How to Secure Your Google Account

    Lock down the Google account behind your Android phone: move it to a private email, set a strong unique password, turn on app-based 2-Step Verification, remove devices you don't recognise, and close the recovery back doors.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated July 2026 · 8 min read

    Your Android phone runs on your Google account — the master key to the whole device. Anyone signed into it from another device can read your messages, open your photos and follow your location through Google sync, with nothing installed on your phone at all. Locking that one account down is the single most important thing you can do to stop being watched.

    Affiliate disclosure: if you sign up for a paid Proton plan through a link on this page, we may earn a commission at no extra cost to you. It helps keep guides like this free.

    Give the account a private anchor first

    Everything below gets reset through one channel: the recovery email on your Google account. Reset links, verification codes, security alerts — they all land there. If that inbox is old, shared with a partner, or protected by a password you have used elsewhere, the padlocks you are about to add can be quietly opened from it. A fresh Proton Mail address — end-to-end encrypted, known to nobody else — makes a clean anchor that is yours alone.

    A recovery inbox nobody else can touch

    The free Proton Mail plan is all a recovery address needs. Mail Plus adds a custom domain, more storage and short @pm.me addresses if you later move your whole inbox across.

    Get Proton Mail
    Proton Unlimited

    Or take the whole privacy suite

    Proton Unlimited pairs the encrypted inbox with Proton VPN, Pass, Drive and Calendar — one subscription covering the email, passwords and network layers this cluster of guides walks you through.

    • End-to-end encrypted
    • Swiss-based, no ads
    • One plan, every app

    Secure your Google account, step by step

    The screens below show the web view — sign in from any browser, or reach the identical screens on your phone under Settings → Google → Manage your Google Account (wording shifts slightly between Android brands). If you can, do this on a computer: the authenticator step asks your phone to scan a QR code off the screen, which is effortless when the code is on a monitor and fiddly when it's on the same phone you're scanning with. Work through the steps in order.

    1

    Start at Security & sign-in

    Use a browser and device that are yours alone for all of this. Head to accounts.google.com, sign in, and pick Security & sign-in from the menu on the left, then scroll to How you sign in to Google. Almost everything you're about to change — password, 2-Step Verification, passkeys, recovery options — lives in this one section.
    accounts.google.com
    Google

    Welcome

    Aalex.taylor@gmail.com

    Forgot password?

    Next

    Signing in to Google, opening Security & sign-in, and scrolling to How you sign in to Google with 2-Step Verification and recovery options

    2

    Register an authenticator app

    Click into 2-Step Verification from Security & sign-in. Google won't let you switch 2-Step on until the account has a second step registered, and the strongest everyday pick is an authenticator app: it creates codes on the phone itself, with no network involved, so a SIM swap gets an attacker nothing. In the Second steps list, open Authenticator, then Add authenticator app and Set up authenticator.
    You'll want the app installed before this step. Our pick is Proton Authenticator — free, open-source, and it makes its codes offline on the device (Google Authenticator and Authy do the job too). Inside the app, hit +, choose Scan a QR code, aim it at the code Google shows, and type the 6-digit result to confirm. A passkey or hardware security key also counts as a second step if you prefer.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Security & sign-in

    How you sign in to Google

    Make sure you can always access your Google Account by keeping this information up to date.

    2-Step Verification

    ● Off

    Password

    Last changed 8 months ago

    Passkeys and security keys

    Not set up

    Opening 2-Step Verification and adding an authenticator app by scanning a QR code and entering the code

    We recommend Proton Authenticator

    Strong one-time codes that can't be SIM-swapped like a text message — free, open-source, and they stay on your device.

    Set it up in 5 minutes
    3

    Switch 2-Step Verification on

    Second step registered? Click Turn on 2-Step Verification. A password by itself now opens nothing: every new sign-in has to produce the second step too, which shuts out anyone who has merely learned your password.

    Google may suggest you add a phone numberSkip is fine. SMS is the weakest second step going, since texts can be intercepted or SIM-swapped; your authenticator or a passkey beats it.

    myaccount.google.com/signinoptions/twosv
    Google AccountA

    2-Step Verification

    Turn on 2-Step Verification

    Prevent hackers from accessing your account with an additional layer of security. You'll be asked to complete the most secure second step available when you sign in.

