---
title: "Protect Accounts from Hackers: 9 Tips for Stronger Passwords"
description: Protect your email and other online accounts from hackers with these 9 best practices for stronger passwords.
image: https://blog.mdaemon.com/hubfs/Tips-for-stronger-passwords-TN-1.png
---

[![MDaemon Technologies](https://blog.mdaemon.com/hs-fs/hubfs/MDaemon-Technologies_logo_large.png?width=564&height=110&name=MDaemon-Technologies_logo_large.png "MDaemon Technologies")](https://mdaemon.com/)

- [Blog Home](https://blog.mdaemon.com)

# MDaemon Technologies Blog

## [Protect Accounts from Hackers: 9 Tips for Stronger Passwords](https://blog.mdaemon.com/9-tips-for-stronger-passwords)

 By [Brad Wyro](https://blog.mdaemon.com/author/brad-wyro)

- [Tweet](https://twitter.com/share)

Passwords have been the primary mechanism for online security for years, but many people continue to use poor habits when creating passwords, and this trend appears to be getting worse as the average online user has to keep track of up to [100 accounts](https://www.cnn.com/2024/02/26/tech/digital-legacy-planning-personal-technology/index.html).

The statistics provide a glimpse of the dire nature of these bad practices.

- [Three out of four](https://securitytoday.com/articles/2023/06/22/three-in-four-people-at-risk-of-being-hacked-due-to-poor-password-practices.aspx) people are at greater risk of being hacked due to poor password practices.
- The average cost of a data breach in 2024 was $[4.88 million](https://legal.thomsonreuters.com/blog/the-cost-of-data-breaches/).
- 85% of people use the same password across multiple accounts.

And while many platforms now support biometrics to enhance online security, the adoption of these passwordless authentication methods is not keeping up with current password use.

## **Understanding Password Strength**

Understanding password strength is crucial for maintaining security in your online accounts. Follow these nine tips for stronger passwords.

1. **Length**: Longer passwords are generally more secure. A good rule of thumb is to aim for a minimum of 12 characters, but longer is even better.
2. **Complexity**: A strong password includes a mix of different character types, such as uppercase letters, lowercase letters, numbers, and special characters (!, @, #, etc.). This complexity makes it harder for attackers to guess or crack the password using automated tools.
3. **Unpredictability**: Avoid using easily guessable information such as common words, phrases, or patterns related to your personal life (like your name, birthdate, or pet's name). Instead, opt for random combinations of characters or use a passphrase—a series of random words strung together.
4. **Use unique passwords for each account**: Each online account should have its own unique password. Reusing passwords across multiple accounts increases the risk—if one account is compromised, all others using the same password become vulnerable.
5. **Avoid common patterns**: Steer clear of common password patterns like "123456", "password", or keyboard patterns like "qwerty". These are often the first combinations tried by attackers.
   
   #### **Tip for Administrators:**
   
    MDaemon has a “Bad Passwords” file that can be used to prevent users from using passwords containing common words such as “password” or “letmein”.
   
   In MDaemon Remote Administration, these settings are located under Setup | Account Settings | Passwords.
   
   ![Prohibited passwords list in MDaemon Email Server](https://blog.mdaemon.com/hs-fs/hubfs/Bad-Passwords-MDaemon-Email-Server.png?width=1307&height=786&name=Bad-Passwords-MDaemon-Email-Server.png)
6. ****Use App Passwords:**** Using app passwords, MDaemon users can have a different, strong password for each of their email clients. In other words, a user can have a separate password for webmail, an IMAP client, an ActiveSync client, and any other connection from a mail client or mobile device. This bolsters account security by making it much hard for an account to be compromised via a single password.
   
   
   
   
   
   
   
    
7. **Update passwords regularly**: Change passwords periodically, especially for sensitive accounts. This reduces the risk in case a password is compromised without your knowledge.
   
   #### **Tip for Administrators:**
   
    MDaemon administrators can ensure users are changing their email passwords regularly by entering a password expiration timeframe via the Account Settings | Passwords menu.
   
