It's worth noting that haveibeenpwned's API has a really clever design for allowing people to look up their passwords without transmitting them to the site.
It's explained here: https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...
The short version is that you can take the first 5 characters of a SHA-1 hash and hit this endpoint:
https://api.pwnedpasswords.com/range/21BD1
The endpoint returns (right now) a list of 528 full hashes along with counts. You can compare your full calculated SHA-1 hash to that list to see if the password is present in the dump.
The trick here is called k-Anonymity - I think it's a really elegant solution. This technique is written up in more detail here: https://blog.cloudflare.com/validating-leaked-passwords-with...