Long is strong.
Make a passphrase.

Free · No account · Nothing to install

What a passphrase looks like
A padlock built from keyboard keys, with a keyhole in the middle

Example — do not use

tulip-bridge-lantern-cocoa-owl-fern

Six words from a list of 1,296 is about 62 bits. Even with a stolen database and fast hardware, guessing takes years on average. Make your own below.

An example. Never use an example you have read somewhere.

Make a passphrase or password

The choice is made by your browser’s secure generator. Nothing is sent or stored.

Test your own password

Type or paste a password. It stays in this field and is sent nowhere. For safety, rather use a password you almost use than the real one.

This is an estimate, not a guarantee. The test knows about 1,296 ordinary words and a few hundred commonly used passwords; a real attacker knows far more. Read a good score as an upper limit, and a bad score as certain.

Four things that really help

Passwords without
the hassle.

Long beats complicatedEvery extra word makes guessing a thousand times harder. X7!q is short and ugly; six ordinary words are long and pleasant.
One per serviceReuse is how a leak at one site becomes a break-in at another. If every service has its own passphrase, a leak stays contained.
Let a manager rememberRemember one good one, for your password manager. Let it create and fill in the rest. See below for how to handle that for a team.
Turn on MFAEven a good password can end up on a fake login page. With a second step, a stolen password alone is not enough.

The passphrase above comes from our own list of 1,296 ordinary English words, compiled by us: short, easy to type and free of offensive words. Each word adds a little over 10 bits, so six words is over 60. That figure is honest: it assumes an attacker cannot guess one of our words, but does know you used this tool. For the password of your password manager itself, rather pick seven or eight. Do not trust a computer with that choice? Then use the With dice tab: you roll, the page looks up the word.

What this does not do

The test does not check whether your password has leaked somewhere. That would mean sending part of the password to another server, and we deliberately do not do that. Use the leak check in your password manager or browser for that.

A strong password does not help if you type it into a fake page. That is why the link check exists (in Dutch for now), and why MFA belongs with it.

Honest about your data

What you make
stays with you.

The generator runs in your browser and uses your operating system’s secure random number generator. The test also runs in your browser. There is no form that sends anything; you can check this on the Network tab of the developer console while you type.

What you may come across besides that is measurement, and only if you accepted the cookie notice. Then our own counter on mkcloud.it counts how often a button was used (for example “passphrase made: 1”), never which passphrase or password. No IP address is stored. If you decline, nothing is counted.

If you copy a passphrase, it stays on your clipboard until you copy something else. Paste it into your password manager and clear the clipboard afterwards.

Passwords for a whole team?

A good passphrase per person only solves part of it. For organisations that also means a password manager, MFA on all accounts and insight into risky sign-in attempts. MK Cloud & IT helps with that, for organisations of 50 to 500 users.

Get in touch →

More tools like this

This is one of the free apps from MK Cloud & IT: small tools that work directly in your browser, without an account and without installing anything. Also see the link check and the mail check (Dutch for now), or all apps.

Sources

The word list is original work by MK Cloud & IT. The strength estimate follows the well-known principle that a password is as strong as the smallest number of guesses that can find it: the cheapest split into known words, years, sequences and single characters wins. It is our own, simplified implementation, not a third-party product.