Gmail Security Checklist: What It Covers
A Gmail account often holds access to banking alerts, work messages, password resets, and sensitive personal data.
This Gmail security checklist shows the most important steps to reduce phishing, stop unauthorized access, and keep your Google Account safer.
Because Gmail is tied to the broader Google ecosystem, securing one inbox also helps protect Google Drive, Google Photos, Contacts, and connected apps.
A few focused settings changes can make a major difference.
Start With the Basics: Secure Your Google Account
Gmail security begins with the Google Account that powers it.
If an attacker gets into that account, they can often read mail, reset passwords, and access other Google services.
- Use a strong, unique password generated by a password manager.
- Avoid reusing passwords across email, banking, and social accounts.
- Review your recovery email and recovery phone number for accuracy.
- Remove outdated recovery methods you no longer control.
- Sign out of old devices you do not use anymore.
Google Account security settings are the foundation for everything else in Gmail, so this is the first place to check.
Enable Two-Step Verification
Two-step verification, also called 2FA, adds a second layer of protection after your password.
Even if someone steals your password through phishing or a data breach, they still need the second factor to sign in.
For most users, the best options are Google prompts, authenticator apps, or hardware security keys such as YubiKey.
SMS codes are better than no second factor, but they are generally weaker than app-based or hardware-based methods.
- Turn on two-step verification in your Google Account settings.
- Prefer Google Authenticator, Authy, or another TOTP authenticator app.
- Consider a FIDO2 security key for stronger protection.
- Save backup codes in a secure offline location.
If you use Gmail for work, pair 2FA with an enterprise identity policy such as SSO or a mobile device management rule when available.
Review Gmail Sign-In Activity and Connected Devices
Regularly checking where your account is signed in helps you catch suspicious access early.
Gmail and Google Account pages show recent login activity and devices that have permission to access your account.
- Look for unfamiliar locations, browsers, or devices.
- Remove sessions you no longer recognize.
- Check for old phones, tablets, laptops, and shared computers.
- Review third-party app access as part of the same audit.
If you see an unknown session, change your password immediately and review security notifications from Google.
Watch for Phishing in Gmail
Phishing remains one of the most common ways attackers compromise Gmail accounts.
A convincing message can push you to enter credentials on a fake sign-in page, approve a fraudulent OAuth consent screen, or open a malicious attachment.
Common warning signs include urgent language, mismatched sender addresses, unexpected attachments, and links that lead to domains that do not match Google or the legitimate sender.
Gmail’s built-in phishing filters help, but they are not perfect.
- Hover over links before clicking them.
- Verify the sender using a separate trusted channel if the request is sensitive.
- Do not sign in from email links when possible; use a bookmarked Google sign-in page instead.
- Be cautious with messages asking for passwords, verification codes, or remote access.
Security awareness is one of the most effective defenses against phishing, especially for business users and administrators.
Check Gmail Forwarding, Filters, and Delegation Settings
Attackers who gain access to an account may set up forwarding rules or filters to silently copy incoming messages.
They may also add delegates or change IMAP settings to keep access even after a password reset.
Review these settings carefully in Gmail:
- Forwarding addresses
- Filters and blocked addresses
- Delegated access
- POP and IMAP access
- Signature changes and auto-reply settings
If you find a forwarding rule you did not create, delete it right away and inspect the account for other signs of compromise.
Hidden mail rules are a common persistence technique used after account takeover.
Audit Third-Party App Access
Many users connect Gmail to calendar tools, CRM systems, email clients, and automation platforms.
Those connections can be useful, but each one increases the attack surface.
Google Account permissions may allow apps to read mail, send mail, or manage contacts.
Over time, old apps can remain authorized long after they are needed.
- Review connected apps and services in your Google Account dashboard.
- Remove apps you no longer use or do not recognize.
- Avoid granting broad Gmail permissions unless absolutely necessary.
- Use OAuth consent only for trusted vendors with clear privacy practices.
This step matters for both consumer and business accounts, especially if you use Gmail with productivity platforms such as Slack, Zoom, Salesforce, or email clients like Outlook and Apple Mail.
Use Secure Sign-In Practices on Every Device
Device hygiene is part of Gmail security because a compromised phone or laptop can expose active sessions, saved passwords, and verification codes.
Keeping operating systems and browsers updated reduces exposure to known vulnerabilities.
- Install updates for Chrome, Safari, Edge, Windows, macOS, iOS, and Android.
- Lock devices with strong PINs, passwords, biometrics, or device encryption.
- Avoid signing into Gmail on public or shared computers.
- Turn off browser password saving on devices you do not control.
If you must use a public machine, sign out fully, close the browser, and clear session data when possible.
Protect Recovery Options and Backup Access
Recovery settings are often overlooked, but they determine how easily you can regain access after a lockout or attack.
They also help prevent attackers from taking over your account through weak recovery details.
- Use a recovery email address you actively monitor.
- Use a mobile number that is secure and under your control.
- Store backup codes in a password manager or offline safe.
- Verify that recovery details are not outdated.
For higher-risk users, such as journalists, executives, and small business owners, consider additional protection with a hardware security key and dedicated recovery planning.
Turn On Gmail Security Alerts and Google Account Notifications
Security alerts help you detect suspicious events such as new sign-ins, password changes, and account recovery attempts.
These notifications are especially valuable because attackers often act quickly after gaining access.
Make sure alerts are enabled on the email address and device you check most often.
If you receive an alert you do not recognize, treat it as urgent and review your account activity immediately.
How to Handle a Suspected Gmail Compromise?
If you think your Gmail account may be compromised, act quickly.
Time matters because attackers may use the account to send spam, reset other passwords, or steal sensitive messages.
- Change your Google Account password immediately.
- Sign out of all devices and revoke unknown sessions.
- Review forwarding rules, filters, recovery details, and third-party access.
- Run a malware scan on devices you use for Gmail.
- Check sent mail, trash, and inbox rules for suspicious activity.
- Alert contacts if the attacker may have sent phishing emails from your account.
If you can no longer sign in, use Google’s account recovery flow and complete it from a trusted device and network when possible.
Gmail Security Checklist for Ongoing Maintenance
Use this recurring Gmail security checklist to keep your account protected over time:
- Update your password when there is a breach or sign-in concern.
- Keep two-step verification enabled.
- Review recovery options every few months.
- Audit connected apps and device sessions regularly.
- Check forwarding, filters, and delegation settings.
- Stay alert for phishing and social engineering attempts.
- Keep devices and browsers patched and encrypted.
Consistent maintenance is the key to keeping Gmail secure because threats change, and attackers often exploit old settings, forgotten devices, or unused app permissions.