Breach lookup is a different job than username search. Username search asks whether an account exists on a platform. Breach lookup asks what has already leaked about a selector: an email address, a handle, a domain, a phone number. The corpora are different, the pricing is different, and the free tiers fail in ways that are worth knowing before you spend money.
So we signed up for four of them on the same day and ran the same selector through each. The selector was richard. DeHashed returned 81,295 rows from 24,051 data wells across an index of 24,116,034,155 assets. LeakCheck's anonymous public endpoint returned 1,000, which is its public cap, drawn from 119 named breach sources. Snusbase let us create an account in seconds and then refused to search anything without a paid plan. Intelligence X rejected the query outright, because it is not a username product.
Disclosure up front: we build Revealer.US, including our own data breach lookup and stealer logs products. Assume bias and check our work. Every number below came out of a real session on 2026-08-26, not a vendor datasheet. The competitor sections are written straight, because a benchmark that flatters the author is worthless.
How we tested
One selector, deliberately common. richard is a name thousands of people use as a handle and as the local part of an email address. Common selectors punish sloppy indexing and expose result caps fast, which is exactly what we wanted to see. A rare selector makes every tool look precise.
Free tier first, then whatever the vendor forces. We started with each platform's cheapest reachable path: anonymous search where offered, free account where required. When a wall appeared, we recorded the wall instead of routing around it. The wall is the product for most people evaluating these tools.
Counts as each tool reports them. DeHashed reports results, data wells, and total indexed assets. LeakCheck reports a found count and a source list. Those are not the same units, and we do not pretend they are. Every hit rate below is a tool measured against its own index, never against another tool's.
One run each, on one day. Breach corpora grow weekly and stealer log feeds grow daily. Treat these as a snapshot with a date on it, not a permanent ranking.
The scoreboard
| Platform | Sources checked | Rows returned | Hit rate | Tier used |
|---|---|---|---|---|
| DeHashed | 24,051 data wells | 81,295 | 0.00034% of 24,116,034,155 assets | Free (values redacted) |
| LeakCheck | 119 sources in result, 1,382 advertised | 1,000 (public cap) | Not measurable, capped | Free public endpoint |
| Snusbase | Not shown | 0, search is paid gated | n/a | Free signup, no free search |
| Intelligence X | Selector based, not username | Invalid Search Term | n/a | Signup blocked by captcha |
Rows returned for the selector richard, one run each:
Two of the four bars are stubs on purpose. Snusbase and Intelligence X did not fail our test, they declined to take it, and the reasons are different enough to matter. Snusbase sells search and will not give any of it away. Intelligence X is a selector engine that does not accept a bare handle as a selector at all.
Why 81,295 rows on a 24 billion row index is the interesting number
DeHashed's own counters are the most honest thing in this test. 81,295 results out of 24,116,034,155 indexed assets is a hit rate of roughly 0.00034 percent. That sounds like a rounding error until you remember what the denominator is. Twenty four billion assets is the aggregate of thousands of breach dumps, combo lists, and stealer collections. Any selector that pulls five figures out of that pile has a real footprint somewhere in it.
The number that actually drives your workflow is 24,051, the count of distinct data wells the hits came from. That is the triage problem in one figure. Nobody reads 81,295 rows. What you do instead is sort by source, recognize the corpora you trust, and work those first. DeHashed's per row source attribution makes that possible: our result set named Zynga, Adobe, Twitter, Apollo, and ApexSMS among thousands of others, and each of those tells you something different about the identity behind the row. An Adobe row is a 2013 artifact. An Apollo row is B2B enrichment data. An ApexSMS row is an SMS spam operation's own leak. Same selector, wildly different evidentiary weight.
This is also where a common selector does its job. richard is not one person. A five figure result count on a common handle is a research surface, not an identity. Filtering it down to a single subject requires a second selector, which is the pivot most of these tools make you perform by hand.
