Find your accounts

How to find every online account linked to your email address

Five free methods to find every account ever registered with your email address — inbox searches, connected-app lists, password manager exports, username lookups — and how to triage what you find.

Updated October 202611 min readFree to read, no signup

Nobody can list their own accounts from memory. Fifteen years of signups, abandoned side projects, one-off purchases and apps that no longer exist leave a trail that is far longer than anything you would guess. The good news is that you do not have to remember any of it — almost every account you ever created left a record somewhere you can still search. This guide walks through five methods, cheapest and highest-yield first.

Why you cannot just remember them

The accounts you can name are the ones you still use, and those are the ones that are least likely to hurt you. The dangerous ones are the opposite: a forum you posted on in 2011 under your real name, a shopping site that still has your old address, a startup that got acquired and quietly handed your record to somebody else.

Old accounts matter for three specific reasons:

  • They hold data you no longer control. A dormant account still has whatever you gave it — full name, address, phone number, date of birth, photos, payment details.
  • They are reused-password landmines. If an old account used a password you still use anywhere, a breach of that old service hands an attacker a working key. This is credential stuffing, and it is the single most common way personal accounts get taken over.
  • They are often still public. Search engines index old profiles for years. A bio you wrote as a teenager is one query away from anyone who knows your username.

Method 1: search your own inbox

This is the highest-yield method by a wide margin, and it costs nothing. Practically every service on the internet sends a welcome or verification email at signup, which means your inbox is an archive of your own registrations. The trick is searching for the language those emails use rather than for the company names you cannot recall.

inbox_sweep

  1. 01

    Search for signup and verification language

    In Gmail, run subject:(welcome OR "verify your email" OR "confirm your email" OR "activate your account") — then repeat with each phrase on its own, since subject lines vary. Also try "thanks for signing up", "your new account" and "complete your registration". In Outlook or Apple Mail, search the same phrases in quotes.

  2. 02

    Search for receipts and invoices

    Anything you paid for has a paper trail: "your receipt", "order confirmation", "invoice", "your subscription", "payment successful", "your order has shipped". This surfaces shopping and subscription accounts that never sent a welcome email.

  3. 03

    Search for password resets

    "reset your password" and "your password has been changed" catch accounts you used often enough to get locked out of — which is a good signal that the account mattered.

  4. 04

    Search by sender, not subject

    Try from:no-reply, from:noreply, from:support and from:accounts. Automated senders are where registration mail comes from, and scanning that list jogs memory in a way keyword search does not.

  5. 05

    Include spam, trash and archive

    Gmail excludes Spam and Trash from normal search; add in:anywhere to every query above. In Outlook, switch the scope to All folders. Verification mail lands in spam constantly, so this pass usually finds accounts the others missed.

  6. 06

    Repeat for every address you have ever had

    Old university addresses, a work address from two jobs ago, the throwaway you made for one purchase, aliases like [email protected]. Each one has its own set of registrations. If you have lost access to an address entirely, skip to the username method below.

Method 2: check your connected-apps lists

Every time you clicked "Sign in with Google", "Continue with Facebook" or "Sign in with Apple", you created an account without ever receiving a welcome email. Those accounts are invisible to an inbox search, but each identity provider keeps a list of them.

  • Google — myaccount.google.com/connections, listed as "Third-party apps & services".
  • Apple — appleid.apple.com, under Sign-In and Security, then "Sign in with Apple".
  • Facebook — Settings & Privacy, then Settings, then "Apps and Websites".
  • Microsoft — account.microsoft.com/privacy, under apps and services that can access your data.
  • X / Twitter — Settings and privacy, Security and account access, then "Apps and sessions".

Method 3: mine your password manager and browser

If you have ever let a browser or password manager save a login, you have a second registry of your own accounts.

  • A password manager — export to CSV from 1Password, Bitwarden, LastPass, Dashlane or Proton Pass. The export is a complete list of every site you deliberately saved.
  • Chrome and Edge — chrome://password-manager/passwords and edge://wallet/passwords, or Google Password Manager on the web.
  • Safari — Settings, then Passwords, or the Passwords app on newer macOS and iOS.
  • Firefox — about:logins.
  • Saved addresses and cards — the autofill section of the same settings pages. A saved shipping address often means an account you forgot you made.

Method 4: search on your username instead of your email

Methods 1 through 3 all depend on having access to the inbox or the device. Usernames work from the other direction, and that makes them better at finding the accounts you have genuinely lost: profile pages are public by design, so a username is checkable from the outside whether or not you can still read the email on file.

