100% in-browser · your passwords are never transmitted

Password Policy Validator — Will It Pass Your Rules?

Validate a password against configurable NIST-style rules (length, classes, symbols) plus a common-password blocklist. See exactly what fails. The password NEVER leaves your device. Free.

Loading tool…

More tools

All free, all private — everything runs in your browser.

How to use Password Policy Validator

  1. 1Set the rules you want to enforce: length, required character classes, and the common-password blocklist.
  2. 2Type or paste a password. It's checked locally — never transmitted.
  3. 3Read exactly which rules pass and which fail.
  4. 4Adjust the password (or the rules) until it satisfies your policy.

Password Policy Validator FAQ

What rules can I check against?
Minimum and maximum length, required character classes (lowercase, uppercase, digits, symbols), and a blocklist of the most common leaked passwords — the core of modern NIST SP 800-63B guidance.
Does NIST still require complex passwords?
Modern NIST guidance (SP 800-63B) de-emphasizes mandatory complexity and instead emphasises length and screening against known-breached passwords. This validator lets you model both approaches and see the result live.