Security

How to Create Strong Passwords

Build strong unique passwords and protect them with a password manager and MFA.

Password manager vault holding unique keys and credentials

Start with the account that can reset your other accounts: your email. This guide gives you a manageable order for replacing reused passwords, checking recovery and confirming that a new sign-in works. Do not enter a real password into a tutorial, calculator or support message.

Choose a different secret for each account

A password copied across several services creates a shared point of failure. Changing a few letters or appending the service name still creates a pattern. Use a password manager to generate independent passwords, and follow the service's supported length and character rules. For a secret you must remember, use a long, unique passphrase whose words are not a familiar quotation or personal fact.

There is no example password on this page to copy: a published example is already known. Generate your actual credentials privately. A password manager reduces the need to remember every account's secret, but its own sign-in and recovery need special attention.

Plan recovery before moving your accounts

Before choosing where to keep passwords, answer three practical questions: Can you unlock the vault on your everyday devices? What happens when your phone is lost? What happens when you forget the vault password? Read the provider's recovery instructions; do not assume customer support can restore encrypted information.

Keep emergency recovery material in a secure location you can reach without opening the locked vault. If you make a paper copy, protect it from casual access and loss. If you export credentials, check whether the export is encrypted before saving it. An ordinary CSV export exposes its contents to anyone who can read the file.

Enable an additional sign-in factor where supported. Our two-factor authentication guide explains recovery codes and method choices. A passkey can resist phishing, but you still need a plan for losing the device or account that holds it.

Replace reused passwords one account at a time

Use this migration worksheet without recording any passwords in it. Mark each row complete only after checking access.

Account migration order
Account groupWhat to verifyCompletion check
Primary emailRecovery address and phone belong to youNew password saved; fresh sign-in works
Password managerRecovery instructions and second factor are availableYou understand access from a replacement device
Payment and cloud accountsAccount activity and connected devices are expectedEach account has its own credential
Shopping, forums and older accountsWhether you still need the accountUnique password set, or account closed deliberately

For each account, open the known app or type the service address yourself. Change the password, update its saved entry, and test a fresh sign-in before ending your existing trusted session. For a shared household account, agree on the change with the other authorized user first so that an unexplained sign-out does not cause confusion.

Example: If email, shopping and a forum share a password, making only the email password unique protects that email from reuse of the old forum credential. Shopping remains exposed until its password changes too. Track accounts, not just the number of password changes.

Handle an exposed password or unexpected login

Open the affected service directly to check an alert. Replace the exposed password everywhere it was reused, review recovery details and active sessions, and remove access you do not recognize using the provider's security controls. If access is already lost, use that provider's official recovery process.

Do not approve an unexpected authentication prompt. A strong password cannot protect you if you hand over a valid verification code or approve an attacker's login. Read our phishing guide when a message pressures you to act immediately.

Your final check is practical: each important account has a separate credential, its recovery belongs to you, and you can explain how you would regain access after losing your phone. Never send us passwords or recovery codes when asking for a correction.

Sources and scope

This is a documentation-based account-maintenance workflow, not a review of a specific password manager. See CISA's password-manager guidance and your provider's instructions for its recovery and export behavior. Report a correction with the relevant page and public documentation.