How to Secure Your Gmail Account

    Lock down your Gmail in about ten minutes — turn on 2-Step Verification, set a strong password, fix your recovery options, and close the gaps attackers exploit.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 7 min read

    Locking down your Gmail takes about ten minutes and shuts the door on the vast majority of account takeovers. We'll go strongest-first — even doing just the first two steps puts you well ahead of most people.

    Think you've been hacked?

    Already seeing strange sign-ins, settings you didn't change, or emails you didn't send? Someone may already be in. Confirm it and lock them out first — then come back to harden your account.
    Check if you've been compromised

    Secure your account, step by step

    1

    Sign in and open Security & sign-in

    Do all of this from a device and browser you trust. Sign in to your Google account at accounts.google.com, then click Security & sign-in in the left menu and scroll down to How you sign in to Google. This one section holds your 2-Step Verification, password, passkeys and recovery options — the next few steps each start right here.
    accounts.google.com
    Google

    Welcome

    Aalex.taylor@gmail.com

    Forgot password?

    Next

    Signing in to Google, opening Security & sign-in, and scrolling to How you sign in to Google with 2-Step Verification and recovery options

    2

    Add an authenticator app

    From Security & sign-in, click 2-Step Verification to open it. Before you can switch 2-Step on, your account needs at least one second step — an authenticator app is the best choice, since it makes codes offline and can't be SIM-swapped like a text message. Under Second steps, find Authenticator, choose Add authenticator app, then Set up authenticator.
    Install an authenticator app on your phone first. We'd suggest Proton Authenticator — free, open-source, and it generates your codes offline on the device itself (Google Authenticator or Authy work too). In the app, tap + and Scan a QR code, point it at the code Google shows, then enter the 6-digit code to confirm. A passkey or security key works as a second step too.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Security & sign-in

    How you sign in to Google

    Make sure you can always access your Google Account by keeping this information up to date.

    2-Step Verification

    ● Off

    Password

    Last changed 8 months ago

    Passkeys and security keys

    Not set up

    Opening 2-Step Verification and adding an authenticator app by scanning a QR code and entering the code

    We recommend Proton Authenticator

    Strong one-time codes that can't be SIM-swapped like a text message — free, open-source, and they stay on your device.

    Set it up in 5 minutes
    3

    Turn on 2-Step Verification

    With a second step in place, click Turn on 2-Step Verification. Now a stolen password isn't enough on its own — signing in also needs that second step, so even someone who already knows your password can't get in.

    If Google offers to add a phone number, you can Skip it — your authenticator (or a passkey) is stronger than SMS, which can be intercepted or SIM-swapped.

    myaccount.google.com/signinoptions/twosv
    Google AccountA

    2-Step Verification

    Turn on 2-Step Verification

    Prevent hackers from accessing your account with an additional layer of security. You'll be asked to complete the most secure second step available when you sign in.

    Second steps

    Passkeys and security keys

    !Add a passkey

    Google prompt

    Authenticator

    Added just now

    Phone number

    !Add a phone number
    Turn on 2-Step Verification

    Turning on 2-Step Verification and skipping the optional phone-number prompt

    Forced to add a phone number?

    Sometimes Google won't let you turn on 2-Step Verification without a phone number — usually when no other second step is set up yet. If it forces you, press Back to return to Security & sign-in, then open 2-Step Verification again — going in a second time usually lets you turn it on and Skip the phone option instead of being forced to add one.

    Remove SMS as a second factor

    Heads up — turning on 2-Step Verification often automatically adds your recovery phone number as an SMS second factor. Once your authenticator app is working, go back into 2-Step Verification and remove the phone / SMS option to cut your exposure to SIM-swap and other SMS-based attacks.
    4

    Save your backup codes

    Now that 2-Step is on, grab your backup codes — ten codes that get you in if you ever lose your phone or can't get a code another way. On the 2-Step Verification page, open Backup codes → Get backup codes, then Download or print them.

    Each code is single-use, and they're a fallback, not your everyday method — keep signing in with your authenticator app and only reach for a backup code when you can't. Once a code is used, it's spent; cross it off, and generate a fresh set if you ever run low.

    Keep them somewhere safe but offline — printed and put away, or saved in your password manager. Don't leave them in the inbox you're protecting or a notes app synced to it.

    myaccount.google.com/signinoptions/twosv
    Google AccountA

    2-Step Verification

    Your account is protected with 2-Step Verification

    Keep your second steps up to date and add more sign-in options.

    Second steps

    Passkeys and security keys

    !Add a passkey

    Authenticator

    Added just now

    Phone number

    !Add a phone number
    123

    Backup codes

    !Get backup codes

    2-Step Verification Backup codes to Get backup codes to download the ten one-time codes

    Strong protection — but don't lose these codes

    Together, your authenticator app and these backup codes give you a strong, fully offline second factor plus a redundant fallback if you ever lose access to the app. That's exactly the security you want — but it cuts both ways: with no phone number or SMS to fall back on, if you lose both your authenticator and your backup codes, you may never get back into the account. Store the codes somewhere safe and offline, and treat them like a spare key.
    5

    Set a strong, unique password

    Go back to Security & sign-in → Password, set a new one, and click Change password. Make it long and random and used nowhere else — reused passwords are how one leaked website becomes a dozen hacked accounts.
    Let a password manager generate and remember it so you never reuse one. Proton Pass (free, end-to-end encrypted) creates strong, unique passwords and fills them in for you across your devices.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Security & sign-in

    How you sign in to Google

    Make sure you can always access your Google Account by keeping this information up to date.

