Email Password Lab

Free email password generator

Your email is the recovery key to almost every other account you own — generate a strong, unique password for it with crypto.getRandomValues(). No servers, no tracking, no storage.

Email Password Generator

Cryptographically random passwords for Gmail, Outlook, Yahoo, or any webmail account, generated entirely on your device.

••••••••••••
16

🔒 This tool runs 100% offline in your browser. We cannot see, save, or transmit anything you generate or type here.

Email Password Security Guide

Your email account isn't just one more login. It's the master key to almost everything else you own online. Nearly every service, from your bank to your streaming subscriptions, uses "forgot password" links sent to your email. Whoever controls your inbox can reset the passwords on those accounts one by one, which is why an email breach tends to cascade into many other breaches instead of staying contained to the inbox itself. It's easy to treat email as background infrastructure, something you log into once and forget about, right up until the moment it's the thing standing between an attacker and everything else you own.

Why the reset-link chain changes the math

That single fact should change how you think about your email password specifically. It deserves to be longer and more unique than almost any other password you own, precisely because it isn't protecting one thing; it's protecting the recovery path to everything. Reusing it anywhere else, even on a site that feels low-stakes, means a breach at that unrelated site can hand over the keys to your bank through the reset-link chain, since an attacker with your email password can simply request a reset on the accounts that matter and read the link the moment it arrives. This is also why email is disproportionately targeted by phishing compared to almost any other account type: compromising one inbox is often worth more to an attacker than compromising ten unrelated logins individually.

Two-factor authentication matters even more here

Two-factor authentication matters even more for email than for most accounts, for the same reason. Gmail, Outlook, and most major providers support an authenticator app or a hardware security key as a second step, and it's worth the five minutes it takes to set up, since it stops an attacker even if they somehow get your password through a breach elsewhere or a phishing page. An authenticator app is generally the better choice over SMS codes where both are offered; text messages can be intercepted through SIM-swapping, a technique where an attacker convinces your carrier to move your phone number onto a device they control, which then lets them receive your login codes directly.

App passwords, and treating them the same way

If you use an email client on your phone or a third-party app that doesn't support two-factor login directly, you may run into app passwords, a separate, randomly generated password issued just for that one app, distinct from your main login. Treat these exactly the same way you'd treat your main password: generate them randomly rather than typing something memorable, never reuse your main password for one, and revoke any app password for a service you've stopped using. A forgotten app password from an old device or a service you no longer use is a small but real leftover risk, since it grants ongoing access even after you've moved on from whatever created it.

Recovery information deserves the same care as the password

Most providers let you set a recovery phone number or a secondary email address in case you're ever locked out, and it's worth checking both are current rather than pointing at a phone number you no longer have or an old address you've abandoned. This matters in two directions: an out-of-date recovery method can lock you out of your own account when you actually need it, and an attacker who compromises an old, abandoned secondary email can sometimes use it as a back door into the primary one. If your provider offers printable backup codes for two-factor authentication, generating and storing a set somewhere safe, not in the inbox they're meant to protect, is worth the few minutes it takes, since it's your way back in if you ever lose access to your authenticator app.

Checking who else has access

Most major providers keep a list of active sessions and connected devices somewhere in the account security settings, often labeled something like "Where you're signed in" or "Connected apps." It's worth glancing at occasionally, since a device or app you don't recognize is one of the clearest signs of unauthorized access, often clearer than any password-strength issue would ever surface on its own. If you see something unfamiliar, revoking it and changing your password immediately closes the door faster than waiting to see what happens.

If you think your email has already been compromised

Act on the account itself before anything downstream. Change the email password first, from a device you trust, then work outward: check the active sessions list and revoke anything unfamiliar, review and correct the recovery phone and secondary email if either has been altered, and look through any mail forwarding or filter rules, since a common trick is quietly setting up a forward so an attacker keeps reading your mail even after you've changed the password and locked them out of direct access. Only after the inbox itself is secure does it make sense to work through the accounts that use it for recovery, changing those passwords too if there's any reason to think they were reset or accessed while the email was compromised.

Making the change itself

For this one account, length is worth spending. The 12 and 15 character presets make generating a strong one a one-click job, and why length and randomness matter explains the reasoning behind going long rather than clever. Store the result in a password manager immediately rather than trying to remember it; an email password is one you'll paste, not type. The same logic applies to other high-value logins like Facebook, covered in our Facebook and social media password guide, and if you'd rather protect the account with a memorable word-based password instead of a dense random string, our passphrase generator is built for exactly that trade-off. Prefer a single page with every tool, including a strength checker for a password you already use? Use the full password generator. And if what you actually need is a token or key rather than an account password, the random string generator and the PIN generator cover those specific cases, while the WiFi password generator and its matching QR code tool handle your home network.

Frequently Asked Questions