. The only question is whether you see it too.

If you already know you want this, start at xposedornot.com/domain. Everything below is me walking you through it, screen by screen.

Step 1: Prove you own the domain

Ownership verification keeps this from being a stalking tool. Nobody gets your company’s exposure detail without controlling the domain. Head to xposedornot.com/domain (the Add Domain button on every dashboard lands here too) and pick a method:

Domain verification page with the three methods

Email confirmation is the two-minute option. We send a confirmation link to a standard admin address on the domain, you click it, done. Fastest when you have the inbox but not the DNS.

DNS record is what I’d pick, and what most security folks pick. Add a TXT record we give you to your DNS and we check for it. Takes maybe ten minutes, most of which is waiting for DNS to do DNS things. The click-by-click guide, including what the TXT record looks like in your registrar, is in our DNS verification walkthrough.

DNS TXT record creation from the walkthrough

And if DNS and the admin inboxes both belong to another team? HTML file upload: drop a small verification file on your web root and skip the internal ticket entirely. Guide here.

Whichever you choose, repeat it for each domain you own. Old brand domains and acquired-company domains are worth adding too. Their exposure is your exposure now.

Step 2: Read your dashboards

You get two, and they answer different questions.

My Dashboard: you and your domains in one place

My Dashboard is where you land after signing in. It puts your personal exposure and your company domains on one screen: a risk score with the reasoning spelled out underneath (not just a scary number), your breach history on a timeline, and a “What to do next” list that turns all of it into two or three concrete moves. I built that list because data without a next step is just anxiety.

My Dashboard overview with risk score

Your verified domains sit in the same sidebar. The Domains view is the compact company picture: exposure per domain, the breaches that touched them most recently, your most exposed addresses, and a one-click jump into the full CxO dashboard when you need the long version.

My Domains view inside My Dashboard

The CxO dashboard: the company-wide picture

The CxO dashboard is the view you put in front of leadership. Four things to look at, in order.

First, the exposure overview. Total breached emails across your monitored domains. Don’t panic at the raw number; almost every company past a certain age has one. What matters is what follows.

CxO dashboard exposure overview

Second, executive exposure. How many CxO, VP, and director addresses appear in breaches. These are the accounts attackers try first, because that is where wire transfers get approved. If this row is anything but zeros, those resets happen today.

Executive exposure tiles

Third, the trend and the top five. Is your exposure mostly historical, or still growing? Industry-wide, 2026 is on a record pace, so “still growing” is the common answer. A spike in a recent year usually traces back to one big breach, and the top-five table names it. This is the moment “we should do something” turns into a specific list with breach names on it.

Yearly trend and top 5 breaches

Fourth, the per-email detail. Which addresses, which breaches, what data types. Sort by what leaked, because a password beats a marketing list for urgency every time (and a stealer-log hit has its own playbook). Current employees with leaked passwords come first. Then shared inboxes. Former employees’ addresses still matter if the accounts are alive anywhere.

Per-email breach detail

One more column worth your attention while you’re in there: each breach shows how it stored passwords, from plain text (bad) to hard-to-crack hashes (survivable). Same leak, very different urgency.

Step 3: Turn on alerts, and decide who acknowledges them

New breaches get indexed continuously. A one-time report would go stale in a month, so this isn’t one.

Enable alerts and, when a new breach touches your domain, an email lands in the verified inbox. Free tier, no catch. And here is the detail I care most about: the alert stays open until someone on your team acknowledges it.

Breach alert with acknowledged status

Not “we sent an email at 2am.” Someone saw it, owned it, closed it. Decide now who that person is. An alert nobody owns is a log line.

Prefer scripts and feeds over dashboards? The free breach-monitoring toolkit for sysadmins covers the API and RSS route to the same data.

Why is this free?

Fair question. Almost everywhere else, this exact capability is a paid product. Domain-level breach visibility usually gets packaged for enterprise security budgets: per-seat pricing, annual contracts, a sales call before anyone shows you a number. The customer those products have in mind runs a security operations center. Most companies do not.

My math works differently. Five employees or five thousand, ten exposed addresses or ten thousand: monitoring your own domains on XposedOrNot is 100% free. There is no threshold where I start charging you for your own exposure.

I spent years on the IT side of companies that would never have had a breach-monitoring budget. Places where one shared inbox was the security team. Those places deserve to know what leaked just as much as a bank does, and they are exactly who commercial threat intel never reaches. That is who I built this for.

Knowing your own exposure should not be a premium feature. And the whole free platform is open source, MIT licensed. Every line of it sits on GitHub if you feel like auditing me.

So what’s the catch? (What paid actually adds)

Not on visibility, there isn’t. Verification, both dashboards, the trends, the per-email detail, email alerts with acknowledgment: all of that sits in the free tier, permanently.

The paid tier, xonPlus, is operational plumbing for teams. Alerts routed into Slack or Teams instead of an inbox. Webhooks into your own tooling. One consolidated alert per breach event rather than a flood, VIP treatment for executive accounts, and the PDF and CSV exports your auditor keeps asking about. SIEM integration is missing from that list on purpose: the Sentinel connector is free and open source. A five-person team reading alerts by email may never need any of it. If you run a staffed security operations team, you will know when you do.

Common questions

How many domains can I add? Every domain you can verify ownership of. Add them all; separate legal entities, old brands, acquisitions.

What do you do with the emails you show me? We show them to the verified owner, alert that owner when new breaches land, and that is the whole business model: no resale, no marketing use, no third parties. Access is passwordless, via a magic link to the verified address. The breach data itself is already public; verification just controls who sees it organized. The code and the privacy policy are both public if you want to check.

A new breach just hit the news. When will my dashboard know? When it is indexed and verified. Speed varies by breach; the alert exists precisely so you don’t have to keep checking. In the meantime you can look any breach up by name.

I found hundreds of exposed addresses. Now what? Triage by data type, not by count. Leaked passwords for current employees first: reset them and check for reuse. Then review shared and service accounts. Old marketing-list leaks go last. The dashboard’s per-email detail gives you this ordering for free.

Ten minutes, once

Verify your domain this week. It is the highest-leverage ten minutes on your security calendar this month, and it costs exactly nothing.

Start here: xposedornot.com/domain

And if this is useful, drop us a star on the GitHub repo. It helps others find the project, and honestly, it makes our day.

Devanand Premkumar, founder, XposedOrNot

Appendix: Sources and references


Check out some of our posts for you.

Discover more from Data Breach Insights

Subscribe now to keep reading and get access to the full archive.

Continue reading