Email Password Policy for a Small Team: Length Over Complexity
A practical email password policy for a small team: why length beats complexity rules, using a password manager, no reuse, breach checks, and when to reset.
Most small businesses either have no password policy or one copied from a corporate template that demands a symbol, a capital, and a change every 90 days. That template produces passwords like Summer2026! and people writing them on sticky notes. A good policy for a small team fits on one page, is built around a password manager, and focuses on the three things that actually get mailboxes taken over: reuse, short passwords, and credentials already in breach data.
Quick answer
Require every email password to be at least 16 characters, unique to that account, generated and stored in a company password manager, and never a previously breached string. Do not require periodic changes; require a change when there is a reason. Pair the policy with two-factor authentication and it covers the vast majority of real-world account takeovers.
Why length beats complexity rules
- Guessing attacks scale with length far more than with character variety. A 16-character passphrase of four random words is stronger and easier to type than an 8-character string with symbols.
- Complexity rules push people toward predictable patterns: capital first, number and symbol last, a season or a year in the middle. Attackers try those patterns first.
- Random generation by a manager removes the human pattern entirely. A generated 20-character password does not need a complexity rule because it already has one by construction.
The one-page policy
- Every work account, including email, uses a password generated by the company password manager. Minimum 16 characters; 20 or more where the site allows it.
- No password is used for more than one account. Ever. The manager makes this effortless.
- The master password for the manager itself is a memorised passphrase of at least four unrelated words, never written down in the office and never reused.
- Two-factor authentication is on for email, the password manager, the domain registrar, and banking.
- Passwords are changed when: a breach is announced for a service you use, a device is lost, someone leaves, or a phishing click is reported. Not on a calendar.
- Passwords are never sent by email or chat. Share through the manager's sharing feature or by phone.
- Sticky notes, spreadsheets, and the browser's built-in "save password" on shared computers are not allowed.
Setting up the password manager
Choose a manager with team sharing, and buy the business tier rather than each person using a personal free one, because you need to reclaim vaults when someone leaves. Create shared folders for things the whole team needs (the office Wi-Fi, the printer portal) and keep individual email credentials in individual vaults. Spend one hour migrating existing passwords, and use the manager's built-in audit to find reused and weak entries; that first report is usually sobering and is the argument for the policy.
Checking for breached passwords
- Most managers include a breach monitor that compares stored passwords against known-leaked data. Turn it on and act on its alerts the same day.
- Have I Been Pwned lets you search by email address to learn which services leaked your details. Search every company address once, and subscribe to notifications for the domain.
- When a breach includes a password you used anywhere else, change it everywhere it was reused, then treat that as the last time a password is ever reused.
How this applies to mailboxes on your domain
Every mailbox on your domain is a door into the company, including role addresses like info@ or billing@ that "nobody really uses". Give each one a generated password and a named owner, and remove mailboxes you no longer need. With OquMail you can create up to 15 mailboxes on the free plan, so there is no cost pressure to share one login between two people; give each person their own address and keep role mailboxes as separate accounts with their own credentials. The same password is used for OquMail webmail and for IMAP/SMTP in a mail app, so it deserves the full 16-plus characters.
Mistakes to avoid
- Forcing 90-day rotation. It produces incremented passwords and no security benefit; both NIST and the UK NCSC advise against it.
- Letting the founder be the exception. The owner's mailbox is the one that resets everything else.
- Storing the manager's master password in the manager, or in the mailbox it protects.
- Relying on "security questions". Answers are often public; where a site insists, generate a random answer and store it in the manager.
Common questions
What if someone refuses to use a password manager?
Offer a passphrase alternative for memorised passwords (four random words, 20 characters or more), but the no-reuse rule still stands. In practice the manager is easier and most objections fade after a week of use.
Should we use passkeys instead of passwords?
Where your mail provider and your other tools support them, yes. Passkeys remove the password entirely and resist phishing. Until every tool supports them, the policy above covers the gap.
How do we handle a shared role mailbox?
Give it its own generated password stored in a shared folder of the manager, with access limited to the two or three people who need it, and change it when any of them leaves. Better still, give individuals their own logins and have the role address deliver to them.
Free business email on your own domain
OquMail gives you up to 15 mailboxes on your domain — free — with guided SPF/DKIM/DMARC, webmail, IMAP/SMTP for any mail app, and a send API. Most teams are live in under fifteen minutes. Start at oqumail.com.
Get started free