How to Run a Google Security Checkup
Quick answer: Open Google’s official Security Checkup, sign in on a device you trust, and work through every recommendation. Pay special attention to unfamiliar devices, recent security events, recovery options, two-step verification, saved passwords, and third-party access.
A Security Checkup is not a virus scan. It is a guided review of the settings and activity that protect your Google Account. Because one Google Account may hold Gmail, Photos, Drive files, contacts, and recovery access for other services, a short review can prevent a much larger problem.
Before you begin
- Use your own updated phone or computer, not a public or shared device.
- Type
myaccount.google.comyourself or use a saved bookmark. Do not follow an unexpected “security alert” link. - Keep your phone nearby in case Google asks you to verify that it is you.
- Allow enough time to investigate anything unfamiliar instead of dismissing warnings quickly.
1. Review recent security events
Start with events such as new sign-ins, password changes, added recovery details, or access from a new device. A city or device label can sometimes be approximate, so do not panic over location alone. Compare the time, device type, browser, and activity with what you were doing.
If you genuinely do not recognize an event, use the account’s security controls to say it was not you, change the password, and follow Google’s recommended steps. Then review the rest of the account rather than assuming a password change solved everything.
2. Check every signed-in device
Look for phones, tablets, computers, TVs, and other sessions connected to the account. Old devices are not automatically dangerous, but an unknown device or a device you sold should not remain signed in.
| What you see | What to do |
|---|---|
| Your current phone or computer | Confirm the recent activity matches your use. |
| An old device you no longer use | Sign it out, especially if it left your possession. |
| An unfamiliar device or session | Sign it out and secure the account immediately. |
| Several similar sessions | Compare device, browser, time, and location before deciding. |
3. Confirm your recovery phone and email
Recovery information helps Google contact you about suspicious activity and helps prove ownership if you are locked out. Confirm that both options still belong to you, are spelled correctly, and can be accessed independently of the account you are protecting.
Avoid using an address you have forgotten or a phone number you no longer control. Never publish recovery details on a website or social profile.
4. Strengthen sign-in protection
Turn on two-step verification if it is not already active. Google prompts, passkeys, and security keys generally resist common phishing attempts better than a code that can be copied into a fake form. Keep more than one safe sign-in or recovery method so losing one phone does not lock you out.
For a detailed comparison, read Two-Step Verification Explained.
5. Review saved passwords
Use the password review offered by your password manager to find reused, weak, or exposed passwords. Replace the most important ones first: email, banking, social media, shopping, and any account that can reset other passwords. Each account should have a different password.
See How to Create Strong Passwords Without Reusing Them for a practical system.
6. Remove access you no longer need
Review apps and services linked to your Google Account. Remove anything you do not recognize or no longer use. Before keeping an app, check who operates it and what data it can access. Removing access may sign you out of that service or disable a feature, but you can reconnect a legitimate app later.
7. Update the devices that access the account
Account settings cannot protect an outdated device from every threat. Install operating-system, browser, and app updates. Keep a screen lock on phones and laptops, and remove browser extensions you no longer need.
What if the checkup shows no warnings?
That is encouraging, but it is not a lifetime guarantee. Security changes when you add devices, connect apps, reuse passwords, or respond to messages. Run the checkup periodically and after a lost device, suspicious message, unexpected sign-in alert, or major account change.
Common mistakes
- Approving a sign-in prompt you did not start.
- Removing every session without first understanding your own devices.
- Keeping only one recovery method.
- Trusting a padlock icon or “security” wording in an email.
- Ignoring linked apps after changing the password.
Frequently asked questions
Does Google Security Checkup cost money?
No. It is part of Google Account security. Be suspicious of anyone who asks for payment to “unlock” the official checkup.
Can the checkup remove malware?
No. It can identify account-related risks, but device malware requires separate device security steps.
How often should I run it?
There is no single schedule for everyone. A regular reminder every few months, plus a check after any suspicious event or device change, is a practical approach.
Comments
Post a Comment