iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
If you see a Google sign-in or device you don’t recognize, use a trusted device to review and sign out the session, then change your password and check your recovery and security settings. A location or timestamp can be misleading on its own, so assess the full session details—but treat activity you didn’t initiate as suspicious.
How to check which devices are signed in to your Google Account
- On a trusted phone or computer, open your Google Account.
- Go to Security & sign-in > Your devices > Manage all devices. Menu labels can vary by device and account type.
- Review each device and session, including its device type, time, location, and other available details. Compare them with devices you use and activity you recognize.
Google may show an approximate location rather than the device’s exact location. Recent use of services such as Gmail or Calendar can also make an activity time appear newer than you remember. Neither a familiar-looking location nor a surprising timestamp proves by itself that a session is yours or someone else’s; consider the complete details and any sign-in alert. See Google’s explanation of device sessions.
How to sign out a device or session you don’t recognize
- In Manage all devices, select the unfamiliar device or session.
- Choose Sign out and follow any confirmation prompts.
- If several sessions have the same device name and you cannot identify the one you trust, sign out every session with that name.
If Google sent you a sign-in alert and you did not initiate the activity, follow its secure-account response and report that it was not yours. Google says this response signs the account out on other devices. Use the alert’s instructions or Google’s guidance for unfamiliar activity.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →What to do after removing an unfamiliar session
Change your Google Account password
Set a new, unique password promptly. If you reused the old password on other websites or apps, change it there too—particularly on accounts that use your Google email address for sign-in or recovery. Signing out a session and changing a password are separate steps; inspect your device list and follow Google’s security prompts rather than assuming a password change has signed out every session. See Google’s guidance for suspicious activity.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Check security events, recovery details, and app access
- Review recent security events for changes you did not make.
- Check your recovery phone, recovery email, and alternate or contact email. Correct unfamiliar details.
- Review your 2-Step Verification settings and methods, and remove methods you do not recognize.
- Review apps with access to your account and remove access you no longer need or do not recognize.
Run Google Security Checkup for account-specific recommendations. Google also outlines steps for securing a compromised account.
How to strengthen future Google Account sign-ins
Google recommends passkeys and 2-Step Verification. Passkeys and security keys are phishing-resistant options. If you use a password and second step instead of a passkey, Google recommends Google prompts over text message codes; codes sent by text or call can be more vulnerable to attacks based on your phone number. Choose a method you can reliably use, and keep a backup recovery option available.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Method | What to consider |
|---|---|
| Passkey | A phishing-resistant sign-in option. Make sure you can access the device or method used for your passkey and have a recovery route. |
| Security key | A phishing-resistant physical option. A FIDO2-compatible hardware security key may suit people who want a physical key; check compatibility and keep a backup method. |
| Google prompt | Google recommends prompts over text codes when you choose not to use a passkey. Keep access to a trusted device that can receive the prompt. |
| Text or call code | Can provide a second step, but may be more exposed to phone-number-based attacks. Do not rely on it as your only recovery plan. |
| Backup codes or another trusted device | Keep a backup option somewhere safe and accessible so you can recover access if your usual method is unavailable. |
Google describes 2-Step Verification as “an extra layer of security to your account in case your password is stolen.” Read its current setup and method guidance at Turn on 2-Step Verification.
Recommended Free Tools
If you can’t sign in or your recovery details were changed
If you are locked out, or someone changed your recovery details, use Google’s compromised-account recovery guidance. If 2-Step Verification is preventing access, follow Google’s account recovery steps for 2-Step Verification. Recovery is not guaranteed. For a work, school, or other organization-managed account, contact the administrator if organizational policy blocks the consumer steps in this guide.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5C Nano is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C Nano secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: The YubiKey 5C Nano is designed to stay plugged into your device via USB-C. Simply tap it to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