    Second steps

    Passkeys and security keys

    !Add a passkey

    Google prompt

    Authenticator

    Added just now

    Phone number

    !Add a phone number
    Turn on 2-Step Verification

    Turning on 2-Step Verification and skipping the optional phone-number prompt

    Forced to add a phone number?

    Sometimes Google won't let you turn on 2-Step Verification without a phone number — usually when no other second step is set up yet. If it forces you, press Back to return to Security & sign-in, then open 2-Step Verification again — going in a second time usually lets you turn it on and Skip the phone option instead of being forced to add one.

    Remove SMS as a second factor

    Heads up — turning on 2-Step Verification often automatically adds your recovery phone number as an SMS second factor. Once your authenticator app is working, go back into 2-Step Verification and remove the phone / SMS option to cut your exposure to SIM-swap and other SMS-based attacks.
    4

    Put backup codes somewhere safe

    With 2-Step live, collect your backup codes: ten one-time codes that rescue you if the phone and authenticator both vanish. From the 2-Step Verification page go to Backup codes → Get backup codes and Download or print the set.

    They're single-use and strictly a fallback, not your everyday method — the authenticator stays your daily driver. When a code gets spent, strike it out; running low means it's time to generate a fresh set.

    Store them offline: printed and tucked away, or inside your password manager — never in the very inbox they protect, or a notes app that syncs to it.

    myaccount.google.com/signinoptions/twosv
    Google AccountA

    2-Step Verification

    Your account is protected with 2-Step Verification

    Keep your second steps up to date and add more sign-in options.

    Second steps

    Passkeys and security keys

    !Add a passkey

    Authenticator

    Added just now

    Phone number

    !Add a phone number
    123

    Backup codes

    !Get backup codes

    2-Step Verification Backup codes to Get backup codes to download the ten one-time codes

    Strong protection — but don't lose these codes

    Together, your authenticator app and these backup codes give you a strong, fully offline second factor plus a redundant fallback if you ever lose access to the app. That's exactly the security you want — but it cuts both ways: with no phone number or SMS to fall back on, if you lose both your authenticator and your backup codes, you may never get back into the account. Store the codes somewhere safe and offline, and treat them like a spare key.
    5

    Give it a password used nowhere else

    Return to Security & sign-in → Password, enter a new one and confirm with Change password. Long, random and never reused is the bar — password reuse is the mechanism that turns one breached website into a chain of hacked accounts.
    A password manager takes the remembering off your plate and makes reuse impossible. Proton Pass (free, end-to-end encrypted) generates strong logins and autofills them on every device you use.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Security & sign-in

    How you sign in to Google

    Make sure you can always access your Google Account by keeping this information up to date.

    2-Step Verification

    ● On

    Password

    Last changed 8 months ago

    Passkeys and security keys

    Not set up

    Recovery email

    ⚠ Add a recovery email

    A long password-manager-generated password rated Strong

    We recommend Proton Pass

    Generate and remember a long, unique password for every account — free, open-source, and end-to-end encrypted.

    Set up Proton Pass
    6

    Point recovery somewhere you control

    Under Security & sign-in → Recovery email, enter an address and hit Save. Best practice is a different provider you control — if Google ever locks you out, the way back in shouldn't be locked inside the same account. A recovery phone is worth adding alongside it.
    Google leans on recovery info to verify you during lockouts and whenever something looks off — which makes the recovery inbox itself worth protecting to the same standard.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Security & sign-in

    Ways we can verify it's you

    Recovery info lets Google reach you if you're locked out or we spot unusual activity.

    Recovery email

    ⚠ Add a recovery email

    Recovery phone

    ⚠ Add a mobile phone number

    Recovery email set, with no recovery phone number

    We recommend Proton Mail

    Your recovery pathway is only as secure as the email it's attached to. For maximum security, we recommend an end-to-end encrypted inbox.

