Your Google Account Security Settings Need a Checkup: What to Review and Why Each Setting Matters

Your Google Account may be connected to Gmail, Google Drive, Photos, YouTube, Chrome, Android devices, saved passwords, and many third-party apps.

That makes the account’s security settings worth checking regularly.

You do not need to change every setting just because it exists. A better approach is to review the important security controls, confirm that the information is yours, remove access you no longer need, and make sure you have a reliable way to recover the account if you lose access.

Google provides a Security Checkup for this purpose, along with separate controls for devices, sign-in methods, recovery information, passkeys, 2-Step Verification, and third-party app access.

This guide explains what to review and why each area matters.

Important: Google frequently changes the names and layout of account settings. If a menu looks slightly different on your device, use the security section of your Google Account rather than relying on an exact button location.


Start With Google Security Checkup

The easiest place to begin is Google’s built-in Security Checkup.

Open your Google Account and go to:

Security & sign-in → Security Checkup

Google recommends taking a Security Checkup regularly to review security settings and activity.

You can also open your Google Account directly and select the security section.

The purpose of the checkup is not to make you change everything.

Instead, use it to answer a few basic questions:

  • Do I recognize the devices using my account?
  • Do I recognize recent security activity?
  • Is my recovery information current?
  • Is 2-Step Verification enabled?
  • Are my sign-in methods familiar?
  • Are third-party apps accessing information I no longer want to share?
  • Are there security warnings that I have ignored?

If everything looks correct, you may not need to make major changes.


1. Review Recent Security Activity

One of the first things to check is whether anything important happened to your account that you do not recognize.

In your Google Account, open:

Security & sign-in → Recent security activity

Look for events such as:

  • New sign-ins
  • New devices
  • Changes to security settings
  • Password changes
  • New sign-in methods
  • Recovery information changes
  • Other important account activity

Google advises reviewing recent security events and taking action when an activity was not performed by you.

Why this matters

A strong password cannot help much if someone has already gained access to your account.

Recent security activity gives you an opportunity to notice something unusual before it becomes a larger problem.

What if you see an unfamiliar event?

Do not automatically assume that every unfamiliar location or device means your account has been hacked.

Google notes that device and session information can sometimes look unfamiliar because of travel, a new browser, an old device, a public computer, or background synchronization.

Check the details first.

If you are confident the activity was not yours, follow Google’s account-security steps rather than simply dismissing the notification.


2. Check Every Device Signed In to Your Account

Go to:

Security & sign-in → Your devices → Manage all devices

Google lists devices and sessions that are currently signed in or were recently used with your account.

Look for:

  • Your current phone
  • Your computers
  • Tablets
  • Older phones
  • Browsers you still use
  • Devices belonging to work or school, if applicable

Why this matters

Old devices are easy to forget.

You may have:

  • Sold an old phone
  • Given a tablet to someone else
  • Replaced a laptop
  • Used a friend’s computer
  • Signed in on a public computer
  • Forgotten about an old browser session

If you no longer own or use a device, signing it out removes that session from your account.

Google specifically recommends signing out of devices that are lost, no longer owned by you, or do not belong to you.

Do not panic over multiple sessions

You may see several sessions associated with what appears to be the same device.

Google explains that multiple sessions can be created when you sign in through different browsers, apps, or services.

Review the details before assuming that every entry represents a separate physical device.


3. Check Your Recovery Phone Number

Your recovery phone is an important account-recovery method.

Open the security settings and look for your recovery information.

Confirm that:

  • The number belongs to you.
  • You still use it.
  • You can receive messages on it.
  • It is not an old number.
  • You recognize the number shown in the account.

Google says keeping recovery information current helps you regain access if you forget your password or become locked out because of suspicious activity.

Why this matters

Imagine losing access to your Google Account and discovering that the recovery phone belongs to a number you stopped using years ago.

You may have fewer options for proving that the account belongs to you.

Important caution

Do not change recovery information simply because you want a different number.

Make sure the new recovery method is actually yours and that you can use it when necessary.


4. Check Your Recovery Email

Your recovery email is another important part of account recovery.

Google recommends using an email address that you regularly use and that is different from the address you use to sign in to the Google Account.

Check that:

  • You recognize the recovery email.
  • You still have access to it.
  • It is protected with its own security measures.
  • It is not an abandoned address.

Why this matters

A recovery email can be particularly useful if you lose access to your phone.

However, there is an important dependency:

Your recovery email should itself be secure.

If another person can access your recovery email, changing your Google Account password alone may not solve the underlying problem.