   ![Password expiration settings in MDaemon Email Server - MDaemon Remote Administration](https://blog.mdaemon.com/hs-fs/hubfs/Password-Expiration-MDaemon-Email-Server.png?width=1521&height=816&name=Password-Expiration-MDaemon-Email-Server.png)
8. **Avoid passwords that have been found in a data breach:** Hackers have access to large databases of passwords that have been stolen in data breaches, leaving any account that  uses one of these compromised passwords vulnerable.  You can use tools such as [HaveIBeenPwned](https://haveibeenpwned.com/) to see if your password has been found in a data breach.
   
   #### **Tip for Administrators:**
   
   Both MDaemon and SecurityGateway can be configured to check for compromised passwords.
   
   In MDaemon Remote Administration, these settings are located at Setup | Account Settings | Passwords.
   
   ![Compromised password check in MDaemon Email Server](https://blog.mdaemon.com/hs-fs/hubfs/MDaemon-Compromised-password-check.png?width=1540&height=870&name=MDaemon-Compromised-password-check.png)
   
   In SecurityGateway, these settings are located at Setup/Users | Accounts | User Options.
   
   ![Compromised password check in SecurityGateway for Email](https://blog.mdaemon.com/hs-fs/hubfs/SecurityGateway-Compromised-password-check.png?width=1542&height=713&name=SecurityGateway-Compromised-password-check.png)
9. **Two-Factor Authentication (2FA)**: Whenever possible, enable two-factor authentication for an extra layer of security. Even if someone gets hold of your password, they would still need a second form of verification to access your account.
   
   - [Knowledge Base Article: How to Configure Two-factor authentication in MDaemon](https://knowledge.mdaemon.com/enable-two-factor-authentication-webmail-remote-administration)

Understanding these principles helps users create and maintain strong passwords, which in turn enhances the security of their online accounts and personal information.

 Tags: [Cybersecurity](https://blog.mdaemon.com/topic/cybersecurity), [Email Security Best Practices](https://blog.mdaemon.com/topic/email-security-best-practices), [Email Best Practices](https://blog.mdaemon.com/topic/email-best-practices), [Passwords](https://blog.mdaemon.com/topic/passwords)

![Brad Wyro](https://blog.mdaemon.com/hs-fs/hubfs/Brad-2023v2.jpg?width=100&height=100&name=Brad-2023v2.jpg)

#### Written by [Brad Wyro](https://blog.mdaemon.com/author/brad-wyro)

Brad has worked in technical and marketing roles at MDaemon Technologies, where he contributes as Content Marketing Manager. Brad balances technical and creative information to develop easy to understand videos and content to educate prospects and customers.

[![BACK TO ALL ARTICLES](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/6572702/05b24dbb-70a6-4eaa-9507-321cb27f7228.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/6572702/05b24dbb-70a6-4eaa-9507-321cb27f7228)

### Subscribe to Email Updates

- [Popular](https://blog.mdaemon.com/9-tips-for-stronger-passwords#tab-2)
- [Recent](https://blog.mdaemon.com/9-tips-for-stronger-passwords#tab-1)
- [Categories](https://blog.mdaemon.com/9-tips-for-stronger-passwords#tab-3)

