Your Google account is the key to your entire digital life. It connects your Gmail, Google Drive, YouTube, Google Photos, and dozens of other services. If someone gains access to your Google account, they could read your emails, access your files, and even lock you out entirely.
Google provides a built-in Security Checkup tool that reviews your account security settings and identifies potential vulnerabilities. Running this checkup regularly is one of the simplest and most effective ways to keep your account safe.
This guide walks you through every section of the Google Security Checkup, explains what each recommendation means, and shows you how to fix any issues it finds.
What the Google Security Checkup Does
The Security Checkup is a free tool built into every Google account. It scans your account settings and flags potential security risks across several categories:
- Sign-in and recovery — Checks whether your recovery email and phone number are up to date.
- Recent security activity — Shows recent sign-in events and alerts you to anything suspicious.
- Devices — Lists every device currently signed into your account.
- Third-party access — Shows which apps and services have access to your Google account data.
- Gmail settings — Checks for email forwarding rules or filters that could be redirecting your messages.
- Saved passwords — Identifies reused, weak, or compromised passwords stored in Google Password Manager.
Each section uses a colour-coded system. A green tick means no issues were found. A yellow warning means something needs attention. A red alert means there is a significant security risk that should be addressed immediately.
How to Access the Google Security Checkup
You can access the Security Checkup from any web browser on your computer or smartphone.
- Open your web browser and go to myaccount.google.com/security-checkup.
- Sign in with the Google account you want to check.
- Google will automatically scan your account and display the results.
You can also reach this page by opening Google Account Settings, selecting Security from the left menu, and clicking Security Checkup at the top of the page.
Review Your Sign-in and Recovery Settings
This section checks whether your recovery options are current. If you ever lose access to your account, Google uses your recovery email and phone number to verify your identity.
What to check:
- Recovery email — Make sure this is an email address you currently have access to. If you have changed email providers or no longer use the listed address, update it immediately.
- Recovery phone number — Confirm this is your current mobile number. If you have changed your phone number, update it.
- Two-step verification — This is the single most important security setting on your account. If it is not enabled, you should turn it on immediately.
Without a recovery email and phone number, account recovery becomes extremely difficult if you forget your password or your account is compromised.
How to Enable Two-Step Verification
Two-step verification (also called two-factor authentication or 2FA) adds an extra layer of security beyond your password. Even if someone discovers your password, they cannot access your account without the second verification step.
- Go to myaccount.google.com/signinoptions/two-step-verification.
- Click Get started.
- Follow the prompts to add your phone number or set up the Google Authenticator app.
- Google will send a verification code to confirm your setup.
For the strongest protection, consider using Google Prompts (which sends a notification to your phone) or a physical security key instead of SMS verification codes.
Check Your Recent Security Activity
This section shows recent security events on your account, such as:
- New device sign-ins.
- Password changes.
- Recovery option changes.
- Suspicious activity alerts.
Review each event carefully. If you see a sign-in from a location or device you do not recognise, your account may have been compromised.
What to do if you see suspicious activity:
- Change your password immediately.
- Sign out of all devices (you can do this from the Security Checkup page).
- Review and remove any unfamiliar third-party app access.
- Check your Gmail for any forwarding rules you did not create.
Review Devices Signed Into Your Account
The device list shows every phone, tablet, and computer currently signed into your Google account. Each entry shows:
- Device type and name.
- Operating system.
- Last activity time.
- Location (approximate, based on IP address).
What to do:
- Remove any devices you no longer use or do not recognise.
- If you sold or gave away a device, make sure it has been signed out.
- Pay attention to devices in locations you have never visited.
To remove a device, click on it and select Sign out. This will immediately revoke that device’s access to your account.
Review Third-Party App Access
Over time, you may have granted various apps and websites access to your Google account. Some of these may have broad permissions, such as reading your emails or accessing your files.
The Security Checkup lists all third-party apps with access to your account and shows what permissions each app has.
What to look for:
- Apps you no longer use — Remove access immediately.
- Apps you do not recognise — Remove access and investigate.
- Apps with broad permissions (such as full Gmail or Drive access) — Consider whether the app genuinely needs that level of access.
To remove an app, click on it and select Remove Access. This does not delete your account with that service but prevents it from accessing your Google data.
Check Your Gmail Settings
This section checks whether any email forwarding rules or filters have been set up in your Gmail account. Attackers sometimes create forwarding rules to silently copy your incoming emails to another address.
What to check:
- Forwarding addresses — If you see a forwarding address you did not add, remove it immediately and change your password.
- Filters — Check for any filters that automatically delete, archive, or forward emails without your knowledge.
- Delegated access — Ensure no one else has been granted access to read or send emails from your account.
You can review these settings directly in Gmail by going to Settings → See all settings → Forwarding and POP/IMAP and Filters and Blocked Addresses.
Review Your Saved Passwords
If you use Google Password Manager to save passwords, the Security Checkup also includes a password check. This scans your saved passwords for:
- Compromised passwords — Passwords that have appeared in known data breaches.
- Reused passwords — Passwords you are using across multiple websites.
- Weak passwords — Passwords that are too short or simple.
For each flagged password, Google recommends changing it. You can click the link next to each entry to go directly to that website and update your password.
Using a unique, strong password for every website is one of the most effective ways to protect yourself online. Google Password Manager can generate strong passwords automatically when you create new accounts.
How Often Should You Run the Security Checkup?
Google recommends running the Security Checkup periodically, but there are specific situations where you should run it immediately:
- After receiving a security alert from Google.
- After using a shared or public computer.
- After travelling and signing in from unfamiliar locations.
- After selling or giving away a device.
- After noticing unusual activity in your account.
- After a major data breach is reported in the news.
As a general habit, running the checkup every few months ensures your security settings remain up to date and no unauthorised access has occurred.
Additional Steps to Strengthen Your Google Account Security
Beyond the Security Checkup, consider these additional measures:
- Use passkeys — Google now supports passkeys as a passwordless sign-in method. Passkeys are more secure than passwords because they use biometric authentication on your device.
- Set up backup codes — Generate and securely store backup codes in case you lose access to your phone. You can generate these from your 2-Step Verification settings.
- Use Google’s Advanced Protection Programme — If you handle sensitive information, this programme provides the strongest account security Google offers, including physical security key requirements and enhanced download protections in Chrome.
- Review app passwords — If you use app-specific passwords for older email clients, review and remove any you no longer need.
- Keep your browser updated — An outdated browser can expose you to security vulnerabilities even if your account settings are perfect.
What to Do If Your Google Account Has Been Compromised
If the Security Checkup reveals signs of unauthorised access, take these steps immediately:
- Change your password — Choose a strong, unique password you have never used before.
- Sign out of all devices — Go to your Google Account security settings and select “Sign out of all other sessions”.
- Remove suspicious third-party apps — Revoke access for any apps you do not recognise.
- Check Gmail forwarding and filters — Remove any rules you did not create.
- Enable two-step verification — If it is not already active, enable it immediately.
- Update your recovery options — Make sure your recovery email and phone number are correct.
- Run the Password Checkup — Change any compromised or reused passwords.
If you are completely locked out of your account, visit Google’s account recovery page and follow the guided steps. The more recovery options you have set up in advance, the easier this process will be.
Keep Your Google Account Safe Going Forward
The Google Security Checkup takes less than five minutes to complete, but it can prevent serious problems. By reviewing your recovery options, removing old devices, revoking unnecessary app access, and enabling two-step verification, you significantly reduce the risk of your account being compromised.
Make it a regular habit. The few minutes you spend on the Security Checkup today could save you hours of recovery work later.