You should also already have two-factor authentication setup, so you shouldn't have anything to worry about: https://support.google.com/accounts/answer/180744?hl=en
You should also already have two-factor authentication setup, so you shouldn't have anything to worry about: https://support.google.com/accounts/answer/180744?hl=en
Also, why wouldn't you give your email address to a random website? I have it plastered all over the net. Spam is a solved problem at this point. Ironically thanks to Gmail!
Agree on 2 factor auth though.
Out of interest - are those two letters the start of a password from any other site?
Presumably the leak came from a third party site so it would be your password from there rather than your gmail password.
It was someplace you used your email with that password. It had a couple of my emails all with the same throwaway password I only use on sites that I either don't trust or have no intention of ever using again.
If you search around the full leak is very easy to find
Someone on Slashdot searched for "+" suffixes in the list, as in username+suffix@gmail.com:
http://tech.slashdot.org/comments.pl?sid=5680529&cid=4787421...
Some of the most popular suffixes were xtube, daz (and daz3d), filedropper, and eharmony. The two characters returned by isleaked.com for my address could indeed have been from daz3d.com.