Length matters most
Every extra character multiplies the work for an attacker. Use 16 or more for anything important, and never fewer than 12.
Create a strong password or an easy-to-type passphrase in one click. It is made in your browser, so nobody else ever sees it, not even us.
Generating a password...
Very strong103 bitsAbout 17 trillion years to guess
Made in your browser with the Web Crypto API. Never sent to Mail Vanish, never stored.
The basics
A password generator creates a random password for you, so you never have to invent one. People are bad at randomness: we reach for names, dates and patterns, and attackers know exactly which ones. A generator picks every character by chance, which makes the password as hard to guess as its length allows.
The Mail Vanish password generator makes random passwords up to 64 characters long and passphrases of three to ten words. It runs entirely in your browser with the same secure random source your browser uses for encryption, and it shows how strong each result is before you use it.
Password strength
The same password can fall in seconds or outlast the sun, depending on how long and how random it is. These figures come from the generator above.
| Password | Example | Entropy | Time to guess |
|---|---|---|---|
| A common password | 123456 | On every list | Instantly |
| A word and a year | Summer2024 | Guessable | Seconds |
| 8 random lowercase letters | qmtvhzra | 37 bits | 10 seconds |
| 4 random words | cedar river lamp quiz | 44 bits | 15 minutes |
| 8 random characters, all types | q7#Lm2!v | 51 bits | 2 days |
| 6 random words and a number | Maple-Orbit7-Tulip-Wagon-Fern-Dune | 71 bits | 7 thousand years |
| 12 random characters, all types | T4m!xQ9#rLw2 | 77 bits | 298 thousand years |
| 16 random characters, all types | k7$Qm!2vR#9xLp@w | 103 bits | 17 trillion years |
Times are the average for an attacker who has stolen a password database and tests 10 billion guesses a second, a realistic rate for a GPU cracking rig against a weakly hashed list. Common and previously leaked passwords are tried first, so they fall in seconds whatever their length.
Best practice
A strong password is long, random and used in one place only. These habits keep your accounts safe even when a website you use is breached.
Every extra character multiplies the work for an attacker. Use 16 or more for anything important, and never fewer than 12.
Upper and lower case letters, numbers and symbols widen the pool each character is drawn from, so the same length is far harder to guess.
When one site leaks, attackers try the same email and password everywhere else. A unique password keeps a breach to one account.
Names, birthdays, pets and teams are easy to find online and are the first guesses attackers make. Random beats clever every time.
Several random words are easier to type and remember than symbols. Six random words and a number are about as strong as 11 random characters.
Nobody can remember dozens of random passwords. A password manager stores them, fills them in and syncs them across your devices.
A code from an app or a security key stops someone who has your password from signing in. Switch it on for email, banking and social accounts first.
Sign up for trials, downloads and one-off accounts with a temp mail address. A leaked database then holds a throwaway address, not yours.
How it works
Choose the length and the characters a site allows, or switch to random words you can type and remember.
Your browser draws every character with the Web Crypto API. The password is never sent to Mail Vanish and never stored.
Copy it with one tap, paste it into the signup form and save it in your password manager. Need another? Generate a new one.
Better together
A strong password protects the account. A temporary email address protects you. Signing up for a free trial, a download or a site you will visit once? Use a random password from this page and a free temp mail address from Mail Vanish, and a breach of that site exposes neither your real inbox nor a password you use anywhere else.
For accounts you need to keep, use a permanent private address instead, with a PIN-protected inbox and forwarding to the inbox you already read.
FAQ
How the generator works, how strong its passwords are, and how to keep them safe.
Yes. Every password is made in your browser with the Web Crypto API, the same secure random source browsers use for encryption. It is never sent to Mail Vanish, never logged and never stored, and the tool keeps working even if you go offline after the page loads.
Grab a free temporary email address for the next signup you do not trust, and burn it with one tap when you are done.