Toolbox
All of Shield404's checkers, free and with no sign-up. File and photo analysis happens on your own device: nothing is uploaded to any server.
When a company gets hacked, its users' data ends up circulating. Check if yours is in known breaches.
Criminals try already-leaked passwords first, everywhere. Your password NEVER leaves your device: it's compared using a technique called k-anonymity.
We query XposedOrNot, a service specialised in data breaches. Your email is used only for the query: we don't store it.
Check if it appears on web pages known to search engines (forums, published leaks, listings...). We never store it.
Paste an IP address (for example, one from a strange login attempt on your email or router) and we'll check it against known abuse lists.
Check your name, ID number or phone in the section above — the web exposure search is right there.
Many phone photos store the exact GPS location and the device model. Check before you post it — the photo is analysed in your own browser, and is never uploaded.
Paste the email's full technical headers (not just the text you read). In Gmail: open the email → the three dots (⋮) → "Show original" → copy everything. We detect whether the sender is spoofed by checking SPF, DKIM, DMARC and where your replies would actually go.
Did you receive an "invoice", a "quote", a "receipt", or a photo you weren't expecting? Check it before opening it. With photos, we also check whether it reveals your GPS location. The file is NOT uploaded anywhere: it's examined on your own device, and only its digital fingerprint travels.
Generated on your own device. It never leaves here.
Or an easy-to-remember phrase:
🧮 How long would it take to crack?
Tick what you've already done. We don't send anything anywhere: only you see your answers.