A long, unique passphrase is usually stronger and easier to use than a short password packed with substitutions. Length and uniqueness matter more than predictable complexity tricks.
Make it strong
Use several unrelated words, make it at least 14–16 characters, and never reuse it. For most accounts, a password manager should generate and store a different password for every site.
Still use MFA
A strong passphrase cannot protect you from every phishing attack, stolen session, or breached website. Turn on multi-factor authentication too.
This page provides general security guidance, not a guarantee that any individual message is safe. When money, passwords, remote access, or sensitive records are involved, verify through a separate trusted channel.
