How to Secure Your Gmail Account

E
Editorial Team·27 days ago
018012 minutes read
How to Secure Your Gmail Account

Quick answer: To secure a Gmail account, enable two-factor authentication using an authenticator app, update recovery options, audit connected third-party apps, check for unauthorized forwarding rules and filters, and review recent sign-in activity. Google's Security Checkup at myaccount.google.com/security-checkup provides a guided review of all critical security settings in one place.


"I Never Thought About My Gmail Security Until Something Went Wrong" — Why Account Security Deserves Attention Before a Problem Occurs

A pattern that comes up regularly in account security: users who have had a Gmail account for years without reviewing the security settings — and then discover, after a compromise or a close call, that the account had connected apps with broad access, outdated recovery options pointing to a phone number that no longer exists, and no two-factor authentication. Gmail accounts accumulate security exposure over time: apps are connected and forgotten, recovery options become outdated, and passwords that were set years ago may have been exposed in data breaches. A periodic security review takes less than 15 minutes and significantly reduces the risk of account compromise. This guide covers the most important steps to secure a Gmail account — from enabling two-factor authentication to auditing connected apps to reviewing account activity. The specific settings and interface may change as Google updates its security features; the steps described here reflect current Google account security settings as of mid-2026, and Google's Security Checkup at myaccount.google.com/security-checkup is the most reliable starting point for a current review.


Why Gmail Accounts Are Targeted — and What Attackers Do With Access

Why Gmail Accounts Are Targeted — and What Attackers Do With Access

Gmail accounts are high-value targets for several reasons. Email is the recovery mechanism for most other online accounts — an attacker who controls a Gmail account can typically reset passwords for banking, social media, e-commerce, and other services linked to that email address. Gmail accounts also contain years of personal and professional correspondence, financial statements, travel confirmations, and other sensitive information. Access to a Gmail account is often more valuable to an attacker than access to any single other account. The most common methods used to compromise Gmail accounts are phishing (a fake login page that captures the password), credential stuffing (using passwords exposed in data breaches from other services), and SIM-swapping (taking over the phone number used for SMS-based 2FA). Password reuse across multiple services is a significant risk factor — a password exposed in a breach of one service can be used to access Gmail if the same password is used there. Checking whether an email address has appeared in known data breaches using a service like haveibeenpwned.com provides useful context for assessing current exposure. Once an attacker has access to a Gmail account, common actions include: setting up a forwarding rule to receive copies of incoming email, searching the inbox for financial information or credentials, using the account to reset passwords for other services, and sending phishing or spam messages from the compromised account. These actions can occur quickly — which is why the response to a suspected compromise needs to be immediate.


How to Secure Your Gmail Account — 5 Key Steps

1. Enable Two-Factor Authentication with an Authenticator App

Two-factor authentication (2FA) is the single most effective security measure for a Gmail account. With 2FA enabled, an attacker who obtains the account password still cannot sign in without the second factor. Google offers several 2FA options: Google prompts (a notification sent to a trusted device), an authenticator app (such as Google Authenticator, Authy, or 1Password), a hardware security key (such as a YubiKey), and SMS codes. SMS-based 2FA is better than no 2FA, but it is vulnerable to SIM-swapping attacks — an attacker who convinces the mobile carrier to transfer the phone number to a new SIM can intercept SMS codes. Using an authenticator app or a hardware security key provides stronger protection. To enable 2FA: go to myaccount.google.com/security, scroll to "How you sign in to Google," and click "2-Step Verification." Follow the setup wizard to choose and configure the preferred 2FA method. After enabling 2FA, generate and save backup codes (available in the 2-Step Verification settings) — these are one-time codes that can be used to access the account if the primary 2FA method is unavailable. Store backup codes in a secure location (a password manager or printed and stored securely) — not in the Gmail account itself.