1. DeHashed: the deepest index, and the most honest free tier
DeHashed is the reference implementation of this category, and our run backs that up on volume. 81,295 rows, 24,051 data wells, per row source attribution, and a visible index size so you can judge the denominator yourself. Few vendors in this space publish anything that checkable.
The free tier is a real search that returns real structure. What it does not return is content. Every result row came back with has_access: false and the field values redacted. You see that a row exists, which breach it came from, and which field types it carries. You do not see the password, the hash, the phone number, or the address until you pay. That is a defensible design, and it is more useful than most free tiers, because a redacted result set is still a source map. You can decide whether the corpora that matched are worth a subscription before you buy one.
Where it stops: DeHashed hands you rows, not conclusions. There is no correlation layer that says these 40 rows are probably the same person and these 81,000 are not. Sorting a five figure result set into identities is the analyst's job, and on a common selector that job is most of the work.
2. LeakCheck: fast, well structured, and capped where it counts
LeakCheck's anonymous public endpoint is the easiest thing to try in this entire category. No account, no key, one HTTP call:
GET https://leakcheck.io/api/public?check=richard
That call came back with found: 1000, 119 named breach sources, and 19 fields per hit. Nineteen fields is a genuinely rich schema for a free endpoint, and the source list is specific enough to be actionable. The site advertises 1,382 sources indexed overall, so the 119 that appeared in our result is the slice that matched, not the size of the corpus.
The catch is that 1,000 is a cap, not a count. The public endpoint stops there regardless of how much more exists, which means you cannot use it to measure a selector's footprint the way DeHashed's counters let you. It answers "is this selector exposed" with a fast yes. It cannot answer "how exposed." Full reports, and uncapped counts, start at the Basic plan at $2.99 per day.
Treat the public endpoint as the best free triage tool in this test and nothing more. It costs one request, it returns structured JSON, and it tells you in under a second whether a selector is worth escalating. That is a legitimate slot in a workflow.
3. Snusbase: instant signup, zero free search
Snusbase's onboarding is the smoothest of the four. Account creation was instant, with no captcha and no email verification loop in our window. Then we typed a query and got the wall: "To search you need to have an active plan."
There is no free search tier at all. Not a capped one, not a redacted one, not a teaser. Plans start at $6.49 for seven days, which is cheap enough that this is not really a complaint, but it does mean you cannot evaluate the data before you buy it. You are paying to find out whether the index covers your case.
Snusbase has a good reputation for query flexibility, wildcard and regex style matching, and speed. We cannot confirm any of that from this run, because we did not buy a plan for this test, and we are not going to report numbers we did not measure. What we can report is the shape of the offer: fastest signup, hardest paywall, lowest entry price of the paid three.
4. Intelligence X: a different tool that people keep putting on the same list
Intelligence X belongs in almost every OSINT roundup and does not belong in a username benchmark. It is a selector based search engine and archive: you feed it an email address, a domain, a phone number, an IP range, a bitcoin address, or a document hash, and it searches its own historical crawls of the web, darknet, document leaks, and paste sites. Feed it a bare handle and it tells you what it told us: Invalid Search Term.
That is not a bug. The product's entire model is built on selectors it can normalize and index. A word is not a selector.
We also could not get through signup in our window, because the registration flow is gated by an image captcha. So this section carries no numbers and makes no claims about coverage. What it does carry is the caveat that keeps people from wasting an afternoon: if your input is a handle, this is the wrong tool. If your input is a domain or an email address and you want historical archives rather than credential rows, it is one of the few products that does that at all. We go deeper on it in our Intelligence X alternatives piece.
Where the free tiers all stop in the same place
Line the four up and a pattern shows up that has nothing to do with index size.
DeHashed gives you rows without values. LeakCheck gives you values without volume. Snusbase gives you nothing without a card. Intelligence X gives you a different product entirely. Every one of them, on the free path, hands you a fragment and leaves the assembly to you.
The assembly is the part that costs analyst hours. A breach row is a lead. A stealer log entry is a lead. An account on a platform is a lead. The case is built when those three point at the same person, and none of the tools above run all three in one pass. You run the username search in one tab, the breach lookup in another, the stealer log search in a third, and you correlate by hand.
