Password Combination Calculator
Character Set
Search Space Growth (log scale relative to 4-char baseline)
The Password Combination Formula
When each position in a password can independently hold any character from a pool of C characters, the total number of possible passwords of exact length L is:
N = possible passwords, C = character pool size, L = password length
The logic is multiplicative: there are C choices for position 1, C choices for position 2, and so on through position L. Multiply them all and you get C × C × ... (L times) = CL. This is sampling with replacement — the same character can appear more than once.
Worked examples
4-Digit PIN
C = 10, L = 4
N = 10^4 = 10,000
Each ATM PIN has a 1-in-10,000 chance of matching yours.
6-Letter Lowercase
C = 26, L = 6
N = 26^6 = 308,915,776
About 309 million possible strings.
8-char Alphanumeric
C = 62, L = 8
N = 62^8 ≈ 2.18 × 10^14
218 trillion combinations.
12-char Full ASCII
C = 94, L = 12
N = 94^12 ≈ 4.76 × 10^23
476 sextillion combinations.
Password Entropy Explained
Entropy converts the combination count into bits, which makes very large numbers easier to compare. The formula is:
Because N = CL, taking log base 2 gives H = log₂(CL) = L × log₂(C). The result is the same information measured in different units: each bit roughly doubles the search space.
| Configuration | Pool | Length | Combinations | Entropy |
|---|---|---|---|---|
| 4-digit PIN | 10 | 4 | 10,000 | 13.29 bits |
| 8-char lowercase | 26 | 8 | 2.09 × 10¹¹ | 37.60 bits |
| 8-char alphanumeric | 62 | 8 | 2.18 × 10¹⁴ | 47.63 bits |
| 12-char alphanumeric | 62 | 12 | 3.23 × 10²¹ | 71.45 bits |
| 16-char full ASCII | 94 | 16 | 3.86 × 10³¹ | 104.94 bits |
| 20-char alphanumeric | 62 | 20 | 7.04 × 10³⁵ | 119.08 bits |
Adding a single character multiplies the combination count by C. For a 62-character pool, each extra character gives 62× more candidates. Adding symbols (going from C=62 to C=94) multiplies each length by roughly 1.5×. This is why length often matters more than character complexity: length compounds exponentially while pool size is a multiplicative factor per extra character.
Combinations vs Real-World Security
The formula N = CL counts every possible string that fits the stated rules. That number is a mathematical property of the space, not a guarantee of any individual password's strength.
Why they differ
Real passwords chosen by people follow patterns. Common choices include dictionary words, names, dates, keyboard walks (qwerty, 123456), predictable substitutions (p@ssw0rd), and repeated characters. Because these patterns are known, attackers typically start with the most probable candidates rather than searching the entire space uniformly.
A 10-character password from a 94-character pool has a theoretical search space of 94¹⁰ ≈ 5.4 × 10¹⁹. A weak password from that same pool might appear near the top of a known-passwords list and fall within the first few hundred guesses in a dictionary attack.
What the calculation does tell you
Theoretical search space gives the upper bound on difficulty for an attacker who knows only the rules (length and character set) and must search blindly. If the password is truly random, that bound applies directly. It also lets you compare policies: a policy requiring 16 random characters beats a policy requiring 8 characters with complexity rules, regardless of which looks more complicated.
Attack models and what they assume
| Attack type | Typical rate | Assumption |
|---|---|---|
| Online rate-limited | 10–1,000/s | Rate limits, lockouts in effect |
| Offline (bcrypt/Argon2) | 10³–10⁶/s | Slow hash; attacker has the hash |
| Offline (MD5/SHA1) | 10¹⁰–10¹²/s | Fast unsalted hash; GPU clusters |
| Dictionary attack | depends | Prioritizes likely candidates, not uniform search |
| Credential stuffing | varies | Reuses leaked username/password pairs |
Combinations vs Permutations vs Password Counts
In everyday speech people say "password combinations" when they mean the count of ordered strings. Mathematically, that count is neither a combination nor a permutation in the classical sense — it is a count of Cartesian products.
Repetition allowed (typical)
N = C^L
Each of L positions can hold any of C characters, independently.
No repetition allowed
N = C! / (C - L)!
Also written P(C,L). Requires L ≤ C.
Math combinations (order ignored)
C(n,r) = n! / (r!(n-r)!)
Not used for passwords — order matters.
Entropy (either mode)
H = log₂(N)
Take log₂ of whatever count you computed.
Passwords are ordered strings: "abc" and "cba" are two different passwords, not two arrangements of the same combination. So the relevant count is always an ordered one. Without restrictions on repetition, it is CL. With a no-repeat rule it is P(C,L) = C!/(C−L)!. If L > C with no repetition, the count is zero — impossible to fill that many positions with unique characters from a smaller pool.
