Password security guide
Google Account Password and Passkey Security
Google recommends a unique password of at least 12 characters. A generated 16 to 20-character value is a practical choice when you still use a password.
Official Google Account password requirements
Google accepts combinations of ASCII-standard letters, numbers and symbols. Accented characters are not supported. It rejects particularly weak passwords, passwords previously used on the account, and values that begin or end with a blank space. Google recommends at least 12 characters.
Use a longer random value stored in a manager rather than a meaningful quotation. The official form remains authoritative if account-specific validation changes.
Use a passkey where it fits your recovery plan
Google Accounts support passkeys on compatible devices. A passkey uses the device unlock method and public-key authentication, so there is no reusable password to type into a phishing page. Create it only on a device or credential manager you control.
Review the account passkey list and remove lost or untrusted devices.
Turn on 2-Step Verification
Google 2-Step Verification can use Google prompts, passkeys, security keys, Authenticator codes and other account-dependent methods. Prefer phishing-resistant options for high-value accounts. Store backup codes securely and enroll more than one safe route.
Protect recovery information
Keep the recovery email and phone current. A primary Google Account often controls mail, files, devices and password resets for other services, so its recovery channels deserve the same protection as the password.
Run Security Checkup
Review signed-in devices, recent security activity, third-party access and sign-in methods through Google Security Checkup. Remove services you no longer use and investigate unfamiliar activity before dismissing an alert.
If the Google password is compromised
Change it from a trusted device, sign out unfamiliar sessions, review forwarding and filter rules in Gmail, check app passwords and third-party access, and replace any reused credentials. Do not enter the replacement through a link in an alert email.