    2-Step Verification

    ● On

    Password

    Last changed 8 months ago

    Passkeys and security keys

    Not set up

    Recovery email

    ⚠ Add a recovery email

    A long password-manager-generated password rated Strong

    We recommend Proton Pass

    Generate and remember a long, unique password for every account — free, open-source, and end-to-end encrypted.

    Set up Proton Pass
    6

    Lock in your recovery options

    Open Security & sign-in → Recovery email, add an address and click Save — ideally on a different provider you control, so a Gmail lockout doesn't take your recovery option down with it. Add a recovery phone too if you can.
    Recovery info is how Google confirms it's really you if you're locked out or it spots unusual activity — so keep that recovery inbox secure as well.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Security & sign-in

    Ways we can verify it's you

    Recovery info lets Google reach you if you're locked out or we spot unusual activity.

    Recovery email

    ⚠ Add a recovery email

    Recovery phone

    ⚠ Add a mobile phone number

    Recovery email set, with no recovery phone number

    We recommend Proton Mail

    Your recovery pathway is only as secure as the email it's attached to. For maximum security, we recommend an end-to-end encrypted inbox.

    Why switch to Proton Mail
    7

    Remove risky app access

    Apps you've connected over the years can read your mail or act on your behalf — and each one is a way in. Open Security & sign-in → Your linked apps → See all linked apps. The list only shows app names, so click any app you don't recognise to see what it can access, and choose Delete all to revoke it.
    Be especially wary of anything with full Gmail access or the ability to change your filters and forwarding — that's exactly how a rogue app quietly reads or redirects your mail.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Manage all devices

    4 ›

    Your linked apps

    Keep track of your Google Account data

    Bing Webmaster Tools

    Proton

    Inbox Cleaner

    See all linked apps

    3

    Google Account Your linked apps to See all linked apps to an app's permissions to Delete all

    8

    Review your devices and recent activity

    Open your Security & sign-in page and look through Recent security activity and Your devices → Manage all devices. Sign out anything you don't recognise.
    A sign-in from a nearby city can be legitimate — location is estimated from your IP address. The clear red flags are devices or operating systems you don't own, or sign-ins at times you weren't online. And a session can stay active long after the original sign-in, so look past the last 28 days here.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Backup codes · 10 codes available

    Your devices

    Where you're signed in

    3 sessions on Windows computer(s)

    Windows, Windows, …

    1 session on Android phone

    Android

    Find a lost device

    Manage all devices

    4

    Security page Your devices to Manage all devices showing every active session

    9

    Check your filters

    On a computer, open Settings → See all settings → Filters and Blocked Addresses. A trick attackers leave behind is a hidden filter that auto-deletes, archives or marks your security alerts as read — so the warnings never reach you. Delete any filter you didn't create.
    These settings aren't in the mobile app — open Gmail in your phone's browser and request the desktop site if you're away from a computer.
    M
    Search mail
    GGoogleSecurity alert9:14 AM
    NNetflixYour receipt for AugustYesterday
    LLinkedInYou appeared in 4 searchesMon
    DDropboxYour files are ready to viewAug 2
    Quick settings
    See all settings

    Density

    ● Default

    ○ Comfortable

    ○ Compact

    Gmail inbox to Settings to Filters and Blocked Addresses, revealing a malicious filter

    10

    Check your forwarding

    Still in Settings, open the Forwarding and POP/IMAP tab. A quiet forwarding rule can send a copy of every email to an address you don't control — so someone keeps reading your mail even after you've locked everything else down. Remove any forwarding address you didn't set up, and turn forwarding off if you don't use it.
    MSettings
    GeneralInboxAccounts and ImportFilters and Blocked AddressesForwarding and POP/IMAP

    The following filters are applied to all incoming mail:

    Matches: subject:(security alert OR password)

    Do this: Skip Inbox, Mark as read, Delete it

    A hidden Gmail forwarding rule sending mail to an unknown address

    For high-risk accounts

    If you're a high-risk target — a journalist, activist, executive, or anyone likely to be attacked — enrol in Google's Advanced Protection Program. It enforces security keys and applies tighter checks across your whole account.

    Frequently asked questions

    Is SMS two-factor good enough?
    It's far better than nothing, but text codes can be intercepted or stolen through a SIM-swap. An authenticator app or a passkey / security key is stronger — use one of those as your main method and keep SMS only as a backup.
    What if I lose my phone?
    That's what backup codes are for — save them offline when you turn on 2-Step Verification. It's also worth adding a second method, like a spare device or a security key, so you're never relying on a single phone.
    Are password managers actually safe?
    Yes — a reputable password manager is far safer than reusing passwords or writing them down. It encrypts everything behind one strong master password and generates long, unique passwords you never have to remember.
    Do I really need to do all of this?
    Start with 2-Step Verification and a unique password — those two alone stop most attacks. The rest closes the smaller gaps, and you can work through them in a single sitting.

    What to do next

    Go further

    Gmail is now hardened, but Google can still read what's inside. For mail that stays private even from your provider, move to an end-to-end encrypted inbox.
    Why switch to Proton Mail

    Locking down other accounts?

    These steps apply to any inbox — here's the complete email-security guide.
    Secure any email account

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Email Security