Password Strength
Idea shared by Tan - 9/1/2026 at 7:17 PM
Under Consideration
Hi,

Is it possible for SmarterMail to allow us to maintain our own password blacklist?

Some clients are trying different ways to bypass the password strength requirements, and recently we have had more password breaches caused by weak or commonly used passwords.

We understand that it is the client's responsibility to use a secure password. However, when one account is compromised, it can affect other users and the reputation of the server.

We would therefore like to have more control by blocking a list of common or known weak passwords that we define ourselves.

No matter how strong we set the password requirements, users often find ways around them. Having our own password blacklist would give us an additional layer of protection.

Does you think it is something that can be implemented in SmarterMail?
Derek Curtis Replied
Employee Post
Not a bad idea. I'll add it as a feature request. Could be managed like extension blacklists, I'd imagine. 
Derek Curtis
CCO
SmarterTools Inc.
Thanks!!

Yes. Please include import and export feature so that we can make sure all of our servers are synced.

Isn't there the common passwords file that could be updated?  Option to not allow common passwords reads that as I recall.
I believe that is just a toggle to block common password but it does not allow us to define our own so I would not want to tamper with any files that is not an official function by Smartermail.

Reply to Thread

Enter the verification text