    Why switch to Proton Mail
    7

    Cut off risky app connections

    Every app you've ever linked can still hold real power here — reading mail, acting as you — and each one is its own doorway. Go to Security & sign-in → Your linked apps → See all linked apps. Names alone tell you little, so open anything you don't recognise, review what it can reach, and strip it with Delete all.
    Treat anything holding full Gmail access — or rights over your filters and forwarding — as top priority: those are the exact levers a rogue app pulls to read or reroute mail unnoticed.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Manage all devices

    4 ›

    Your linked apps

    Keep track of your Google Account data

    Bing Webmaster Tools

    Proton

    Inbox Cleaner

    See all linked apps

    3

    Google Account Your linked apps to See all linked apps to an app's permissions to Delete all

    8

    Go through devices and activity

    From Security & sign-in, work through Recent security activity, then open Your devices → Manage all devices — and sign out whatever you can't account for.
    Don't panic over a sign-in from a town nearby — IP-based location is fuzzy. The genuine red flags are hardware or operating systems that aren't yours, and activity at hours you weren't online. Remember a session can outlive its original sign-in by months, so look well past the recent history.
    myaccount.google.com/security
    Google Account
    Search Google Account
    A
    Home
    Wallet & subscriptions
    Personal info
    Security & sign-in
    Google password
    Linked apps
    Data & privacy
    People & sharing
    Family
    Account storage

    Backup codes · 10 codes available

    Your devices

    Where you're signed in

    3 sessions on Windows computer(s)

    Windows, Windows, …

    1 session on Android phone

    Android

    Find a lost device

    Manage all devices

    4

    Security page Your devices to Manage all devices showing every active session

    9

    Hunt for planted filters

    From a computer, go to Settings → See all settings → Filters and Blocked Addresses. A classic intruder move is leaving behind a filter that quietly archives, deletes or marks-as-read Google's own security alerts — so the warning that would expose them never reaches you. Anything you didn't create gets deleted.
    The mobile app hides these settings — if no computer is handy, load Gmail in your phone's browser and request the desktop site.
    M
    Search mail
    GGoogleSecurity alert9:14 AM
    NNetflixYour receipt for AugustYesterday
    LLinkedInYou appeared in 4 searchesMon
    DDropboxYour files are ready to viewAug 2
    Quick settings
    See all settings

    Density

    ● Default

    ○ Comfortable

    ○ Compact

    Gmail inbox to Settings to Filters and Blocked Addresses, revealing a malicious filter

    10

    Shut down stray forwarding

    Stay in Settings and switch to the Forwarding and POP/IMAP tab. One forwarding rule is enough to hand a copy of everything — password resets included — to an outside address indefinitely, surviving every other lock you've just turned. Delete any forwarding address that isn't yours, and if forwarding serves no purpose for you, disable it outright.
    MSettings
    GeneralInboxAccounts and ImportFilters and Blocked AddressesForwarding and POP/IMAP

    The following filters are applied to all incoming mail:

    Matches: subject:(security alert OR password)

    Do this: Skip Inbox, Mark as read, Delete it

    A hidden Gmail forwarding rule sending mail to an unknown address

    Finish with the built-in audit

    Google's Security Checkup (at the top of the Security section) cross-checks everything you just did — devices, recovery info, third-party access and recent security events. A clean sweep there means the account is sealed.

    Think something's already watching?

    Locking the account shuts the remote door. Monitoring can also live on the handset itself — shared location, forwarded messages, apps hiding in plain sight — and that needs its own sweep of the phone's settings.

    See if your phone is being tracked

    Where to go next

    Common questions

    Is my Google account really how someone watches my phone?
    It's the most common way. Someone who knows your password can sign in on their own device and see your messages, photos and location through Google sync, with no app installed on your phone for a scan to find.
    What's the single most important step?
    Moving your account onto a strong, private email no one else can reach. Every other protection can be undone by someone who controls the recovery inbox, because that's where reset links and verification codes are sent.
    Do I still need to change my password if I turn on 2-Step Verification?
    Yes. 2-Step Verification stops a stolen password being used on a new sign-in, but it doesn't remove sessions already signed in. Change the password to force everyone out, then keep 2-Step on to keep them out.
    Should I use text-message codes for 2-Step Verification?
    Keep a phone number as a backup, but rely on an authenticator app where you can. SMS codes can be redirected with a SIM swap, so they're the weakest link.

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Device Security