Regex for Strong Password Validation
Copy the pattern, type a candidate password below, and see whether it passes. Below the tester: how the lookaheads enforce each rule and how to change the requirements.
What this pattern matches
This requires a password of at least 8 characters that contains at least one lowercase letter, one uppercase letter, one digit, and one special character.
How it works, part by part
(?=.*[a-z]) — a lookahead demanding a lowercase letter somewhere.
(?=.*[A-Z]) — demands an uppercase letter.
(?=.*\d) — demands a digit.
(?=.*[^\w\s]) — demands a special (non-word, non-space) character.
.{8,}$ — and the whole thing must be at least 8 characters long.
Tuning the rules
Change {8,} to raise the minimum length, or drop a lookahead to relax a rule. Note: length is a stronger defense than character-class rules — consider allowing long passphrases.
FAQ
Why use lookaheads instead of one big class?
Lookaheads let each rule be checked independently without forcing a character order, so the letters and digits can appear anywhere.
How do I require 12 characters instead of 8?
Change .{8,} to .{12,} at the end of the pattern.
Does it allow spaces in the password?
Yes, spaces count toward length but are not accepted as the required special character. Adjust the last lookahead if you want them to.