That gap is the reason the next section exists, and you should read it with the disclosure in mind.
Revealer.US: breach rows, stealer logs, and account enumeration in one report
We build this one, so grade it against the numbers above rather than against our description of it.
The design choice that matters here is that a Revealer search does not treat these as separate products. One query runs account enumeration, breach dataset lookup, and infostealer log search together, and the results arrive in a single report keyed to the same selector. The pivot that costs you three tabs and a spreadsheet elsewhere happens inside one result set.
Two things fall out of that.
The stealer search surfaces email addresses. Infostealer logs are structured differently than breach dumps: they carry the victim's saved credentials, autofill data, and session artifacts, which means a search keyed to a username can return the email addresses that user had saved. That is a selector you did not have before the search, and it is the single most useful pivot in this whole category. A handle gets you into the corpus. An email address gets you a person.
Correlation is scored, not left to you. When account enumeration, a breach row, and a stealer entry all point at the same identifiers, that agreement is visible in the report instead of being something you reconstruct from three exports. On a selector like richard, where a raw breach search returns five figures of rows belonging to thousands of different people, the correlation layer is the difference between a research surface and a lead.
Start on the free tier. Paid self serve runs from $12.99/mo on pricing, with an API for pipelines. Entry points: username search, data breach lookup, stealer logs.
Revealer is not a consumer reporting agency, and its data may not be used for employment, tenant, credit, or insurance eligibility decisions.
How to choose
| You need | Start with |
|---|---|
| The deepest raw breach index with source attribution | DeHashed |
| A one request free check on whether a selector is exposed | LeakCheck's public endpoint |
| Cheap short term paid access with flexible queries | Snusbase, from $6.49/7 days |
| Historical archives keyed to a domain, email, or hash | Intelligence X |
| Breach rows, stealer logs, and accounts correlated in one report | Revealer.US |
| API access for a pipeline | Revealer.US (see API docs) |
Two rules survived this test. First, never conclude from one corpus, because a selector missing from one index is almost always a coverage gap rather than evidence of anything. Second, count what the tool actually shows you: a capped 1,000 and an uncapped 81,295 are not comparable numbers no matter how the marketing page frames them.
For adjacent ground, see our DeHashed alternatives breakdown, the Have I Been Pwned alternatives rundown, and the username side of the house in best osint.industries alternatives.
Frequently asked questions
Which breach lookup tool returned the most results? DeHashed, with 81,295 rows from 24,051 data wells for the selector richard, against a published index of 24,116,034,155 assets. LeakCheck's anonymous endpoint returned 1,000, which is its public cap rather than a true count.
Is there a free data breach lookup that actually returns data? LeakCheck's public endpoint is the closest: no account, one GET request, 19 fields per hit across 119 matched sources, capped at 1,000 results. DeHashed's free tier returns the rows and their sources but redacts the field values until you pay.
Why did DeHashed show such a low hit rate? Because the denominator is enormous. 81,295 results out of 24.1 billion indexed assets is about 0.00034 percent. That figure describes index size, not accuracy. What matters operationally is the 24,051 distinct sources those hits came from.
Can I search Intelligence X by username? No. It is a selector based engine that takes emails, domains, phone numbers, IPs, hashes, and similar normalized inputs. A bare handle returns Invalid Search Term. Use it for archive and document leak work keyed to a domain or address.
What is the difference between breach data and stealer logs? Breach data comes from a compromised service and describes accounts on that service. Stealer logs come from malware on a victim's machine and describe everything that victim had saved: credentials across many sites, autofill data, and session artifacts. Stealer logs are usually fresher and often expose selectors, including email addresses, that no breach dump contains.
Can I use these tools for background checks? Not Revealer. It is not a consumer reporting agency, and its data may not be used for employment, tenant, credit, or insurance eligibility decisions. Use an FCRA compliant provider for those purposes.