Length Ranges and Special Rules
Length ranges
Some systems accept passwords of varying length. If you need to count every possible password from length Lₘᵢₙ through Lₘₐₓ, you sum the combinations at each valid length:
For example, passwords from 8 to 12 characters in a 62-character pool:
| Length | 62^L | Contribution |
|---|---|---|
| 8 | 2.18 × 10¹⁴ | tiny relative to longer lengths |
| 9 | 1.35 × 10¹⁶ | |
| 10 | 8.39 × 10¹⁷ | |
| 11 | 5.20 × 10¹⁹ | |
| 12 | 3.23 × 10²¹ | dominates the sum |
| Total | ≈ 3.28 × 10²¹ | ~1.6% larger than 62¹² alone |
Because CL grows so quickly, the longest length in a range almost always dominates. Using only CLₘₐₓ is a common shortcut when a conservative upper estimate is acceptable, but the exact figure requires summing each length.
Excluded characters
Excluding characters reduces C directly. If a 94-character pool excludes 0, O, 1, l, and I (5 characters) to avoid visual ambiguity, the effective pool is 94 − 5 = 89, and N = 89L. Exclusions always reduce the theoretical search space, so they have a small cost in combinatorial strength for a usability benefit.
Required character types
A policy requiring at least one character from each of four categories (upper, lower, digit, symbol) excludes strings that use only some categories. Counting valid strings requires subtracting the invalid ones using inclusion-exclusion. For a password of length L with pool C requiring at least one from each of four non-overlapping categories of sizes c₁, c₂, c₃, c₄:
The Advanced tab in the calculator uses the full logarithmic approach for arbitrary pool sizes. For exact counts with required-type constraints at large lengths, the differences are typically small relative to CL.
Passphrase Search Space
A passphrase is a sequence of randomly chosen words. If the word list contains W entries and you select K words with replacement, the number of possible passphrases is WK.
| Word list size (W) | Words (K) | Combinations | Entropy |
|---|---|---|---|
| 2,048 (BIP-39) | 4 | 1.76 × 10¹³ | 44 bits |
| 2,048 | 6 | 7.38 × 10¹⁹ | 66 bits |
| 7,776 (EFF large) | 5 | 2.82 × 10¹⁹ | 64.6 bits |
| 7,776 | 6 | 2.21 × 10²³ | 77.5 bits |
A 5-word EFF diceware passphrase (W = 7,776) has about 64.6 bits of entropy, which matches a random 11-character alphanumeric password. Both the word-count and the list size matter, just as character count and pool size do for character-based passwords. The critical word is randomly: a passphrase that is a meaningful sentence the user invented does not carry the full entropy of a randomly generated one from that word list.
Common Calculation Mistakes
| Mistake | Correct approach |
|---|---|
| Using only CLₘₐₓ for a length range | Sum Ck for each k from Lₘᵢₙ to Lₘₐₓ |
| Assuming "symbols" = 32 always | Symbols differ by system; document exactly which characters are included |
| Using C(n,r) for password counts | Use CL (ordered, with replacement) or P(C,L) (no repetition) |
| Adding category sizes when multiplying is needed | Pool size = sum of category sizes; then raise to the power L |
| Treating entropy as guaranteed security | Entropy assumes uniform random generation; human choices reduce effective entropy |
| Ignoring dictionary attacks in time estimates | Brute-force time assumes uniform random search; real attacks are faster on weak passwords |
| Floating-point overflow for large values | Use log-domain arithmetic; display log₁₀(N) and scientific notation |
Frequently Asked Questions
It depends entirely on length and the character pool. For a 12-character password drawn from 62 characters (letters and digits), there are 62¹² ≈ 3.23 × 10²¹ possible strings. For a 4-digit PIN there are 10⁴ = 10,000. The calculator above lets you set any combination of these parameters instantly.
Use N = CL, where C is the number of distinct characters available and L is the password length. Count up your character types: lowercase (26) + uppercase (26) + digits (10) = 62. Then raise 62 to the power of your target length. That gives the theoretical count of all distinct strings of that length from that pool.
With digits only (C = 10): 10⁸ = 100,000,000. With lowercase letters only (C = 26): 26⁸ = 208,827,064,576. With letters and digits (C = 62): 62⁸ = 218,340,105,584,896. With all printable ASCII (C = 94): 94⁸ = 6,095,689,385,410,816. The choice of character set makes a very large difference.
