TROUBLESHOOTING GUIDE
My password keeps getting rejected. What do I do?
You made a long, random password and the site still says no. This usually comes down to a hidden rule: a length cap, a banned symbol, a required mix, or a blocklist. Here is how to work out which one, and how to fix it without making the password weaker.
Start with the error message
Read the exact wording before changing anything. NIST’s guidance for sign-in systems says that when a service rejects a password because it is on a blocklist, it “SHALL provide the reason for rejection” (NIST SP 800-63B). Many sites give a reason; some only say “invalid password.” If the message is vague, look for a rules link next to the field or in the site’s help pages, then work through the checklist below.
The usual causes, and the fix for each
| What is happening | How to tell | What to do |
|---|---|---|
| Too long for the site | Shorter passwords work; the field cuts off typing, or the error says “maximum.” | Find the maximum and generate at exactly that length or just under it. Do not drop to a short password “to be safe.” |
| A symbol the site doesn’t allow | The error says “invalid character,” or the password works when you remove one symbol. | Exclude the banned symbols and generate again. Keep other symbols if they are allowed. In MorphPass, type the banned characters into the exclusions box. |
| A required mix you haven’t met | The error says “must contain” followed by a list of character types. | Use exact counts to meet the mix precisely, for example 2 numbers and 2 symbols in a 20-character password. |
| On a blocklist | The error says “too common,” “found in a breach,” or “choose a different password.” | Generate a new random password. Don’t add a “1” or “!” to the end of the old one. |
| Contains your name, email, or the site’s name | The error mentions personal information or the username. | Generate a fresh random password. NIST’s example blocklist includes “Context-specific words, such as the name of the service, the username, and derivatives thereof.” |
| Same as a previous password | The error mentions “recent” or “previous” passwords. | Generate a new one instead of editing the old one. |
| Paste is blocked or the field misbehaves | Nothing appears when you paste, or the strength meter doesn’t react. | Try your password manager’s autofill. NIST says services “SHALL allow the use of password managers and autofill functionality” and “SHOULD permit” pasting, but not every site follows this. |
| A hidden space or a mistyped confirmation | “Passwords do not match,” or it works when typed by hand. | Copy again from the source and check for an added space at the start or end. Avoid typing a long random password twice by hand. |
NIST sources: SP 800-63B, Password Verifiers. NIST’s rules are written for government systems and other services that choose to follow them. A private website is free to set stricter or odder rules, and you still have to meet them.
A worked example (fictional)
Say a site’s rules are: 8–16 characters, at least one uppercase letter, one lowercase letter, one number and one special character, and only ! # $ % allowed as special characters.
- Use the maximum length: 16.
- In MorphPass, choose Password and turn on exact counts, for example 5 uppercase, 5 lowercase, 3 numbers and 3 symbols (total 16).
- In the exclusions box, list every symbol you can’t use. MorphPass’s symbol set is
!@#$%^&*()-_=+[]{};:,.?/, so exclude everything except! # $ %. - Generate, copy, paste into both fields, and save it in your password manager straight away.
A string of that shape looks like Q7r!Mx#2kT$wPa9L. This is a fictional, public example: never use it as a real password.
When rules make you choose a weaker password
Some rules force a short maximum, such as 8 or 12 characters. Use the maximum, keep the password unique, and turn on multi-factor authentication if the site offers it. For federal systems, NIST says a password used as the only sign-in factor should be at least 15 characters, and one used only with multi-factor sign-in at least eight (NIST SP 800-63B). A site with a very low cap is setting a weaker limit than that. You can tell the site through its support channel; CISA’s archived consumer guidance says that if an important account lets you use a short password or a dictionary word, “ask them why” (archived CISA page).
Things not to do
- Don’t reuse a password from another account just because it was accepted there.
- Don’t shorten a strong password to the bare minimum unless the site’s maximum forces it.
- Don’t make a weak edit of the old password, such as adding a number on the end.
- Don’t send the password to a support agent, a chat, or a “password checker” site you don’t trust.