5. Check Whether 2-Step Verification Is Enabled

Look under:

Security & sign-in → How you sign in to Google → 2-Step Verification

Google says 2-Step Verification adds another layer of protection if your password is stolen.

Instead of relying only on your password, Google can require an additional authentication step.

Depending on your account and devices, available methods can include:

  • Google prompts
  • Authentication codes
  • Passkeys
  • Security keys
  • Other supported verification methods

Why this matters

A stolen password does not automatically provide the same level of access when another authentication step is required.

Google specifically explains that 2-Step Verification helps protect accounts from password-stealing attacks.

Don’t stop after turning it on

Check the available backup methods as well.

You want to avoid a situation where your account is well protected but you cannot sign in because your only verification method is unavailable.


6. Review Your 2-Step Verification Methods

If 2-Step Verification is already enabled, review the methods attached to it.

Look for:

  • Phones you still own
  • Authenticator methods you still use
  • Security keys
  • Backup codes
  • Other verification options

Remove or update methods that no longer belong to you.

Why this matters

Security settings can become outdated just like devices and recovery numbers.

For example, you might have:

  • Replaced your phone
  • Lost a security key
  • Reset an old device
  • Changed your authentication app
  • Created backup codes that you no longer want to keep

If you lose your backup codes, Google allows you to revoke them and generate new ones.


7. Review Your Backup Codes

Backup codes can help you sign in when you cannot use your normal second verification method.

Google provides backup codes after 2-Step Verification is enabled.

If you have generated them, ask:

Do I still know where they are stored?

If the codes were:

  • Saved on an old computer
  • Printed and lost
  • Shared with someone
  • Stored somewhere you no longer control

generate a new set and store it securely.

Do not leave backup codes in an easily accessible public document or send them to another person through ordinary chat.


8. Review Your Passkeys

Passkeys are now an important part of Google Account sign-in.

Google says passkeys can use a device’s:

  • Fingerprint
  • Face scan
  • Screen lock
  • PIN

instead of relying on a traditional password.

Open your Google Account’s sign-in settings and review the passkeys associated with your account.

Why this matters

A passkey should be created on a device you personally own and regularly use.

Google specifically warns that anyone who can unlock a device with a passkey may be able to access the associated Google Account.

Check for old devices

If you created a passkey on an old device that you no longer own, review the passkey and device information.

Google provides options for removing passkeys associated with devices you no longer trust.


9. Understand “Skip Password When Possible”

If you use passkeys, you may see an option related to:

Skip password when possible

Google says creating a passkey normally opts you into a passkey-first sign-in experience, while the password can still be used.

This is not a setting you should change automatically.

Instead, understand what it does.

If you prefer to use your password first, Google provides a setting to turn off the password-skipping preference.

The important point is to recognize that passkeys and passwords are not necessarily competing security systems. Passkeys can be used as a secure sign-in method while your existing recovery and authentication options remain available.


10. Check Your Password

Your Google Account password should be:

  • Unique
  • Difficult for others to guess
  • Not reused on unrelated websites
  • Kept private

Google Password Manager can help identify compromised saved passwords and recommends strong, unique passwords.

Why password reuse is risky

Suppose you use the same password for:

  • Your Google Account
  • An online forum
  • A shopping website
  • A gaming account

If the other website suffers a password leak, attackers may try the same credentials against your Google Account.

That is why your Google password should not be reused elsewhere.


11. Review Passwords Saved in Google Password Manager

If you use Google Password Manager, review the passwords stored there.

You do not necessarily need to delete saved passwords.

Instead, look for security problems such as:

  • Reused passwords
  • Weak passwords
  • Compromised passwords
  • Accounts you no longer use

Google Password Manager can notify you about compromised saved passwords and help you change them.

What to do with a compromised password

Change it on the affected website or service.

Do not simply delete the saved password and assume the underlying account is secure.

The actual password must be changed with the service that uses it.


12. Review Third-Party Apps With Google Account Access

This is one of the most commonly overlooked areas.

Google Accounts can be connected to apps and services outside Google.

Go to your Google Account’s linked-apps section and review the services listed there.

Google allows you to review what access third-party applications have and remove access when you no longer want them connected.

Why this matters

An app might have been given access months or years ago.

You may no longer:

  • Use the app
  • Remember installing it
  • Trust the developer
  • Need the connection

Removing access can prevent the application from continuing to access the Google Account information covered by that authorization.

Don’t remove everything blindly

Some applications legitimately need Google access.