With alphanumeric characters (C = 62): 62¹² ≈ 3.23 × 10²¹. With all printable ASCII (C = 94): 94¹² ≈ 4.76 × 10²³. These numbers exceed the estimated number of grains of sand on Earth (≈ 7.5 × 10¹⁸), which is why randomly generated passwords at this length are infeasible to brute-force under most attack models.
N = CL, where N is the number of possible passwords, C is the character pool size, and L is the password length. Each of the L positions can independently hold any of the C characters, so there are C choices per position and C × C × … (L times) = CL total strings. When repetition is not allowed, the formula becomes P(C,L) = C! / (C − L)!.
Password entropy is H = L × log₂(C), measured in bits. It is the base-2 logarithm of the number of possible passwords. A 12-character alphanumeric password has H = 12 × log₂(62) ≈ 12 × 5.954 ≈ 71.45 bits. This figure assumes uniform independent character selection. If the password is human-chosen rather than machine-generated, the effective entropy is lower because human choices follow predictable patterns.
Passwords are ordered strings, so "abc" and "cba" count as two different passwords. The relevant count is an ordered one: CL with repetition allowed, or P(C,L) = C!/(C−L)! without repetition. The mathematical combination formula C(n,r) = n!/(r!(n−r)!) ignores order and does not apply to password counting. When people say "password combinations" they actually mean ordered strings — not combinations in the strict mathematical sense.
Yes, because you never enter a real password here. The calculator works from rules only — length and character types — and performs all arithmetic locally in your browser. Nothing is sent to a server. There is no input field for an actual password value, and the results depend only on the rules you select, not on any secret.
Without repetition the count is P(C,L) = C! / (C−L)!, which is always smaller than CL. If L > C, no valid password exists and the count is zero — you cannot fill more positions than there are unique characters. For example, a 7-character password from a 62-character pool without repetition gives 62 × 61 × 60 × 59 × 58 × 57 × 56 ≈ 3.26 × 10¹². The Advanced tab in the calculator handles this mode.
Adding symbols expands the pool from 62 to 94 characters, which multiplies the combination count by roughly 1.5 per character position. That helps theoretically. For randomly generated passwords, adding one extra character of any type has a larger effect than switching to a bigger pool, because each extra position multiplies the search space by the full pool size. For human-chosen passwords, predictable substitutions like @ for a or 3 for e offer little real protection against dictionary attacks that already include these patterns.
Average exhaustive-search time: Tavg = N / (2R), where R is the guess rate in attempts per second. Worst case: Tworst = N / R. For example, 3.23 × 10²¹ candidates at 10⁹ guesses per second gives Tavg ≈ 1.6 × 10¹² seconds ≈ 51,000 years. These figures apply only to uniform exhaustive search. Real attacks against predictable or reused passwords are far faster.
The search space is the set of all candidate strings an attacker would need to consider under a given attack model. It is determined by the assumed length range, character pool, and any known constraints. For an attacker who knows only that a password is exactly 12 characters from a 62-character pool, the search space is 62¹² ≈ 3.23 × 10²¹. If the attacker also knows the password is a dictionary word with a number appended, the effective search space is far smaller.
When passwords can vary in length from Lmin to Lmax, the total count is the sum: CLmin + CLmin+1 + … + CLmax. Because each term is C times larger than the previous one, the longest-length term dominates almost entirely. For a 62-character pool from length 8 to 12, the total is ≈ 3.28 × 10²¹ — only about 1.6% larger than 62¹² alone. The Advanced tab calculates this correctly using the full summation.
A standard 4-digit PIN uses digits 0–9 (C = 10) with repetition allowed, giving 10⁴ = 10,000 possible combinations. If PINs cannot start with 0 the count drops to 9 × 10³ = 9,000. A 6-digit PIN gives 10⁶ = 1,000,000 combinations. These counts assume each digit is chosen independently — real users disproportionately choose PINs like 1234, 0000, and birth years, so practical guessing difficulty is much lower than 10,000 implies.
Key Takeaways
- The number of possible passwords is N = CL when repetition is allowed, where C is the pool size and L is the length.
- Password length increases search space exponentially. Adding one character multiplies the count by C.
- Pool size also matters: going from 62 to 94 characters multiplies each-length count by about 1.5 per character position.
- No-repeat passwords use P(C,L) = C!/(C−L)!, which requires L ≤ C.
- Length ranges require summing Ck for each valid length k.
- Entropy in bits: H = L × log₂(C). It assumes uniform random generation.
- Theoretical combinations ≠ real-world password strength. Human patterns and reuse dramatically reduce effective security.
- Never enter an actual password into a search-space calculator. The math only requires rules, not values.