How to Run a Google Security Checkup

Google Account security review represented by a laptop, phone, checklist cards and shield

Quick answer: Open Google’s official Security Checkup, sign in on a device you trust, and work through every recommendation. Pay special attention to unfamiliar devices, recent security events, recovery options, two-step verification, saved passwords, and third-party access.

A Security Checkup is not a virus scan. It is a guided review of the settings and activity that protect your Google Account. Because one Google Account may hold Gmail, Photos, Drive files, contacts, and recovery access for other services, a short review can prevent a much larger problem.

Before you begin

  • Use your own updated phone or computer, not a public or shared device.
  • Type myaccount.google.com yourself or use a saved bookmark. Do not follow an unexpected “security alert” link.
  • Keep your phone nearby in case Google asks you to verify that it is you.
  • Allow enough time to investigate anything unfamiliar instead of dismissing warnings quickly.

1. Review recent security events

Start with events such as new sign-ins, password changes, added recovery details, or access from a new device. A city or device label can sometimes be approximate, so do not panic over location alone. Compare the time, device type, browser, and activity with what you were doing.

If you genuinely do not recognize an event, use the account’s security controls to say it was not you, change the password, and follow Google’s recommended steps. Then review the rest of the account rather than assuming a password change solved everything.

2. Check every signed-in device

Look for phones, tablets, computers, TVs, and other sessions connected to the account. Old devices are not automatically dangerous, but an unknown device or a device you sold should not remain signed in.

What you seeWhat to do
Your current phone or computerConfirm the recent activity matches your use.
An old device you no longer useSign it out, especially if it left your possession.
An unfamiliar device or sessionSign it out and secure the account immediately.
Several similar sessionsCompare device, browser, time, and location before deciding.

3. Confirm your recovery phone and email

Recovery information helps Google contact you about suspicious activity and helps prove ownership if you are locked out. Confirm that both options still belong to you, are spelled correctly, and can be accessed independently of the account you are protecting.

Avoid using an address you have forgotten or a phone number you no longer control. Never publish recovery details on a website or social profile.

4. Strengthen sign-in protection

Turn on two-step verification if it is not already active. Google prompts, passkeys, and security keys generally resist common phishing attempts better than a code that can be copied into a fake form. Keep more than one safe sign-in or recovery method so losing one phone does not lock you out.

For a detailed comparison, read Two-Step Verification Explained.

5. Review saved passwords

Use the password review offered by your password manager to find reused, weak, or exposed passwords. Replace the most important ones first: email, banking, social media, shopping, and any account that can reset other passwords. Each account should have a different password.

See How to Create Strong Passwords Without Reusing Them for a practical system.

6. Remove access you no longer need

Review apps and services linked to your Google Account. Remove anything you do not recognize or no longer use. Before keeping an app, check who operates it and what data it can access. Removing access may sign you out of that service or disable a feature, but you can reconnect a legitimate app later.

7. Update the devices that access the account

Account settings cannot protect an outdated device from every threat. Install operating-system, browser, and app updates. Keep a screen lock on phones and laptops, and remove browser extensions you no longer need.

What if the checkup shows no warnings?

That is encouraging, but it is not a lifetime guarantee. Security changes when you add devices, connect apps, reuse passwords, or respond to messages. Run the checkup periodically and after a lost device, suspicious message, unexpected sign-in alert, or major account change.

Common mistakes

  • Approving a sign-in prompt you did not start.
  • Removing every session without first understanding your own devices.
  • Keeping only one recovery method.
  • Trusting a padlock icon or “security” wording in an email.
  • Ignoring linked apps after changing the password.

Frequently asked questions

Does Google Security Checkup cost money?

No. It is part of Google Account security. Be suspicious of anyone who asks for payment to “unlock” the official checkup.

Can the checkup remove malware?

No. It can identify account-related risks, but device malware requires separate device security steps.

How often should I run it?

There is no single schedule for everyone. A regular reminder every few months, plus a check after any suspicious event or device change, is a practical approach.

Official sources

Comments

Popular posts from this blog

How to Create Strong Passwords Without Reusing Them

12 Online Safety Habits Every Beginner Should Use

What to Do If Your Online Account Is Hacked: 12 Immediate Steps