xonPlus Logo
Whose domain is it? A signpost with two arms: your own domain points left to a free XposedOrNot dashboard with exposure tiles and acknowledged alerts; other people's domains point right to a xonThreatIntel+ partner console with isolated tenant rows.
Guide9 min read

Free vs Paid Breach Monitoring: Exactly Where We Draw the Line

Your inbox. Your company's domain. The old brand domain you still own. Free. Your clients' domains, your users' domains, a domain list that belongs to somebody else. That's where we send an invoice.

One question settles it, and it isn't "how many domains" or "how many alerts". It's whose domain is it?

If it's yours, everything on xposedornot.com is open to you without a card or an account: the email check, the breach catalog , domain monitoring with alerts, the dashboard, the community API. If it's someone else's, the product is xonThreatIntel+, and as of 11 September 2026 it starts at $99 a month for up to ten domains.

Same breach index on both sides. 783 breaches, 11,621,497,431 records. We pulled that from our own public endpoint on 11 September 2026, and you can pull it too. What changes is who the domains belong to.

That's the line. The rest of this post is the reasoning, the edge cases, and the bit about what the money buys, because "same data" begs an obvious question.

Your own domain costs nothing

People arrive on the free side expecting a paywall somewhere. A "see the other 40 results" button. A locked report. Support has actually had tickets asking where the upgrade prompt went.

Nowhere. It doesn't exist. What's open, with the limits that actually exist:

ToolWhat it doesWhere it stops
Email check Which breaches in our index hold this address, and which data classes each one exposed. Checked in memory, never stored.Nowhere. No account, no daily quota.
Breach catalog Every breach we've verified and indexed, with dates, record counts and data classes.Nowhere. The full list, not a teaser.
Domain monitoring Prove you own a domain, then get an email when an address on it turns up in a new breach.Domains you can verify. More than one is fine.
Breach dashboard Exposure overview per verified domain: executive block, yearly trend, top breaches, alerts held red until someone acknowledges them.Your domains only. Nobody else's.
Privacy Shield Take your address out of public search results. You can still check it yourself.One email at a time, confirmed by mail.
Community API The same lookups, programmatically. No key for most endpoints.2 requests a second per IP, plus hourly and daily caps. Domain endpoints need a key.

Verifying a domain works about how you'd guess. Pick one of five mailboxes on the domain, security@ or admin@ or webmaster@ or postmaster@ or hostmaster@, and we send it a one-time link. Thirty minutes to click it. Or a DNS TXT record. Or a file on the web root if DNS is locked. Ten minutes for the mail route, up to half an hour if you're waiting on DNS to propagate.

Then you give us a monitoring address on that same domain, and that's where the alerts go.

Seven domains? Verify seven. Nothing in that flow asks for money, and we're not going to pretend the dashboard is a trial.

Six free tools on XposedOrNot as a grid: email check, breach catalog, domain monitoring, breach dashboard, Privacy Shield, community API, each with its one real limit

Other people's domains are the paid product

Now flip it. You're an MSSP with 30 client domains. You're a SaaS product whose customers want breach exposure on their own dashboard, next to the other risk signals. You run IT for a dozen small firms and they've handed you their domain lists.

None of those domains are yours. You can't verify them by mailing postmaster@, because that mailbox belongs to your client. And you shouldn't be able to. The free route is built around proof of ownership, and ownership is exactly what a service provider doesn't have.

So the paid product is a tenancy model, not a data upgrade.

xonThreatIntel+ for MSSPs gives you one console over every client domain, each client isolated from the others, alerts and monthly reports under your own brand, and nothing of ours visible to the client if you don't want it there. The platform mode is the same thing without the dashboard: the API and SDKs, so the exposure picture lands inside your product.

Prices are on the site, read 11 September 2026:

PlanPer monthDomainsWhat's added
Basic$99up to 10Email alerts, API and CSV access, CXO dashboards
Growth$243up to 25Webhooks, JSON feeds, deep-dive analysis, same-day support
Ultimate$447up to 50Four-hour first response, advisory sessions, custom integration help

Monthly billing. No trial, a 30-day refund instead. 20% off on annual. Volume pricing above 50 domains is a conversation, not a form.

Could an MSSP verify each client domain on the free side instead, one at a time, with the client's cooperation? Technically, if every client hands over a postmaster mailbox and a monitoring address. We've watched two shops try. Both were back inside a quarter, because thirty separate dashboards with thirty separate alert mailboxes isn't monitoring, it's a chore list.

What the money actually buys

Not the data. We want to be blunt about that because vendors in this space love to imply the paid tier sees "more".