2. Update Recovery Options

Recovery options — a recovery phone number and a recovery email address — are used to verify identity when the account password is forgotten or when Google detects suspicious activity. Outdated recovery options (a phone number that has changed, or a recovery email address that is no longer accessible) can prevent legitimate account recovery while potentially allowing an attacker who controls the old phone number to receive recovery codes. To review and update recovery options: go to myaccount.google.com/security and scroll to "Ways we can verify it's you." Confirm that the recovery phone number is current and accessible, and that the recovery email address is an account that is actively monitored and secured. The recovery email address should ideally be a different email provider than Gmail — if the Gmail account is compromised, a recovery email at a different provider is more likely to remain accessible. Update recovery options whenever a phone number changes or a recovery email address becomes inaccessible.

3. Audit Connected Third-Party Apps

Third-party apps connected to Gmail via OAuth can access email data to the extent permitted by the access scope granted during authorization. Over time, apps that were connected for a specific purpose and then forgotten may retain access to the account. Apps from unknown developers, apps that are no longer actively maintained, or apps that request broader access than their function requires are worth removing. A connected app with "Read, compose, send, and permanently delete all your email from Gmail" access has significant capability to access and modify the account. To review connected apps: go to myaccount.google.com/permissions. This page lists all apps and services that have been granted access to the Google account. For each app, review the access scope and the last time it was used. Remove any apps that are no longer needed, unrecognized, or that have broader access than their function requires. Removing an app's access does not delete any data the app has already accessed — it only prevents future access. After removing an app, the app's developer may prompt to reconnect the next time the app is used.

4. Check for Unauthorized Forwarding Rules and Filters

Unauthorized forwarding rules and filters are a common indicator of account compromise — an attacker who gains access to a Gmail account often sets up a forwarding rule to receive copies of incoming email, or a filter to hide security alerts from Google. These rules persist even after the account password is changed, so checking for them is an important part of both routine security review and post-compromise remediation. To check forwarding rules: go to Settings > See all settings > Forwarding and POP/IMAP. Confirm that forwarding is either disabled or set to a recognized address. To check filters: go to Settings > See all settings > Filters and Blocked Addresses. Review all active filters for any that forward messages to an external address, delete messages, or apply actions to messages from Google (which could hide security alerts). Remove any forwarding rules or filters that are not recognized or not intentionally set up.

5. Review Recent Account Activity and Sign-In Locations

⚠️ Worth checking regularly: Gmail provides a log of recent account activity that shows the IP addresses, locations, and device types used to access the account. Reviewing this log periodically — and immediately if there is any suspicion of unauthorized access — can identify unfamiliar sign-ins before significant damage is done. To access the activity log: scroll to the bottom of the Gmail inbox and click "Details" next to "Last account activity." This opens a window showing recent access, including the access type (browser, mobile, IMAP), location, and time. If any access appears unfamiliar, click "Sign out all other web sessions" to terminate active sessions, then change the account password and review security settings. Google's Security Checkup at myaccount.google.com/security-checkup also highlights any security issues detected by Google, including unfamiliar devices and recent security events.


Step-by-Step: How to Secure Your Gmail Account

Step 1: Run Google's Security Checkup

Go to myaccount.google.com/security-checkup and complete Google's guided security review. The Security Checkup reviews recent security events, sign-in and recovery options, third-party access, and device activity — and highlights any issues that need attention. This is the fastest way to get a comprehensive overview of the account's current security posture. Address any issues flagged by the Security Checkup before proceeding to the more detailed steps below.

Step 2: Enable Two-Factor Authentication

Go to myaccount.google.com/security and click "2-Step Verification" under "How you sign in to Google." Follow the setup wizard. Choose an authenticator app (Google Authenticator, Authy, or a password manager with TOTP support) as the primary 2FA method rather than SMS if possible. After enabling 2FA, generate backup codes and store them securely outside the Gmail account. If a hardware security key is available (YubiKey or similar), adding it as a second 2FA method provides additional protection.