Most people reuse two or three handles across their entire life online, often with small variations. Write down every handle you can remember, including the embarrassing ones, and then:

  1. Try the obvious profile URL patterns directly: reddit.com/user/<handle>, github.com/<handle>, instagram.com/<handle>, medium.com/@<handle>. A page that loads is an account that exists.
  2. Search each handle in quotes on Google and Bing: "yourhandle". Add a second term you used in bios to cut the noise.
  3. Reverse image search an old profile photo. If you used the same avatar across sites, this finds accounts under handles you no longer remember.

Method 5: look yourself up the way a stranger would

Search your own name in quotes, then your name plus your city, employer, school and old phone number. Do the same on Bing and DuckDuckGo — they index different things. What comes back is your actual public footprint, which is not the same as the list of accounts you own: it also includes people-search sites that assembled a profile on you from public records without you ever signing up.

That second category needs a different fix. See how to remove your personal information from Google and the data broker opt-out list.

What to do with the list

A list of 80 accounts is paralysing, so sort before you act. Deleting the account that holds your home address matters; deleting a dead forum login does not, even though it feels productive.

triage

What you foundDo thisWhy
Unused, holds real data (address, phone, DOB, payment details)Delete the accountThis is the whole point. Nothing you gain from keeping it offsets the breach exposure.
Unused, holds nothing of valueDelete it anyway, but lastStill worth closing — it may share a password with something important — but it is the lowest-risk pile.
Still in use, profile is publicKeep it, lock it downStrip the bio, remove the real name, drop the location, and check what the profile exposes when logged out.
Cannot be deletedEmpty it, then rotateOverwrite the profile fields, change the email to an alias, set a unique password, and remove any saved card.
Appears in a known breachChange the password everywhere you reused it, firstDo this before any deleting. See how to check if your email was leaked.

Where the manual method runs out

The five methods above are genuinely the right place to start, and for a lot of people they are enough. They share one blind spot, though: each of them can only show you accounts that left a record you still control.

  • Inbox search finds nothing from services that never emailed you, or whose mail you deleted years ago.
  • Connected-app lists only show apps that are still connected.
  • A password manager only contains what you chose to save.
  • Checking usernames by hand across any meaningful number of platforms is hours of work with a high false-positive rate.

This is the gap Tracebase is built for. You add your email addresses and usernames, and it checks supported platforms for accounts that match, cross-references your verified email addresses against the public breach corpus, and returns what it finds with the removal steps attached. It never asks for a password to any of your accounts — it works from the outside, the same way the username method above does, just across far more platforms than you would ever check by hand.

Two things worth knowing before you try it. Breach results require you to verify the email address with a six-digit code first, because we will not run breach lookups on an address you have not proven you own. And the free tier is a preview: it shows you a handful of accounts and one breach record, with the rest counted but hidden. Full results and the removal guides are on the paid plan ($10/month, or $1 for the first month when the offer is running).

common_questions

Is there a single website that lists every account tied to my email?

No, and anything claiming to be one is overselling. There is no central registry of internet accounts — no company, including us, has a complete list. What is possible is checking a large number of platforms for a match on your email or username, plus searching the breach corpus. That covers a lot, but "every account" is not a promise anyone can keep honestly.

Can I find accounts made with an email address I no longer have access to?

Not through inbox search, which is why the username method matters. If you remember the handles you used, profile lookups work regardless of which email is on the account. For breach data, you can still check the old address — it is the address that appears in a breach record, not the mailbox.

Does checking my email address somewhere put it at more risk?

Checking it against a reputable breach database does not — your address is already in those records, which is the problem. What does carry risk is typing your address into a random "free account finder" site, which is often itself a lead-generation scheme. Stick to tools that say plainly what they do with the address.

How many online accounts does the average person actually have?

Published estimates land between roughly 70 and 240 depending on how the study counts and who it surveyed, which tells you mostly that nobody knows. The number that matters is yours, and the inbox sweep above is the fastest way to get it.

Should I delete old accounts or just change the password?

Delete, where you can. A unique password protects the account from being taken over, but it does nothing about the data already sitting in it — that data is still exposed if the company gets breached, sold or acquired. Rotating the password is the right first move for anything you reused credentials on; deletion is the actual fix.

Will deleting an account remove me from Google search results?

Eventually, and only for pages that actually disappear. Google re-crawls on its own schedule, so an old profile can stay in the index for weeks after deletion, and cached or archived copies can outlive it entirely. The removal request process is covered in how to remove your personal information from Google.

Keep reading

Rather not do this by hand?

Tracebase takes your email addresses and usernames, checks supported platforms for matching accounts, cross-references the public breach corpus, and hands you the removal steps for what it finds.

Start a scan

No account passwords needed · How Tracebase works →