For example, a service might use Google Drive, Calendar, Photos, or another Google product as part of a feature you actively use.

Review the requested access first.

Google explains that third-party applications can receive different levels of access, ranging from basic profile information to the ability to access or manage certain account data.


13. Review “Sign in With Google” Connections

Using Sign in with Google does not mean that the third-party website becomes your Google Account.

The accounts remain separate.

However, the connection itself is worth reviewing.

Google provides controls for reviewing and removing Sign in with Google connections.

If you no longer use a service, consider removing the connection.

Important distinction

Removing a Google sign-in connection does not necessarily delete your account or data on the third-party service.

Google specifically notes that removing the connection does not delete data already held by the third-party service.

If you want that data deleted, you may need to contact or use the privacy controls of the third-party service itself.


14. Check Which Apps Can Access Your Google Data

Do not only look at whether an app uses Sign in with Google.

Some apps may have separate permissions to access Google services or data.

Review what each connected application can access.

For example, a third-party application might request access to:

  • Google Drive
  • Gmail
  • Contacts
  • Calendar
  • Photos
  • Other Google Account information

Google says an application can only access the data and services that you authorize, but some authorizations can include permission to modify, create, or delete account data.

That makes the requested permission level important.


15. Check Security Alerts

Google may send security alerts when it detects important activity, such as a sign-in from a new device or suspicious account behavior.

Do not automatically dismiss these notifications.

When you receive one:

  1. Review the device information.
  2. Check the time.
  3. Check the location information.
  4. Decide whether the activity was yours.
  5. Follow Google’s security instructions if it was not.

Be careful with security-alert emails

If an email tells you to sign in urgently, avoid clicking suspicious links.

Instead, open your Google Account directly through your normal browser or Google app and check the security section yourself.

This reduces the risk of entering your password into a fake login page.


16. Check for Unfamiliar Changes to Recovery Information

Security problems do not always begin with a new device.

Someone with access to an account may attempt to change:

  • Recovery phone
  • Recovery email
  • Password
  • 2-Step Verification settings
  • Sign-in methods
  • Connected applications

Google identifies unfamiliar changes to important security settings as a warning sign that should be investigated.

If you find a security setting that you did not change, treat it more seriously than an old device you simply forgot about.


17. Check Your Gmail Security Separately

Your Google Account protects Gmail, but Gmail itself has important settings worth reviewing.

Pay attention to:

  • Mail delegation
  • Forwarding
  • Filters
  • Automatic replies
  • Suspicious sent messages
  • Recovery information
  • Recent account activity

This matters because an attacker who gains access to Gmail may be able to see password-reset emails from other services.

If you find an unexpected forwarding address or suspicious Gmail setting, investigate it promptly.

Google lists unfamiliar Gmail setting changes among the signs that can indicate suspicious account activity.


18. Check Your Devices Before Blaming the Account

Sometimes a strange sign-in notification has a completely normal explanation.

For example:

  • You recently bought a new phone.
  • You reset an old device.
  • You signed into Chrome on another computer.
  • You used a work browser.
  • You used a public computer.
  • An application synchronized in the background.

Google explains that sessions can appear because of browser, app, service, or background synchronization activity.

The correct approach is to examine the details rather than immediately assuming account compromise.


19. Check Whether You Still Control Your Recovery Methods

A security checkup is incomplete if your recovery methods do not work.

Confirm that you can access:

  • Your recovery phone
  • Your recovery email
  • Your trusted devices
  • Your passkeys
  • Your 2-Step Verification methods
  • Your backup codes, if used

The goal is to avoid having strong security settings that accidentally lock you out of your own account.

Google recommends keeping recovery information up to date specifically to help restore account access when you forget your password or become locked out.


20. Don’t Change Security Settings Just for the Sake of Changing Them

A security checkup is not a race to enable or disable every available option.

For each setting, ask:

What problem does this setting solve?

Do I recognize the device, method, or application connected to it?

Would changing it affect how I recover my account?

This is especially important with:

  • Passkeys
  • 2-Step Verification
  • Recovery methods
  • Security keys
  • Third-party permissions

A good security configuration is one you understand and can reliably use.


What to Do If You Find Something You Don’t Recognize

If you discover an unfamiliar device, security event, recovery method, or sign-in method, don’t simply delete one item and move on.

Start with the account-security process.

Google recommends reviewing security activity and devices and following its steps to secure a compromised account.