Step 3: Update Recovery Options and Password

Go to myaccount.google.com/security and review the recovery phone number and recovery email address. Update any that are outdated. If the current Gmail password is old, reused across other services, or may have been exposed in a data breach (check at haveibeenpwned.com), change it to a strong, unique password. Use a password manager to generate and store the new password — a password manager makes it practical to use a different strong password for every account without needing to remember them.

Step 4: Audit Connected Apps and Remove Unnecessary Access

Go to myaccount.google.com/permissions and review all connected apps. For each app, consider: Is this app still in use? Is the access scope appropriate for the app's function? Is the developer recognized and trustworthy? Remove any apps that are no longer needed, unrecognized, or that have broader access than their function requires. Pay particular attention to apps with Gmail read/write access, as these have the most significant capability to access email data.

Step 5: Check Forwarding, Filters, and Recent Activity

Go to Settings > See all settings > Forwarding and POP/IMAP and confirm no unauthorized forwarding is active. Go to Settings > See all settings > Filters and Blocked Addresses and review all active filters. Scroll to the bottom of the Gmail inbox and click "Details" to review recent account activity. If any unfamiliar access is found, sign out all other sessions, change the password, and complete a full security review. Set a reminder to repeat this review periodically — annually at minimum, or whenever a security event occurs.


Frequently Asked Questions — Secure Gmail Account

How do I secure my Gmail account?

The most effective steps are: enable two-factor authentication using an authenticator app, update recovery options, audit connected third-party apps, check for unauthorized forwarding rules and filters, and review recent sign-in activity. Google's Security Checkup at myaccount.google.com/security-checkup provides a guided review of all these settings.

What is two-factor authentication and why does it matter for Gmail?

Two-factor authentication requires a second verification step — a code from an authenticator app, a hardware key, or an SMS — in addition to the password. Even if an attacker obtains the password, they cannot access the account without the second factor. Using an authenticator app or hardware key is more secure than SMS-based 2FA.

How do I check if my Gmail account has been compromised?

Check recent sign-in activity by scrolling to the bottom of the Gmail inbox and clicking "Details." Look for unfamiliar IP addresses, locations, or device types. Also check for unauthorized forwarding rules, filters, and changes to recovery options. Google's Security Checkup at myaccount.google.com/security-checkup highlights any security issues detected.

Are third-party apps connected to Gmail a security risk?

Apps with broad access scopes (such as full Gmail read/write access) have significant capability to access email data. Apps that are no longer used, unrecognized, or that request more access than their function requires are worth removing. Connected apps can be reviewed and revoked at myaccount.google.com/permissions.

What should I do if my Gmail account is hacked?

Use Google's account recovery at accounts.google.com/signin/recovery to regain access. After regaining access: change the password, restore recovery options, remove unauthorized forwarding rules and filters, revoke unrecognized connected apps, review recent account activity, and enable two-factor authentication. Change passwords for other accounts that use the same password.


Conclusion & My Take

Securing a Gmail account is not a one-time task — it is a periodic review that takes less than 15 minutes and significantly reduces the risk of compromise. The most impactful single step is enabling two-factor authentication with an authenticator app, which prevents the majority of account takeover attempts even when the password has been exposed. The connected apps audit and the forwarding rule check are the steps most often skipped, and they are the ones most likely to reveal unexpected access that has accumulated over time. Google's Security Checkup is the most practical starting point for anyone who has not reviewed their Gmail security settings recently — it surfaces the most important issues in a guided format without requiring knowledge of where each setting is located. Running it annually, and immediately after any suspected security event, is a reasonable baseline practice. For accounts that contain particularly sensitive information — financial, legal, or professional — a more frequent review and the use of a hardware security key as the 2FA method provides additional protection. Have you recently reviewed your Gmail security settings and found something unexpected — an old connected app with broad access, or a forwarding rule you did not set up? These discoveries are more common than most users expect — feel free to share your experience in the comments below.


Sources

Share

Related Posts