Support desk — Monday to Friday, 08:30 to 17:30Client AreaGet help now →

Watch your domains for breaches with uBreach

Watch your domains for breaches with uBreach – EasyLifeIT guide
For IT administratorsAbout eight minutesusecure

uBreach tells you when an email address on your domain turns up in a known data breach. That is useful and it is also widely misunderstood, because most alerts are old, most are somebody’s LinkedIn password from 2012, and a few are genuinely urgent. Knowing which is which is most of the skill.

Licensing first

Domain monitoring is uBreach Pro only. On standard uBreach you get user level monitoring but not the domain wide view. Worth checking before you promise a client a monthly domain report.

Adding a domain

  1. Open the settings. Go to Settings and open the uBreach tab.
  2. Add the domain. There is a Monitored Domains box. Type or paste in the domains you want watched, click Add, then Save.
  3. Go and look. Open the uBreach page and scroll down to the Domains tab.

Add every domain the business owns, not just the one people email from. Old trading names, the domain from the company you acquired, and the one that only exists to redirect to the main site all have mailboxes behind them more often than anyone remembers.

The three views

View What it shows you
Breaches Breach name, severity as low, medium or high, the breach date, how many of your people are in it, how many you have resolved, and what information was exposed
Domains Per domain: last breach date, breach count, how many users are affected, how many resolved. Pro only
Users Name, email address, when it was resolved, and the option to look at the detail or mark it resolved

The column that decides what you do is exposed information. An email address and nothing else is noise. An email address and a password, or a password hash, is work.

What to do when an alert lands

  1. Read what was actually exposed. If it is just an address in a marketing list, note it and move on. If a password was in it, keep going.
  2. Find out how old it is. A 2016 breach where the person has changed their password twice since is not an emergency. A breach from last month is.
  3. Assume the password was reused. This is the part that matters. The risk is almost never the breached service; it is that the same password is on your Microsoft 365. Get it changed there and anywhere else it is likely to have been used.
  4. Check the account for signs of use. Sign in logs, forwarding rules, registered authentication methods. There is a separate guide on what a compromised Microsoft 365 account looks like.
  5. Then mark it resolved. Not before. Mark Resolved is a record that you dealt with it, so it should mean you dealt with it.
The honest answer for most alerts

Most breach alerts need one action: confirm the person is not using that password anywhere that matters now. If multifactor authentication is on across the business, a leaked old password is an irritation rather than an incident. If it is not, every one of these is a live risk, and that tells you what to fix first.

How this feeds the risk score

usecure combines three things into a risk score, from 0 to 900, in five bands from very low to very high: breach exposure and how sensitive the exposed data was, phishing simulation behaviour, and training completion and scores. It has to be switched on in the report settings.

Two caveats worth holding on to. usecure states plainly that the component scores shown are not simply added together to produce the final number, so do not try to reverse engineer it for a client. And it lags: allow up to 48 hours after a simulation before the score moves.

Use it as a trend, not a target

A risk score is useful for showing a board that the direction of travel is right. It is much less useful as a target, because the moment a number becomes a target people optimise the number rather than the behaviour. Report the trend and the things behind it.

Common questions

A breach is listed for somebody who left years ago.
Remove them from the platform. Then check the mailbox has actually gone, because an orphaned licensed mailbox with a leaked password is worse than the alert.
We get an alert for the same breach repeatedly.
It will keep appearing until it is marked resolved. That is deliberate.
Should we tell the person?
Yes, and without blame. It is almost never their fault, it is usually a service they signed up to years ago, and the useful outcome is them changing a reused password rather than feeling caught out.
Can you monitor this for us?
Yes. If we run your usecure we will watch the alerts and come to you when one needs action, rather than you watching a dashboard.

If you need a hand

Call the service desk on 03333 22 11 00 or email support@easylifeit.com. If a current password has been exposed, ring rather than emailing.

Take this guide with you

A clean branded copy you can print or save as a PDF, with our service desk details on every page.

Get the PDF

Checked against usecure’s help centre, Monitor domains with uBreach, Find exposed users and credentials with uBreach and Introducing Risk Score, September 2026. The response steps are our own practice.

Found this useful?

We write these because the same questions keep coming up. If one of them is yours, the answer is usually a short conversation away.

Keep reading