Skip to main content

Password Policy Tester

Test a password against a configurable complexity policy — minimum/maximum length, required uppercase, lowercase, digit and symbol characters, a no-whitespace rule, and an optional forbidden-text check (e.g. ban a username or company name) — with a clear pass/fail report for every rule. Runs entirely in your browser; the password is never sent anywhere.

Input

Your password never leaves your browser — the check runs entirely locally.

0 = no maximum.

Case-insensitive substring check — useful for policies that ban usernames or company names.

Output

Policy report
RuleStatus
No data yet
Was this helpful?

Guides

What does this tool do?

Type a password and check it against a configurable complexity policy — the kind of rule set a signup form, an internal admin panel, or a compliance checklist might enforce. Unlike a generic strength meter, this tool doesn't guess what "strong" means; you set the exact rules (minimum/maximum length, which character types are required, whitespace, and a forbidden-text check) and get a clear pass/fail report for each one.

Settings

  • Minimum / maximum length — set a minimum length (defaults to 8) and, optionally, a maximum (0 disables the maximum check — most policies don't cap length).
  • Character requirements — toggle whether an uppercase letter, lowercase letter, digit, and/or symbol must be present.
  • Disallow whitespace — reject passwords containing spaces, tabs, or other whitespace, which many systems don't handle well.
  • Must not contain (optional) — a case-insensitive substring check, useful for policies that ban a username, email prefix, or company name from appearing in the password itself.

How to use it

  1. Type or paste the password to test into the Password field — it's masked and never leaves your browser.
  2. Adjust the policy settings to match the rules you're validating against (a specific site's signup requirements, an internal password standard, etc.).
  3. Read the Policy report table: an Overall Pass/Fail row, followed by one row per active rule showing whether the password satisfies it.
  4. Copy or download the report if you're documenting a policy compliance check.

FAQ

How is this different from a password strength analyzer? A strength analyzer scores how hard a password would be to guess or brute-force. This tool checks compliance against rules you define — a password can pass every rule here (meets the minimum length, has a digit, etc.) and still be objectively weak, or fail here while being reasonably strong, if your policy requires something like a symbol that the password doesn't have. For overall strength scoring, use the Password Strength Analyzer instead.

Why is the maximum length off by default? Most password policies only enforce a minimum. A maximum is left at 0 (no limit) unless you explicitly need to check one — for example, a legacy system that truncates or rejects unusually long passwords.

Does the forbidden-text check search for real usernames automatically? No — type the exact text you want to disallow (a username, email prefix, or company name) into the field. The check is a simple case-insensitive substring match, not a lookup against any external data.

Privacy

The check runs entirely in your browser using JavaScript — your password is never transmitted, logged, or stored anywhere, including to iotools.cloud's own servers.

passwordpolicyvalidatorsecuritycompliancecomplexityrequirements

Love the tools? Lose the ads.

One payment clears every ad from your account, for good. No subscription, no tracking.