Advertisement
Advertisement

Password Strength Checker

See how a password holds up against real guessing methods, not just a checklist of character types.

🔒 What you type stays on this page. It is checked by your own browser and is never stored, logged or sent anywhere.
Personal words are easy for someone who knows you to guess. The checker treats them as weak.
Start typing to see the strength

Estimated time to crack

Quick checks

    How to use the Password Strength Checker

    1. Type or paste a password into the box. Use Show if you want to see what you typed.
    2. Optionally add personal words, like your name or your pet's name, so the checker knows to treat them as weak.
    3. Read the strength meter and the main warning. The feedback explains what makes the password guessable.
    4. Look at the crack-time table to see how it would hold up in different attack situations.
    5. If it is weak, follow the suggestions or create a new one with our Password Generator, then click Clear.

    How it works

    Simple meters count character types: one uppercase letter, one digit, one symbol, done. Real attackers don't guess that way. They try leaked passwords, dictionary words, names, dates, keyboard patterns like qwerty, and common substitutions like @ for a first. This page uses zxcvbn, an open-source estimator originally built by Dropbox, which looks for exactly those patterns and estimates how many guesses it would take to find the password. P@ssw0rd! ticks every checklist box yet scores as very weak, while a long phrase of four unrelated lowercase words scores well.

    The guess count becomes a time by assuming a guessing speed. The table shows four situations: an online attack against a website that limits attempts (about 100 guesses per hour), one that doesn't limit them (10 per second), an offline attack on a stolen database that uses a slow password hash (10,000 per second), and one that uses a fast, weak hash on specialized hardware (10 billion per second). The last row is the worst case and the one to pay most attention to for important accounts.

    Our own quick checks run alongside it: length, the mix of character types, repeated characters, simple runs like abcd or 4321, and keyboard rows. The "if random" figure shows the maximum possible strength for that length and character set, which only applies when every character was picked at random, for example by a password generator. All estimates are approximations; they rank passwords well but can't promise how long a specific attacker would take.

    Frequently asked questions

    Is it safe to type my real password here?
    The check happens entirely in your browser, and the password is never stored, logged or sent. Even so, a good habit is to test a password that is similar to your real one rather than the exact one, or to test before you start using it.

    What makes a password strong?
    Length and unpredictability. A random password of 16 or more characters, or a passphrase of four or five random words, is very hard to guess. Avoid names, dates, common words with a number at the end, and anything you have used elsewhere.

    Why does my password with symbols score so low?
    Swapping letters for look-alike symbols (@ for a, 0 for o) and adding ! or 1 at the end are among the first tricks cracking tools try. They add very little real strength.

    Should I use the same strong password everywhere?
    No. If any one site is breached, attackers try that email and password everywhere else. Use a different password for each account; a password manager makes that practical.

    Does a strong password mean my account is safe?
    It helps a lot, but turn on two-step verification as well. It protects you if your password is ever leaked or phished, no matter how strong it is.

    Advertisement

    You might also need