Depending on what you find, this can include:

  1. Securing the account.
  2. Changing the Google Account password.
  3. Removing unfamiliar devices.
  4. Reviewing recovery information.
  5. Reviewing 2-Step Verification methods.
  6. Removing unfamiliar third-party access.
  7. Checking Gmail for suspicious activity.
  8. Checking saved passwords for reuse or compromise.

If you cannot sign in, use Google’s official account-recovery process rather than relying on third-party recovery services.


What You Should Not Do During a Security Checkup

Don’t remove every connected app

Some connections may be legitimate and necessary.

Review the permissions first.

Don’t delete recovery information without a replacement

You want reliable recovery options, not fewer recovery options.

Don’t share verification codes

A legitimate support process should not require you to hand a verification code to a stranger who contacts you unexpectedly.

Don’t give your Google password to another app

Google explicitly advises against sharing your Google Account password with third-party applications.

Don’t panic over an unfamiliar location alone

Location information can be imperfect, and sessions may reflect background communication.

Look at the complete activity details.

Don’t click suspicious security links

If you receive a security warning, open your Google Account directly and check the security section yourself.


A Simple Google Account Security Checkup Routine

You do not need to inspect every setting every day.

A practical routine is:

Regularly

Check:

  • Recent security activity
  • Your devices
  • Security alerts
  • Recovery information

When you install or stop using apps

Review:

  • Sign in with Google connections
  • Third-party account access
  • Permissions requested by the service

After replacing a phone or computer

Check:

  • Old device sessions
  • Passkeys
  • 2-Step Verification methods
  • Recovery options
  • Google Account sessions

After a security warning

Do a deeper review of:

  • Password
  • Devices
  • Recent security activity
  • Recovery information
  • Passkeys
  • 2-Step Verification
  • Third-party applications
  • Gmail activity

Google Account Security Checklist

Use this checklist when reviewing your account:

  • Security Checkup completed
  • Recent security activity reviewed
  • All signed-in devices recognized
  • Old devices signed out
  • Recovery phone is current
  • Recovery email is current
  • 2-Step Verification reviewed
  • Backup methods reviewed
  • Backup codes stored securely
  • Passkeys reviewed
  • Password is unique
  • Compromised passwords checked
  • Third-party apps reviewed
  • Sign in with Google connections reviewed
  • Gmail security settings checked
  • Security alerts reviewed
  • No unexplained security-setting changes

Frequently Asked Questions

How often should I check my Google Account security settings?

Google recommends taking a Security Checkup regularly. You should also review your settings after changing devices, losing a device, receiving a suspicious security alert, or installing services that receive Google Account access.

Is a passkey safer than a password?

Passkeys are designed to provide stronger protection against phishing and use cryptographic authentication tied to your device. Google describes them as a secure alternative to passwords.

However, you should still review the devices where passkeys exist and maintain appropriate recovery options.

Should I turn on 2-Step Verification?

Google describes 2-Step Verification as an additional layer of protection if your password is stolen.

If you use it, also review your backup authentication and recovery methods so you can still access the account when your primary device is unavailable.

What should I do if I don’t recognize a Google device?

First review the device details and session information. If you are confident it does not belong to you, follow Google’s account-security process and sign out the unfamiliar session.

Does removing a third-party app delete my data from that service?

Not necessarily. Removing its Google Account access prevents further access covered by that authorization, but the third party may already have stored data. Google recommends contacting the third-party service if you want data it already holds deleted.

Should I remove old Google Account devices?

If you no longer own or use a device, signing it out is a sensible account-maintenance step. Google specifically recommends signing out devices that are lost, no longer owned, or do not belong to you.

What if someone changed my recovery email or phone number?

Treat an unexplained change to important security information seriously. Google lists unfamiliar changes to recovery information among signs that someone else may be using an account. Follow Google’s account-security or recovery process rather than simply changing one setting and assuming the problem is solved.

Can I remove a passkey from an old device?

Yes. Google provides controls for reviewing and removing passkeys, including passkeys associated with devices you no longer use.


Final Takeaway

A Google Account security checkup is not about changing every available option.

The most useful approach is to verify what is already connected to your account.

Start with Security Checkup, then review recent security activity, signed-in devices, recovery information, 2-Step Verification, passkeys, passwords, and third-party applications.

Pay particular attention to anything you do not recognize.

If everything belongs to you and your recovery methods still work, you may not need to make major changes. If something is unfamiliar, investigate it before dismissing it.

The goal is simple: know who can sign in, what methods can be used, which devices have access, what outside services are connected, and how you would recover the account if something went wrong.

Official Google Resources

Leave a Comment