Introduction
Business Data Breach Scanner monitors all email addresses under your company domain to help you quickly detect and respond to data exposures. Once configured, it tracks your entire domain—for example, monitoring acme.inc would alert you if addresses like john.smith@acme.inc, ceo@acme.inc, or finance@acme.inc appear in dark web breaches.
Note: Organizations have a domain limit: Enterprise organizations - 10 domains, Business organizations - 1 domain. If you’d like to add more, please contact our sales team at sales@nordpass.com.
This guide explains how to set up the Data Breach Scanner for NordPass Business to monitor whether any company email addresses under your domain have appeared in known data breaches.
Before you start
A domain host is an internet service that manages your domain name, such as 'www.example.com'. Domain hosts use Domain Name System (DNS) records to connect your domain name with email, websites, and other web services.
If you don’t know your DNS provider, check your domain host (GoDaddy, NameCheap, Google Domains), or use MXToolbox (select DNS lookup) and enter your domain.
Also, add the DNS entry for the top-level domain, not a subdomain. Usually, that is done by either leaving the subdomain empty or using @ sign in “Name” or similar value.
Here's what to do
- Navigate to the Admin Panel for Business as an organization's owner.
- Next, select the "Settings" button on the left, then click the "Admin Panel" button.
- Click the "Data Breach Scanner" button, then select the "Add Domain" button.
- In the new window, enter the domain name you want to monitor, then click the "Save" button.
- Copy the exact generated DNS TXT snippet.
- In your domain’s DNS configuration, create a new TXT record and paste the snippet as the TXT value.
Note: The TXT record must contain only the NordPass verification code. If the TXT record value contains anything else, verification will fail. If you must, create a new TXT record. Enter “@” as the hostname or leave it blank.
- Optionally, manually check if the TXT entry was added correctly using a DNS lookup tool (for example, ViewDNS). Enter your domain and confirm that the NordPass verification code appears under the TXT records.
- After you add the TXT entry, NordPass will periodically check it in the background and email you when verification succeeds or fails.
- Wait for verification to complete. DNS TXT verification usually takes minutes, but in rare cases, it may take up to 72 hours, depending on your domain host.
- If you lose your DNS TXT record, you can view it again by selecting the "Three-dots" button next to your chosen domain and selecting the "Show details" button.
- Additionally, you can permanently stop domain monitoring by pressing the "Delete" button and selecting "Delete" again to confirm your choice.
Additional Tips
- If you can't verify your domain, it may be because of one of two reasons:
- Your TXT record setup may be incorrect. The TXT record must contain only the NordPass verification code. If the TXT record value contains anything else, verification will fail. If needed, create a new TXT record with the hostname “@” or an empty value.
- If you can't start or retry verification, the domain may already be on a list, or there may be a system error. In this instance, we recommend reaching out to our support team with your query, and we will look into it immediately.
- If your data was breached, we recommend checking out our guide on how to handle a data breach incident.
- If the domain is unknown, we cannot provide further clarification with that specific entry. This occurs because data found on the dark web can be incomplete - we may find out about the total scope of data categories, but the data itself may be missing. In either case, we will inform you when we find your email address or credit card, regardless of the data's completeness. Please change any passwords you may be using with the exposed credentials.