Free tool
Password Generator & Strength Checker
Generate strong random passwords in your browser and check how long a password would take to crack, measured properly in bits of entropy.
Length beats complexity
Entropy measures how many guesses an attacker needs, in bits. Each extra bit doubles that. A sixteen character password of plain lowercase letters is far stronger than eight characters of mixed symbols, which is why the old advice about swapping letters for symbols produced passwords that were hard for people and easy for computers.
The crack time shown assumes offline attacking of a stolen database at around one hundred billion guesses per second, which is realistic with modern hardware against a weak hash. Anything under about sixty bits should be treated as already broken.
None of this helps if the password is reused. Most accounts are lost because a password leaked from somewhere else entirely, not because it was guessed. Use a different one everywhere, keep them in a password manager, and turn on two factor authentication wherever it is offered.