A good username is forgettable to strangers and hard to guess, even if they know your name
The best usernames do two things at once: they tell you nothing about the person behind them, and they are difficult to crack through guessing. A username like "sarah.martinez.1987" leaks your full name, likely birth year, and makes it trivial for someone to test variations across multiple sites. A username like "northbound.badger" or "marble.shelf.4" tells a stranger nothing, uses words that don't connect to your real identity, and is harder to predict even if someone knows who you are.
The goal is not to be clever or memorable — it is to be boring and opaque to anyone outside your own life. The usernames that work best are the ones you would never think to use, because they sound random. That randomness is the point.
Key Takeaways
- Avoid usernames that contain your real name, birth year, pet names, or anything someone could learn from your social media profile.
- Use two unrelated common words (like "marble.shelf") or a word plus random numbers, because these are harder to guess than patterns based on your life.
- Keep usernames between 8 and 16 characters when the site allows it, since longer strings take longer to crack through automated guessing.
- Use the same username across sites only if you do not mind people connecting your accounts; use different usernames on banking and email sites than on public forums.
- A password manager can store usernames so you do not have to remember them, which means you can use truly random ones.
Why your real name or nickname is a bad choice
If your username is your actual name or a version of it, anyone who knows you can guess it. More importantly, anyone who finds your username on one site can search for it on others and build a profile of where you spend time online. A person looking to target you — whether a scammer, a stalker, or someone trying to embarrass you — starts by finding your username on a public forum or social media site, then searches for that same username on banking sites, email providers, and shopping platforms.
The same risk applies to nicknames, pet names, or anything tied to your identity. If your username is "jessica.loves.dogs" and you have a dog named Max, someone can test variations like "jessica.loves.max" on other sites. If it is "tom.1985", someone can test "tom.1984", "tom.1986", and "tom.1987" across multiple platforms.
How to build a username that is hard to guess
The simplest approach is to combine two common words that have nothing to do with each other or your life. Examples: "marble.shelf", "northbound.badger", "purple.invoice", "kitchen.compass". These are straightforward to remember, impossible to guess, and sound like nothing in particular. You can add numbers to the end if the site requires them — "marble.shelf.47" works just as well as "marble.shelf" and is still random.
If you want something even less memorable, use a password manager to generate a username for you. Many password managers (like Bitwarden, 1Password, or Dashlane) can create random strings of letters and numbers. You store the username in the manager alongside your password, so you never have to remember it. This approach is especially useful for banking sites, email accounts, and other high-value targets, because the username becomes as random and unguessable as the password itself.
Avoid patterns that sound random but are not. "Abc123def456" looks random but follows a predictable pattern. "Qwerty.user.2024" uses keyboard sequences and the current year, both of which are common in guessing attacks. Stick to actual random combinations or two unrelated words.
Length and character rules that matter
Longer usernames are harder to crack through automated guessing, so use the full length the site allows. If a site lets you use up to 20 characters, use 15 or more. If it limits you to 8 characters, that is a limitation of the site, not a reason to make your username shorter than it needs to be.
Most sites allow letters, numbers, and a few special characters (periods, underscores, hyphens). Use what the site allows. A username like "marble_shelf-47" is slightly harder to guess than "marbleshelf47" because the special characters add variation. Do not go overboard — a username with 10 special characters is annoying to type and offers no real security gain.
Different usernames for different sites
You face a trade-off between convenience and privacy. Using the same username everywhere makes it straightforward for someone to find all your accounts. Using a different username on each site makes it much harder for someone to connect your accounts, but you have to remember or store more usernames.
A practical middle ground: use one username for high-security sites (email, banking, password manager) and a different username for everything else. Your email username should be especially hard to guess, because email is the key to resetting passwords on other sites. Your banking username should also be unique and unguessable. For forums, social media, and shopping sites, you can use a different username on each one, or use the same one across all of them — the risk is lower because these sites hold less sensitive information.
What to do if your username is already compromised
If you have been using the same username across multiple sites for years, or if you used your real name as a username, you cannot change the past. What you can do now is change your username on the sites that matter most: your email provider, your password manager, your bank, and any site that holds payment information.
Start with email. If someone knows your email username and has your password, they can reset passwords on every other account you own. Change your email username to something random, then update your password manager and any other critical accounts. This breaks the chain that connects your accounts to each other.
For other sites, change your username when you next log in, or when the site offers a username change feature. You do not have to do it all at once. Prioritize the sites where you store money or sensitive information, then work through the rest over time.
Frequently Asked Questions
Should I use my email address as my username?
No. If you use your email address as your username, anyone who finds that username on one site knows your email address and can use it to search for your accounts elsewhere. Use a random username instead, and keep your email address private except where necessary.
Is it okay to use the same username on forums and social media?
Yes, because these sites are public anyway — people can already see your username and connect your accounts if they want to. The risk is lower than using the same username on banking or email sites. If you do not mind people knowing you use the same username across platforms, there is no security reason to change it.
What if a site will not let me use the username I want?
The username is already taken. Try adding numbers to the end, or use a different word combination. If you are using a password manager, generate a new random username instead of trying to remember a variation. The goal is a username that is hard to guess, not a specific one you prefer.
Can I change my username after I create an account?
Most sites allow username changes, but some do not. Check the account settings or help section before you create the account if the username matters to you. For sites that do not allow changes, choose carefully the first time.
Do I need to use special characters in my username?
No. A username made of two random words is just as find as one with special characters mixed in. Use special characters if the site allows them and you want to, but they are not required for a strong username.