### Lists by Topic

- [Email Security (72)](https://blog.mdaemon.com/tag/email-security)
- [MDaemon Email Server (44)](https://blog.mdaemon.com/tag/mdaemon-email-server)
- [Email How To (36)](https://blog.mdaemon.com/tag/email-how-to)
- [Email Best Practices (29)](https://blog.mdaemon.com/tag/email-best-practices)
- [Phishing (28)](https://blog.mdaemon.com/tag/phishing)
- [Product Updates (28)](https://blog.mdaemon.com/tag/product-updates)
- [Security Gateway for Email (27)](https://blog.mdaemon.com/tag/security-gateway-for-email)
- [Stop Spam Email (25)](https://blog.mdaemon.com/tag/stop-spam-email)
- [Cybersecurity (24)](https://blog.mdaemon.com/tag/cybersecurity)
- [Email Security Best Practices (22)](https://blog.mdaemon.com/tag/email-security-best-practices)
- [Email Server (22)](https://blog.mdaemon.com/tag/email-server)
- [Two-Factor Authentication (18)](https://blog.mdaemon.com/tag/two-factor-authentication)
- [Email Gateway How-To (17)](https://blog.mdaemon.com/tag/email-gateway-how-to)
- [Email Security Trends (15)](https://blog.mdaemon.com/tag/email-security-trends)
- [Health Care Security (12)](https://blog.mdaemon.com/tag/health-care-security)
- [SecurityGateway (12)](https://blog.mdaemon.com/tag/securitygateway)
- [Spear Phishing (12)](https://blog.mdaemon.com/tag/spear-phishing)
- [Data Leak Prevention (11)](https://blog.mdaemon.com/tag/data-leak-prevention)
- [Email Encryption (11)](https://blog.mdaemon.com/tag/email-encryption)
- [Anti-Spoofing (10)](https://blog.mdaemon.com/tag/anti-spoofing)
- [MDaemon Webmail (10)](https://blog.mdaemon.com/tag/mdaemon-webmail)
- [Email Archiving (8)](https://blog.mdaemon.com/tag/email-archiving)
- [Email Management (8)](https://blog.mdaemon.com/tag/email-management)
- [Email Privacy (8)](https://blog.mdaemon.com/tag/email-privacy)
- [Email Spoofing (8)](https://blog.mdaemon.com/tag/email-spoofing)
- [Business Email Compromise (7)](https://blog.mdaemon.com/tag/business-email-compromise)
- [Anti-Virus (6)](https://blog.mdaemon.com/tag/anti-virus)
- [Email Software (6)](https://blog.mdaemon.com/tag/email-software)
- [Tutorial (6)](https://blog.mdaemon.com/tag/tutorial)
- [Update (6)](https://blog.mdaemon.com/tag/update)
- [Collaboration (5)](https://blog.mdaemon.com/tag/collaboration)
- [Email Authentication (5)](https://blog.mdaemon.com/tag/email-authentication)
- [Compliance (4)](https://blog.mdaemon.com/tag/compliance)
- [Email Remote Administration (4)](https://blog.mdaemon.com/tag/email-remote-administration)
- [MailStore Archive Server (4)](https://blog.mdaemon.com/tag/mailstore-archive-server)
- [Microsoft 365 Exchange Alternative (4)](https://blog.mdaemon.com/tag/microsoft-365-exchange-alternative)
- [Passwords (4)](https://blog.mdaemon.com/tag/passwords)
- [Software update (4)](https://blog.mdaemon.com/tag/software-update)
- [Archive (3)](https://blog.mdaemon.com/tag/archive)
- [Attachments (2)](https://blog.mdaemon.com/tag/attachments)
- [Business Email (2)](https://blog.mdaemon.com/tag/business-email)
- [Cloud (2)](https://blog.mdaemon.com/tag/cloud)
- [DMARC (2)](https://blog.mdaemon.com/tag/dmarc)
- [Industry Insight (2)](https://blog.mdaemon.com/tag/industry-insight)
- [MDaemon (2)](https://blog.mdaemon.com/tag/mdaemon)
- [insider threats (2)](https://blog.mdaemon.com/tag/insider-threats)
- [msp (2)](https://blog.mdaemon.com/tag/msp)
- [Anti-Relay (1)](https://blog.mdaemon.com/tag/anti-relay)
- [BEC (1)](https://blog.mdaemon.com/tag/bec)
- [Backscatter (1)](https://blog.mdaemon.com/tag/backscatter)
- [Bayesian Learning (1)](https://blog.mdaemon.com/tag/bayesian-learning)
- [Content Filter (1)](https://blog.mdaemon.com/tag/content-filter)
- [DNS-BL (1)](https://blog.mdaemon.com/tag/dns-bl)
- [Disaster Recovery (1)](https://blog.mdaemon.com/tag/disaster-recovery)
- [Email Collaboration (1)](https://blog.mdaemon.com/tag/email-collaboration)
- [Email Software Reviews (1)](https://blog.mdaemon.com/tag/email-software-reviews)
- [Encrypt (1)](https://blog.mdaemon.com/tag/encrypt)
- [External Email Threats (1)](https://blog.mdaemon.com/tag/external-email-threats)
- [Gateway (1)](https://blog.mdaemon.com/tag/gateway)
- [Inbox (1)](https://blog.mdaemon.com/tag/inbox)
- [Inbox Zero (1)](https://blog.mdaemon.com/tag/inbox-zero)
- [Macros (1)](https://blog.mdaemon.com/tag/macros)
- [Monitoring (1)](https://blog.mdaemon.com/tag/monitoring)
- [Quarantine (1)](https://blog.mdaemon.com/tag/quarantine)
- [RelayFax (1)](https://blog.mdaemon.com/tag/relayfax)
- [Software (1)](https://blog.mdaemon.com/tag/software)
- [Training (1)](https://blog.mdaemon.com/tag/training)
- [Upgrade (1)](https://blog.mdaemon.com/tag/upgrade)
- [Windows Server (1)](https://blog.mdaemon.com/tag/windows-server)
- [internal email threat (1)](https://blog.mdaemon.com/tag/internal-email-threat)
- [ssl (1)](https://blog.mdaemon.com/tag/ssl)
- [tax scams (1)](https://blog.mdaemon.com/tag/tax-scams)