We keep one catalog. The breach that entered the index last week is visible to a free user checking their own address and to a paying MSSP checking a client's domain at the same moment. There's no premium feed, no held-back tranche.

What the money buys is everything around the data:

  • Tenancy. Fifty domains as fifty separate clients, none of them able to see each other.
  • Delivery. Webhooks and JSON feeds into whatever you already run, so an alert doesn't have to be a human reading an email.
  • Reports somebody else can receive. A PDF with your logo that a client can forward to their board. The reading guide walks through one.
  • A support desk with a clock on it.
  • The infrastructure bill, honestly. Keeping an index of 11.6 billion records fast and current isn't free for us, and the paid side is what pays for the free side.
Venn diagram: one breach index in the overlap, free tools on the left for domains you own, xonThreatIntel+ on the right for domains you don't, the data shared, the tenancy and delivery not

Where readers actually landed

The line sounds clean on paper. Here's how it played out for real domain lists people have sent us (details changed, shapes kept).

A freelance developer with one domain and a personal Gmail. Free. Verified by the email link, alerts to their own address, done before the coffee cooled.

A 40-person company with a main domain, a retired brand domain that still receives mail, and a regional .co.uk. All three theirs. All three free. The retired one turned out to be the interesting one (old brand, old signups, three breaches from 2016).

An IT consultancy looking after twelve client firms, no charge for the monitoring, "just as a favour". Still xonThreatIntel+. The test is whose domain it is, not whether you bill for it. They took the Growth plan and now hand each client a monthly report with their own name on the cover.

A SaaS company that wanted a "breach exposure" tile on every customer's settings page. Platform mode. Their customers never see us, and never verify anything with us either, because the SaaS holds the relationship.

Someone at a bank who wanted to know if their own work address had leaked, without involving IT. Free homepage check, no account, results in memory and gone. That's the use case the whole project started from.

Four situation cards, each stamped either FREE or TI+: freelancer, 40-person company, IT consultancy with client domains, SaaS product

The edge cases people email us about

Subsidiaries are the common one. A holding company that owns three operating companies, each with its own domain. Yours? Legally, yes. Verify all of them on the free side. If the holding company is instead a managed-services arm billing those companies, that's a client relationship in all but name, and it belongs on the paid side.

Agencies with a client's DNS access. You could verify their domain. Please don't. The alerts would go to a mailbox on their domain anyway, and the moment the relationship ends you're holding a monitor on a domain you no longer touch.

"Can I just use the community API for my product?" At two requests a second per IP, with daily caps, and with domain endpoints keyed, no. That tier exists for scripts, research and personal projects. If breach lookups are a feature your customers pay you for, the volume alone will move you across the line, and the platform mode is built for exactly that load.

The free snapshot on plus. Exposure check runs a point-in-time scan of any domain you type, with a PDF. No verification, because it's a snapshot, not a monitor. Useful for a sales conversation, useful for checking a vendor before you sign with them. It doesn't alert you afterwards; monitoring needs ownership or a plan.

What people ask before they pay

Is domain monitoring on XposedOrNot really free, or is it a trial?

Free. Verify a domain you own at xposedornot.com/domain , pick a monitoring address on that domain, and alerts come by email for as long as the verification stands. No card, no account, no expiry we've set.

Do free users and paying users see the same breach data?

Yes. One index, 783 breaches and 11.62 billion records on 11 September 2026, served to both. The paid product adds tenancy, delivery channels, branded reports and support, not extra breaches.

I monitor client domains but don't charge for it. Am I still on the paid side?

Yes. The line is ownership. A domain you don't own is a client domain whether or not money changes hands, and the free route can't verify it for you without the client's own mailboxes.

What happens if I outgrow the free side?

Nothing you set up is wasted. The verified domains, the alert history, the dashboard, all stay. Moving to xonThreatIntel+ happens when the domains stop being yours, not when your own list gets longer.

Is there a free trial of xonThreatIntel+?

No. There's a 30-day refund on any plan, and the Basic plan is $99 a month with monthly billing, so a month is the trial.

If we drew it wrong for you

The line is by ownership because ownership is the one thing we can verify and you can't fake. We've said no to money because of it (a prospect wanted to pay for a single own-domain monitor with a support SLA, and the honest answer was that the free route already did the job). And we've moved people the other way, off a free setup that was quietly monitoring domains they didn't own.

Not sure which side your domain list lands on? Send it to us. We'll say which, and "don't pay us" is an answer we give more often than you'd think.

Start with the setup guide if the domains are yours. Start with the MSSP page if they aren't.

Sources, with dates