
Zero. That's how many of the free browser add-ons and homepage widgets promising to "scan the dark web for your data" actually touch anything on the dark web. Most of them just check your email against a breach database sitting on the regular, indexed internet, which sounds like a letdown until you realize that's usually where the useful information already is. A real dark web scan, the kind that crawls forums and marketplaces directly, is slower and messier, and it's mostly the domain of paid privacy tools with a research team behind them. The free layer still catches the two things that matter most for basic data removal: old passwords and the broker sites currently listing your name.
Quick disclosure before the walkthrough: this site runs on affiliate links, and if you sign up for a service like Proton through one of mine, I get a small commission at no extra cost to you. None of that changes what follows — about two years of testing removal services against free tools side by side is what this is built on, and it covers the dark web and the open web both, most of which costs nothing to check yourself.
What a Free Dark Web Scan Actually Checks
Start with a breach-database lookup, not a broker search. Have I Been Pwned remains the standard for this — enter an email address and it tells you which verified corporate breaches included that address, sometimes going back over a decade. It reads like a property record lookup: dry, factual, no drama. Running my own consulting email through it turned up three matches, one from a marketing forum I hadn't logged into since the mid-2010s, which is a decent reminder that a breach doesn't need to be recent to still be useful to whoever's holding the file.
Google's "Results About You" tool is the second stop, and it matters more for people-search sites than for breach data. It only surfaces what shows up in a Google search of your name, not what's buried on a broker site that doesn't rank well, but it lets you file removal requests straight from the results page. A search of my own name a while back turned up a home address and my wife's maiden name spread across three different people-search sites, which is a fairly ordinary result, not the personalized targeting the marketing copy tends to imply. That short list is really just the visible edge of a much longer broker industry — worth its own separate breakdown, but not this one.
Why Do the Same Broker Listings Keep Coming Back?
Data brokers don't stay quiet just because a removal request went through. PeopleFinder pulled my address down after one opt-out, then re-listed it twice more before the change actually stuck, and the whole cycle ran close to three months from the first request to the listing finally staying gone. That kind of re-listing is common enough to be basically its own topic, why a broker keeps re-adding a name it already dropped, and it's the main reason a single scan or a single opt-out round isn't the end of the process. It's the first pass in an ongoing one.
Decide Between Manual Opt-Outs and a Paid Removal Service
Once you've checked the free layer, decide whether you want to run broker removal by hand or pay someone to file the requests for you. Both paths land in the same place eventually; they just cost different amounts of your own time. I keep Proton running in the background for the mail side of this, Mail, VPN, Drive, and Calendar under one account, and its built-in monitoring only pings me when a genuinely new data breach includes an address I actually use, which is quieter than the antivirus suite I tried and dropped after a month of near-daily "your identity is at risk" alerts that turned out to be the same three-year-old leak repackaged. A breach alert like that only tells you a leak happened, though. Getting a broker to remove a current listing is a separate job, and that's what a service like DeleteMe is built for, it files the requests, follows up when a site ignores the first one, and reports back on what actually came down.
The manual route is real and free, but it takes longer than most people expect going in. I spent part of one weekend working through a two-year-old opt-out spreadsheet someone had posted in a Facebook privacy group, and roughly a third of the links pointed to opt-out pages that had since moved or been redesigned, one broker's form looped me through the same verification puzzle three separate times before it would accept the submission. Who actually sticks with the manual path varies. A guy I know from a privacy subreddit, Seth Calder, still opts out by hand on principle even though he could afford any service on the market — he wants to see exactly what each broker asks for before handing that job to software. My neighbor Jonah Becker is closer to the opposite case: a financial planner who shrugged off every suggestion I made for months, right up until his own name turned up somewhere that put his business at risk. He brought it up over coffee near The Domain like it was breaking news, and by the following weekend he wanted a service already running. Coverage varies by provider too, which matters more once you've actually compared what each one catches than any sticker price does.
Your Password Manager Should Flag Breach Exposure Too
Password managers are the other half of this checkup, worth pairing with whatever removal service you land on. RoboForm is the one I've kept on my own accounts, its security center cross-references stored logins against known breach lists and flags anything that needs a fresh password, which is a smaller, more useful signal than a generic dark web alert. Clipping a hardware key to your keychain adds a layer that a leaked password alone can't get past, and that pairing is genuinely its own topic worth reading up on separately. None of this replaces a VPN, either, a VPN protects what happens on the network in front of you, like a shared coffee-shop connection, not what a broker already has filed away behind the scenes, and mixing those two up is a common mistake. If you're setting this up for a household rather than just yourself, I put together a longer breakdown in my guide to data removal services for family protection, since coverage per person changes the math.
Wiping Local Data Is a Different Job Than Broker Removal
Broker removal and local data cleanup solve two different problems, and it's easy to handle one while forgetting the other. Before selling an old laptop, I ran EaseUS BitWiper to wipe the drive properly, a standard delete or even a factory reset can leave recoverable files behind, and a one-time wipe tool closes that gap without adding another subscription to the pile. That's strictly a local problem, though; it has nothing to do with what a broker already has stored on its own servers, and keeping that distinction straight matters so you don't assume one fixes the other. If you're still deciding whether the manual opt-out route or a paid service makes more sense for your own situation, I laid out the actual time cost of each in my comparison of manual opt-outs versus paid removal services — the short version is that manual only wins if your time is worth less to you than the subscription, and most people underestimate how many hours the manual path actually takes.
What To Do Once You Find Something
A scan or a removal report only matters if it changes what you do next. If a breach alert shows up for an account you still use, change that password immediately and check whether the same password shows up anywhere else, reused passwords are the actual mechanism behind most account takeovers, and a dark web check is really the detection step that has to happen before you know which accounts need locking down in the first place. If the exposed data leans more toward broker listings than passwords, home address, relatives, phone number, that's when starting a removal cycle makes sense, whether that's Incogni running requests under CCPA and GDPR rules, or a broader service doing the same job. I've stuck with DeleteMe the longest for that particular task, mostly because the removal reporting makes it easy to see which brokers actually stayed quiet after the first pass and which ones need watching. None of this needs to feel urgent. Treat it the way you'd treat a credit freeze — set it up once, let it run, and check back periodically instead of refreshing the results every week.