see all

### Posts by Topic

- [Email Security (72)](https://blog.mdaemon.com/tag/email-security)
- [MDaemon Email Server (44)](https://blog.mdaemon.com/tag/mdaemon-email-server)
- [Email How To (36)](https://blog.mdaemon.com/tag/email-how-to)
- [Email Best Practices (29)](https://blog.mdaemon.com/tag/email-best-practices)
- [Phishing (28)](https://blog.mdaemon.com/tag/phishing)
- [Product Updates (28)](https://blog.mdaemon.com/tag/product-updates)
- [Security Gateway for Email (27)](https://blog.mdaemon.com/tag/security-gateway-for-email)
- [Stop Spam Email (25)](https://blog.mdaemon.com/tag/stop-spam-email)
- [Cybersecurity (24)](https://blog.mdaemon.com/tag/cybersecurity)
- [Email Security Best Practices (22)](https://blog.mdaemon.com/tag/email-security-best-practices)
- [Email Server (22)](https://blog.mdaemon.com/tag/email-server)
- [Two-Factor Authentication (18)](https://blog.mdaemon.com/tag/two-factor-authentication)
- [Email Gateway How-To (17)](https://blog.mdaemon.com/tag/email-gateway-how-to)
- [Email Security Trends (15)](https://blog.mdaemon.com/tag/email-security-trends)
- [Health Care Security (12)](https://blog.mdaemon.com/tag/health-care-security)
- [SecurityGateway (12)](https://blog.mdaemon.com/tag/securitygateway)
- [Spear Phishing (12)](https://blog.mdaemon.com/tag/spear-phishing)
- [Data Leak Prevention (11)](https://blog.mdaemon.com/tag/data-leak-prevention)
- [Email Encryption (11)](https://blog.mdaemon.com/tag/email-encryption)
- [Anti-Spoofing (10)](https://blog.mdaemon.com/tag/anti-spoofing)
- [MDaemon Webmail (10)](https://blog.mdaemon.com/tag/mdaemon-webmail)
- [Email Archiving (8)](https://blog.mdaemon.com/tag/email-archiving)
- [Email Management (8)](https://blog.mdaemon.com/tag/email-management)
- [Email Privacy (8)](https://blog.mdaemon.com/tag/email-privacy)
- [Email Spoofing (8)](https://blog.mdaemon.com/tag/email-spoofing)
- [Business Email Compromise (7)](https://blog.mdaemon.com/tag/business-email-compromise)
- [Anti-Virus (6)](https://blog.mdaemon.com/tag/anti-virus)
- [Email Software (6)](https://blog.mdaemon.com/tag/email-software)
- [Tutorial (6)](https://blog.mdaemon.com/tag/tutorial)
- [Update (6)](https://blog.mdaemon.com/tag/update)
- [Collaboration (5)](https://blog.mdaemon.com/tag/collaboration)
- [Email Authentication (5)](https://blog.mdaemon.com/tag/email-authentication)
- [Compliance (4)](https://blog.mdaemon.com/tag/compliance)
- [Email Remote Administration (4)](https://blog.mdaemon.com/tag/email-remote-administration)
- [MailStore Archive Server (4)](https://blog.mdaemon.com/tag/mailstore-archive-server)
- [Microsoft 365 Exchange Alternative (4)](https://blog.mdaemon.com/tag/microsoft-365-exchange-alternative)
- [Passwords (4)](https://blog.mdaemon.com/tag/passwords)
- [Software update (4)](https://blog.mdaemon.com/tag/software-update)
- [Archive (3)](https://blog.mdaemon.com/tag/archive)
- [Attachments (2)](https://blog.mdaemon.com/tag/attachments)
- [Business Email (2)](https://blog.mdaemon.com/tag/business-email)
- [Cloud (2)](https://blog.mdaemon.com/tag/cloud)
- [DMARC (2)](https://blog.mdaemon.com/tag/dmarc)
- [Industry Insight (2)](https://blog.mdaemon.com/tag/industry-insight)
- [MDaemon (2)](https://blog.mdaemon.com/tag/mdaemon)
- [insider threats (2)](https://blog.mdaemon.com/tag/insider-threats)
- [msp (2)](https://blog.mdaemon.com/tag/msp)
- [Anti-Relay (1)](https://blog.mdaemon.com/tag/anti-relay)
- [BEC (1)](https://blog.mdaemon.com/tag/bec)
- [Backscatter (1)](https://blog.mdaemon.com/tag/backscatter)
- [Bayesian Learning (1)](https://blog.mdaemon.com/tag/bayesian-learning)
- [Content Filter (1)](https://blog.mdaemon.com/tag/content-filter)
- [DNS-BL (1)](https://blog.mdaemon.com/tag/dns-bl)
- [Disaster Recovery (1)](https://blog.mdaemon.com/tag/disaster-recovery)
- [Email Collaboration (1)](https://blog.mdaemon.com/tag/email-collaboration)
- [Email Software Reviews (1)](https://blog.mdaemon.com/tag/email-software-reviews)
- [Encrypt (1)](https://blog.mdaemon.com/tag/encrypt)
- [External Email Threats (1)](https://blog.mdaemon.com/tag/external-email-threats)
- [Gateway (1)](https://blog.mdaemon.com/tag/gateway)
- [Inbox (1)](https://blog.mdaemon.com/tag/inbox)
- [Inbox Zero (1)](https://blog.mdaemon.com/tag/inbox-zero)
- [Macros (1)](https://blog.mdaemon.com/tag/macros)
- [Monitoring (1)](https://blog.mdaemon.com/tag/monitoring)
- [Quarantine (1)](https://blog.mdaemon.com/tag/quarantine)
- [RelayFax (1)](https://blog.mdaemon.com/tag/relayfax)
- [Software (1)](https://blog.mdaemon.com/tag/software)
- [Training (1)](https://blog.mdaemon.com/tag/training)
- [Upgrade (1)](https://blog.mdaemon.com/tag/upgrade)
- [Windows Server (1)](https://blog.mdaemon.com/tag/windows-server)
- [internal email threat (1)](https://blog.mdaemon.com/tag/internal-email-threat)
- [ssl (1)](https://blog.mdaemon.com/tag/ssl)
- [tax scams (1)](https://blog.mdaemon.com/tag/tax-scams)

