“I was able to do 10, manually. I bet a script could try thousands a minute, or more”
If the numbers make brute-force cracks less likely (and shorter passwords could be cracked, I bet), I still hold that email-sending of passwords in clear text is a major violation of security. I, personally, was stung with someone who sniffed my email when I sent credit-card information to myself.
every combination doesn’t need to be tried ... only until you get a hit ...