How to Tell If Your Gmail Has Been Compromised

    Confirm whether someone has actually accessed your account — with plain-English checks that each take under a minute.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 6 min read

    2 readers found this helpful
    Maybe you suspect someone has been in your Gmail and want to know for sure — or you've just recovered the account and need to be certain nothing was left behind to let them back in. Either way, take a breath: you're doing exactly the right thing. The same handful of quick checks cover both jobs — they confirm whether your account was actually accessed, and surface the quiet traps an intruder leaves to sneak back in later, like rogue forwarding rules, hidden filters and connected apps, so you can shut them down.

    How to check for unauthorised access

    1

    Sign in and check security activity

    First, sign in to your Google account on a device and browser you trust — go to accounts.google.com and log in. Once you're in, click Security & sign-in in the left menu, find Recent security activity, and click Review security activity to see the full list of recent sign-ins and alerts from the last 28 days.
    A sign-in from a city near you can still be legitimate — location is estimated from your IP address and is often imprecise. The clearest red flags are devices or operating systems you don't own, sign-ins at times you were asleep or not online, or any activity that doesn't match what you actually did.

    Keep in mind: if you use a VPN or a relay service (like iCloud Private Relay), your own legitimate activity can show up at unfamiliar or distant locations.
    accounts.google.com
    Google

    Welcome

    Aalex.taylor@gmail.com

    Forgot password?

    Next

    Google's Recent security activity list showing an unfamiliar new sign-in from another country

    2

    Lock out a sign-in you don't recognise

    Still in Recent security activity, click the sign-in you don't recognise. Google shows the device and location and asks Do you recognize this activity? Choose No, secure account — Google immediately walks you through changing your password and signing that session out, locking the intruder straight out.
    If it turns out the sign-in really was you (a new phone, a trip, or a VPN), choose Yes, it was me to clear the alert.
    myaccount.google.com/notifications
    Google AccountA

    Recent security activity

    Security activity and alerts from the last 28 days. Learn more

    See unfamiliar activity?

    June 16, 2026

    2:47 AM

    New sign-in on Windows

    Frankfurt, Germany

    Windows

    June 15, 2026

    4:40 PM

    New sign-in on Android

    New
    Android

    Opening a suspicious sign-in from Recent security activity and choosing No, secure account

    3

    Check your signed-in devices

    On the same Security & sign-in page, scroll down to Your devices and click Manage all devices. This lists every device with an active session — open any you don't recognise and choose Sign out.
    Unlike Recent security activity, which only covers the last 28 days, a session here can stay active long after the original sign-in. If you suspect someone has had access for a while, this is the most important place to look — a session they opened weeks ago can still be live here even though it no longer appears in your recent activity.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Backup codes · 10 codes available

    Your devices

    Where you're signed in

    3 sessions on Windows computer(s)

    Windows, Windows, …

    1 session on Android phone

    Android

    Find a lost device

    Manage all devices

    4

    Security page Your devices section, then Manage all devices showing every active session

    4

    Check your recovery and verification methods

    An attacker who got in may have quietly added their own way back. Start with your recovery options: open Security & sign-in and check your recovery email and phone, and remove or reset anything you don't recognise — a recovery method they control lets them reset your password all over again later.

    Then open 2-Step Verification and read every method listed under Second steps. A second authenticator, phone or passkey they added is another way in — remove any you don't recognise.

    Finally, check your backup codes. If a set exists that you didn't create — or you can't be sure — choose Get new codes straight away. That generates a fresh set and instantly cancels the old ones, so any codes the attacker copied stop working.

    myaccount.google.com/security
    Google AccountA

    Security & sign-in

    Ways we can verify it's you

    Recovery info helps confirm it's really you — make sure none of it belongs to someone else.

    Recovery email

    a•••@mail.ru · don't recognise this?

    Remove

    Recovery phone

    •••• ••89

    2-Step Verification

    ● On

    2-Step Verification second steps with an unrecognised method, then regenerating backup codes to invalidate old ones

    5

    Review your linked apps

    Now go back to the Security & sign-in page and scroll to Your linked apps, then click See all linked apps. The list only shows app names — click any app you don't recognise to see exactly what it can access. If it has broad access to your Gmail, contacts or Drive and you didn't set it up, choose Delete all to revoke it. Attackers sometimes connect an app to keep a way in even after you change your password.
    Don't judge by the name alone — check the permissions, since a harmless-looking app can hold full mailbox access.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Manage all devices

    4 ›

    Your linked apps

    Keep track of your Google Account data

    Bing Webmaster Tools

    Proton

    Inbox Cleaner

    See all linked apps

    3

    Security page Your linked apps section, then See all linked apps showing every app with access

    6

    Check your filters

    In Gmail on a computer, open Settings → See all settings → Filters and Blocked Addresses. A favourite trick is a hidden filter that automatically deletes, archives or marks your incoming security alerts as read — so the warning emails never reach you. Delete any filter you didn't create.
    These settings aren't in the mobile app; open Gmail in your phone's browser and request the desktop site if you're away from a computer.
    M
    Search mail
    GGoogleSecurity alert9:14 AM
    NNetflixYour receipt for AugustYesterday
    LLinkedInYou appeared in 4 searchesMon
    DDropboxYour files are ready to viewAug 2
    Quick settings
    See all settings

    Density

    ● Default

    ○ Comfortable

    ○ Compact

    Gmail inbox to Settings to See all settings to Filters and Blocked Addresses, revealing a malicious filter that deletes security alerts

    7

    Check your forwarding

    Still in Settings, open the Forwarding and POP/IMAP tab. A common trick is a quiet forwarding rule that sends a copy of every email to an address the attacker controls — so they keep reading your mail even after you change your password. Remove any forwarding address you didn't set up, and turn forwarding off if you don't use it.
    MSettings
    GeneralInboxAccounts and ImportFilters and Blocked AddressesForwarding and POP/IMAP

    The following filters are applied to all incoming mail:

    Matches: subject:(security alert OR password)

    Do this: Skip Inbox, Mark as read, Delete it

    A hidden Gmail forwarding rule sending mail to an unknown address

    Frequently asked questions

    Can someone read my emails without me knowing?
    Yes. If an attacker has your password or has set up a hidden forwarding rule, they can read your mail silently. That's why checking your filters, forwarding settings and active sessions matters even when nothing looks obviously wrong.
    I got a security alert, but it was me. Should I worry?
    No. Alerts for your own new phone, browser or location are completely normal. Only act if the device, place or time is something you genuinely don't recognise.
    Does changing my password log everyone else out?
    On most accounts, yes — changing your password ends other active sessions, which is one of the fastest ways to push out someone who has access. Turn on two-factor authentication straight afterwards so a stolen password alone isn't enough next time.
    What if I'm locked out of my account completely?
    Start the account recovery process as soon as you can — the longer you wait, the more an attacker can change. Our step-by-step Gmail recovery guide walks you through getting back in, even if your password, recovery email and phone have all been changed.

    What to do next

    If you found something

    You've signed the intruder out and cleared the footholds they left behind — now make sure they can't get back in. Lock the account down with two-step verification and tighten your recovery details.
    Secure your Gmail account

    If everything looks clean

    That's a relief — and it's the perfect moment to get ahead of the next attempt. Gmail will always be a high-value target. With an end-to-end encrypted inbox like Proton Mail, your messages are encrypted so that only you can ever read them — not even Proton can see inside. It's the single biggest upgrade you can make to your email security.
    Why switch to Proton Mail

    Worried about another account?

    The warning signs are universal — here's the full checklist that works for any email account.
    Signs any email is hacked

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Email Security