See all

#### About MDaemon Technologies

MDaemon Technologies is a pioneer in developing email and email security software helping to protect customers from evolving cyber-security threats. Its products and services are trusted by thousands of organizations in over 140 countries. For more than two decades, the company’s products have been developed with the ongoing input of IT professionals who demand reliable, affordable software that requires minimal effort to manage.

The software can be deployed in virtual, hosted cloud, on-premises, or hybrid network environments. The company sells its software and services directly and through a network of global channel partners.

For more information, visit [www.mdaemon.com](https://www.altn.com/).

Copyright © 1996-2026 MDaemon Technologies.  View [privacy policy](https://mdaemon.com/policies/privacy-policy).

 

###### Contact Us

 +1.817-601-3222

[sales@help.mdaemon.com](mailto:sales@help.mdaemon.com)

 6340 Lake Worth Blvd.  
 Fort Worth, TX 76135

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Brad Wyro",
    "url" : "https://blog.mdaemon.com/author/brad-wyro"
  },
  "dateModified" : "2025-04-04T16:46:33.034Z",
  "datePublished" : "2024-05-06T14:31:40.000Z",
  "headline" : "Protect Accounts from Hackers: 9 Tips for Stronger Passwords",
  "image" : [ "https://blog.mdaemon.com/hubfs/Tips-for-stronger-passwords-TN-1.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.mdaemon.com/9-tips-for-stronger-passwords",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.mdaemon.com/hubfs/MDaemon-Technologies_logo_large.png"
    },
    "name" : "MDaemon Technologies"
  }
}
```