Treat the full nine digits as sensitive
A Social Security Number is a key that many systems still treat as proof of identity. It is not a membership card you flash to prove you exist. Every extra copy, photo, and email attachment is another place the same nine digits can be reused later.
Do not type someone else’s number into a public website, including this one. Use the tools on a public sample, or on your own number if you need a format check. Curiosity about a coworker, tenant, applicant, or relative is not a reason to paste their card into a browser.
This page stays on practical privacy: forms, the last four digits, data brokers, phishing, IdentityTheft.gov, and credit freezes. A format check is not a government match. That distinction lives in SSN validation is not verification. The limits of this website are on the site disclaimer.
Ask why a form wants all nine digits
Some requests have a real job. Payroll and tax withholding, a credit application you started, a government benefit, and some medical or insurance enrollments may need the full number. A gym waiver, a sweepstakes, a shipping form, or a “create your free account” checkbox often does not.
Ask two questions before you write all nine digits: why do you need the full number, and how will you store it? A clerk who cannot answer is a reason to pause. Many businesses can use the last four digits, an account number, a student or employee ID, or an in-person look at the card.
When you must give the number, write it yourself. Do not let a stranger photograph the card “for the file” if a written last four, or a photocopy you control, would do. On a website, read the address bar and the organization name before you submit. A logo is easy to copy. A hostname is harder to fake well.
If the company already has the number from a prior relationship, do not send it again by email “to confirm.” Point them at the account they already hold. A second copy in an inbox is a new copy, not a courtesy.
Watch the last four
Pay stubs, campus IDs, explanation-of-benefits letters, and patient portals often print only the last four digits. That redaction is better than printing all nine. It is not the same as making those four digits public property.
Before 25 June 2011, the first three digits followed a public state chart based on where the card was issued or the mailing ZIP on the application, not automatically the birth state. SSA also published a High Group List. Together with other public clues, that could sometimes narrow the first five digits. Randomization removed geography from new prefixes and froze the High Group List. It did not make the last four harmless.
The last four still identify a record when they sit next to a name, a date of birth, or an account. Treat them as a password fragment: acceptable over a phone line you placed to a company you already know, poor on a forum, a hallway badge, or a photo of a pay stub.
If a school, employer, or clinic still uses the last four as a default login or a public identifier, ask for a random student or employee ID instead. You are not being difficult. You are asking them to stop printing a key fragment on every letter.

Phishing, look-alike sites, and inbox requests
SSA, the IRS, and the nationwide credit bureaus do not send surprise emails or texts that ask you to type your full Social Security Number into a link. A message that threatens benefits, a lawsuit, a warrant, or a refund unless you “verify now” is a classic phish. Urgency is the tell. Official mail can wait a day while you check the hostname.
Read the domain, not the logo. Extra hyphens, swapped letters, and unexpected .net or .xyz hosts are enough reason to close the tab. If you think SSA really needs you, open a new window and type ssa.gov yourself. Do the same for IdentityTheft.gov instead of following a link in the message.
Do not photograph a card and send it by email, chat, or social DM because someone claiming to be HR, a landlord, a recruiter, or a “verifier” asked. Call the organization on a number from its official site or from a statement you already have. A voice on a new number is not a credential.
If you already typed the number into a page you no longer trust, treat it as exposed. Changing the password on that one site is useful and incomplete. Start at IdentityTheft.gov rather than waiting to see whether anything happens.
Data brokers and people-search listings
People-search and data-broker sites collect public records and marketed lists. Some listings have included a Social Security Number, or the last four, next to addresses and relatives. You did not have to post the number yourself for a listing to exist.
Opt-out forms are tedious and often expire. They are still worth filing with the largest brokers if your number, or a close family member’s number, has already appeared. Keep a short list of the sites you submitted and a calendar reminder to check them again. One afternoon of forms is dull. It is also finite.
A format website cannot scrub those listings for you. We do not sell people-search data, and we do not keep a leaked-number index. Paying a stranger who promises one-click “removal” is often another copy of the same file, plus a card charge.
If a listing includes the number, save the URL and the date. Include that fact when you start at IdentityTheft.gov. The site is for recovery steps, not for arguing with every broker in the same week.
What this site will do with a number you type
The checker on this site runs in your browser. It does not send the digits to our servers or put them in the URL. Clearing the tab clears the field. That is a privacy design, not a reason to paste a household roster or a tenant file.
Still use a device you trust. A shared computer, a screenshot tool, or a browser extension you do not remember installing can copy a field we never stored. Do not type someone else’s number here. Our tools are not a lookup of a person, and they are not cover for collecting one.
If you want to see how the tools behave, use the public samples in Famous sample Social Security Numbers. Those strings are famous because they were printed, not because they belong to a stranger you should look up.
A “possible” format result is not a government match and not a reason to gather more data about anyone. That line is also on the site disclaimer. For the difference between a local format check and official SSA channels, use the validation guide.
If a number is exposed, start at IdentityTheft.gov
IdentityTheft.gov is the FTC’s federal starting point. If someone already used the number, file a report and get an FTC Identity Theft Report and recovery plan. If it was only exposed, use the lost-or-stolen steps for freezes and monitoring. Do not invent a misuse report. Waiting for a perfect picture of the incident is how weeks disappear.
Write down what you know: the date you learned of the exposure, the company or inbox involved, and whether the full nine digits or only the last four were shown. You will reuse that note with SSA, the credit bureaus, and any bank or tax account you later call. One page of facts beats a pile of forwarded emails.
