Contact

Free security tool

Strong Password Generator

Generate random, unique passwords

Create long, random passwords that are unique to every account in one click. You choose the length and character types.

Strength: Very strongabout 128.9 bits of entropy · pool of 87 characters

Strength is estimated for randomly generated passwords as length × log₂(character pool); it is not a guarantee.

The password is generated in your browser with the Web Crypto API; it is never sent to Doruva or stored.

Password options

Definition

What makes a password strong?

A strong password is random enough that it can’t be guessed, long enough that it can’t be found by trial and error, and used for one account only. Birthdays, names, sequences like “123456” and dictionary words are easy to guess, even with some letters swapped for symbols.

This tool builds the password with your browser’s cryptographic random number generator (the Web Crypto API, crypto.getRandomValues). Every character is drawn from the chosen pool with equal probability, and each character type you select appears at least once.

Length

Why length matters most

Every extra character multiplies the number of possible passwords by the size of the character pool. That is why length adds more strength than complexity: a 20-character password of letters and digits is far harder to guess than a 10-character one with symbols.

For accounts you keep in a password manager, 16 to 20 characters or more is a good baseline. If a site limits the length, use the longest password it accepts.

Estimated entropy by length

With all four character types selected (a pool of 87 characters)
LengthEstimated entropyLevel
8~52 bitFair
12~77 bitStrong
16~103 bitVery strong
20~129 bitVery strong
32~206 bitVery strong

The values apply to randomly generated passwords only; passwords people choose are much weaker at the same length.

Uniqueness

Why reusing a password is risky

When a site is breached and e-mail and password pairs leak, attackers try the same credentials on other sites with automated tools (credential stuffing). However strong a password is, using it on several accounts means one leak can open all of them.

Create a separate password for every account, and use unique passwords plus two-step verification wherever you can, especially for e-mail, banking and work accounts.

Storage

Use a password manager

You don’t need to memorise dozens of long random passwords. A password manager keeps them in an encrypted vault, fills them in on the right site and makes using a unique password for every new account easy.

Copy the password you generate here straight into your password manager or the account’s password field. Don’t keep passwords in plain text files, e-mails or chat apps.

Method

How the strength meter works

The meter is based on the estimated entropy of a randomly generated password: length × log₂(character pool), assuming the attacker knows the generation rules. The levels:

Weak
Below 45 bits: short passwords or a single character type.
Fair
45–59 bits: acceptable for low-risk accounts, but longer is better.
Strong
60–79 bits: a good level for most online accounts.
Very strong
80 bits and above: for important accounts and long-lived passwords.

FAQ

Strong password generator FAQ

Is the generated password saved anywhere?

No. The password is generated only in your browser; it is never sent to Doruva or any other server, is not stored, and is gone when you reload or close the page. Save the passwords you want to keep in your own password manager.

How long should a password be?

For accounts kept in a password manager, at least 16 characters and ideally 20 or more. For the one master password you need to remember, a long passphrase of several random words is also a good choice.

What does excluding look-alike characters do?

Characters such as I, l, 1, O and 0 look alike in some fonts. If you have to type or read the password, this option reduces mistakes; it slightly shrinks the pool, so it lowers strength only a little.

Do I have to use symbols?

No. Symbols enlarge the pool, but length matters more. Some sites don’t accept symbols; in that case turn them off and increase the length.

Should I change my password regularly?

Current guidance (e.g. NIST SP 800-63B) does not recommend forcing periodic changes of a strong, unique password. Change it immediately if you suspect it has leaked or someone else knows it.

Is a “very strong” password unbreakable?

No password comes with an absolute guarantee. The meter shows estimated resistance to guessing attacks; leaks, phishing and malware need other safeguards. Two-step verification is an important extra layer against them.

Where does the randomness come from?

The tool uses the Web Crypto API (crypto.getRandomValues), the browser’s cryptographically secure random number generator. Math.random, which can produce predictable results, is never used, and characters are chosen with equal probability, without bias.

Tools

More free Doruva tools

Check your site’s technical SEO health, its readiness for AI search or the length of your texts with our other free tools.