Do not pay a format website, a “dark web scan” upsell, or a look-alike SSA domain to file the report for you. IdentityTheft.gov is free. This site cannot file a freeze, a fraud alert, or an SSA record flag. We can only point at the official doors.
If tax refund fraud is in play, the IRS has its own identity-theft path. IdentityTheft.gov will point you there. Keep using official hostnames you type yourself. SSA’s current card and account pages live on the SSA homepage.
- Write what leakedthe date, the company or inbox, and whether it was all nine digits or the last four
- Start at IdentityTheft.gova free federal door, not a paid format site
- Freeze creditEquifax, Experian, and TransUnion, then lift a freeze only when you apply
- Ask SSA about the card or the recorda replacement card is not a reset of every copy already out there
Credit freezes and fraud alerts
A credit freeze tells a nationwide consumer reporting agency not to release your file to new creditors until you lift the freeze. Under current federal law, placing and lifting a freeze is free. You file with each bureau you care about, usually Equifax, Experian, and TransUnion. This website cannot file those steps.
A fraud alert is a lighter mark. It asks lenders to take extra steps to confirm it is you. An initial alert is shorter-lived than a freeze. An extended alert has extra requirements. Read the bureau’s current terms the week you file instead of memorizing a blog post.
Consider a freeze even if you are not sure the exposure was “that serious.” You can lift it for a day when you apply for credit. That is usually less work than closing an account you did not open. A freeze is paperwork, not a confession that something terrible already happened.
Keep the PINs or login methods the bureaus give you in a place that is not the same inbox that was phished. IdentityTheft.gov can remind you which bureaus to visit. Come back to this site for format questions, not for filing.
What SSA can do if a card or record is at risk
SSA can replace a lost or stolen card, review an earnings record, and, in narrow cases, discuss extra protections on a record. Current instructions live on the SSA homepage, including my Social Security. Type those addresses. Do not trust a search ad that looks similar.
A replacement card does not change the number. It only prints the same nine digits on a new piece of paper. If the card itself is gone, still treat the number as exposed and use IdentityTheft.gov plus a freeze. The new card is for you. It is not a reset of every copy already in circulation.
SSA does not take a consumer identity-theft report the way IdentityTheft.gov does. Card, benefit, and earnings questions belong at SSA. Credit and consumer recovery belong at IdentityTheft.gov and the bureaus. Many people need both, in that order: plan first, then the agencies the plan names.
A new Social Security Number is rare and tightly limited. Do not start there, and do not buy a third-party “new SSN” service. If SSA ever discusses that option, it will be on their site or in their office, not in a chat window. Replacement-card limits and document lists also change. Read SSA’s checklist the week you go.
Use public samples, not someone else’s card
If you are testing software, teaching a class, or trying this site’s tools, use a published sample. The history of 078-05-1120, 123-45-6789, and the other well-known strings is in the famous-samples guide. Those numbers are famous because they were printed.
Do not harvest a number from a pay stub, a tax form in a shared drive, or a relative’s wallet “just to see what the checker says.” That is someone else’s key. It also trains the people around you to treat the number as casual.
SSA tells advertisers to display 000-00-0000 rather than a lookalike card. If you publish a screenshot of any tool, crop the digits. If you file a bug report about this site, never paste a live number. A sample reproduces the bug just as well.
What this page will not do
This page will not walk through SSNVS, E-Verify, or a name-and-number match. That belongs in the validation guide. It will not tell you that a leak destroyed a life, or that a freeze makes you invisible. Recovery is a list of official forms. It is not a movie.
It will not accept a report, store a number, or call a bureau for you. The legal limits of the tools are on the site disclaimer. Official help is on IdentityTheft.gov and on SSA’s site.
If you came here because a form asked for the number and you wanted a second opinion, the useful question is still the first one. Do they need all nine digits, and can they use something else?
Frequently Asked Questions
Is it safe to type an SSN here?
The checker runs in your browser and does not send the digits to our servers or put them in the URL. Still use a device you trust, and do not type someone else’s number. Public samples are enough to see how the tools behave.
Should I give a business my full Social Security Number?
Ask why they need all nine digits and how they will store them. Payroll, tax, credit, and some government or medical enrollments may have a real reason. Many other requests can use the last four, an account number, or an in-person look at the card.
Are the last four digits public?
No. They still identify a record when combined with a name or other data. Randomization made old chart tricks harder for new cards. It did not make the last four harmless.
What should I do if my SSN is leaked?
Start at IdentityTheft.gov. If someone already used the number, file a report. If it was only exposed, use the lost-or-stolen steps. Consider credit freezes at the nationwide bureaus. SSA can help with a replacement card or a record question. This site cannot file those steps for you.
How do I place a credit freeze?
File a freeze with each nationwide bureau you care about, usually Equifax, Experian, and TransUnion. Placing and lifting a freeze is free under current federal law. IdentityTheft.gov can walk you through the list. We cannot file a freeze.
Can this site remove my number from data-broker listings?
No. File each broker’s own opt-out if a listing already shows the number, and include the URL when you start a plan at IdentityTheft.gov.
Should I type someone else’s SSN to check it?
No. Do not type someone else’s number into a public website, including this one. Use a published sample from the famous-samples guide if you only need to see the tools.
Does this site file an identity-theft report or replace a card?
No. Identity-theft plans start at IdentityTheft.gov. Cards, earnings, and replacement requests go through SSA. This site is a format checker. See the site disclaimer for what a result is not.



