Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The strongest practical way to protect a Google Account is to make a stolen password insufficient for sign-in, keep recovery details current, and regularly review which devices and apps can access the account. Start with Google’s Security Checkup, then strengthen sign-in and prepare a recovery route you can actually use.
Start with Google Account Security Checkup
Sign in to your Google Account and open Security Checkup. Review the recommendations shown for your account, including recovery options, recent security activity, passkeys or 2-Step Verification, and apps with account access. Recommendations can differ by account and device.
A green shield means the page has no immediate recommendations; it is still worth reviewing the settings and access listed there. Remove access you no longer need, and investigate unfamiliar activity rather than assuming it is harmless.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesMake a password theft less damaging
Use a unique password
Choose a strong password that you do not use on any other site. Reusing passwords means a breach elsewhere can expose the Google Account if attackers try the same credentials. A password manager can help create and keep track of unique passwords. Google’s Password Checkup can flag weak, exposed, or reused passwords saved in your account.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Add phishing-resistant sign-in
A passkey lets you sign in using a fingerprint, face scan, or the screen lock on a compatible device. Google says passkeys are designed to resist phishing. For accounts using 2-Step Verification or Advanced Protection, a passkey can also satisfy the second-step requirement. Choose this option if it works across the devices you use and you have a recovery plan for losing access to them.
If you continue to sign in with a password, turn on 2-Step Verification. A second step means a stolen password alone is not enough to sign in.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Sign-in method | What it offers | What to consider |
|---|---|---|
| Passkey | Uses a device screen lock, fingerprint, or face scan; designed to resist phishing. | Make sure you can use it on your devices and have a way to recover access if a device is lost. |
| Security key | Google describes security keys as its most secure 2-Step Verification option; they can provide phishing-resistant sign-in. | Check that the key works with your devices. If relying on keys, keep a backup key in a safe place. |
| Google Prompt | A Google sign-in prompt is a recommended second step for people not using a passkey. | You need access to a device that can receive the prompt. |
| Authenticator code | Provides codes that can be used offline. | Plan for what you will do if you lose or replace the device holding the authenticator. |
| Text or phone call code | Adds a second step using a phone number. | More exposed to phone-number-based attacks than stronger options such as a security key or Google Prompt. |
| Backup codes | Can help you sign in if you lose your phone. | Keep them private and secure; Google says they are unavailable to Advanced Protection users. |
Google recommends Google Prompts if you are not using a passkey, and identifies security keys as its strongest second-step option. Texts and calls are better than password-only sign-in, but phone-number-based attacks make them a less robust choice. Never share a verification code or backup code with someone who contacts you.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Keep recovery and account access under control
Check recovery details
Keep a recovery phone number and email address current, and confirm that you can access them. Google says these details can help block unauthorized use, alert you to suspicious activity, and restore access when you cannot sign in.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Changes to authentication or recovery factors may take up to seven days to take effect, according to Google’s help guidance; that timing is not a universal waiting period for every account change. In some cases, Google says the process may be accelerated when the account already has a trusted passkey or security key.
Review apps and devices
In Security Checkup, inspect recent security activity and third-party apps with account access. Remove unfamiliar or unnecessary access. Also remove browser extensions and apps you no longer use, especially from devices used for sensitive information.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Consider Advanced Protection if you face targeted attacks
Google recommends its Advanced Protection Program for people at elevated risk of targeted online attacks, such as journalists, activists, political campaign staff, business leaders, and IT administrators. It is not necessary for every account, but it adds protections beyond ordinary sign-in settings.
Free tools Windows power users keep installed
One-click scans. No signup required.
- Signing in on new devices requires a passkey or security key.
- Some third-party app access is restricted, and Google applies stronger checks to suspicious downloads.
- The program is free, though you may need to buy hardware security keys.
- Account recovery is more involved, and some apps or services may not work with the account.
Before enrolling, consider whether you can reliably use a passkey or security key and accept the tighter app-access rules. If you choose physical keys, Google recommends having a primary key and at least one backup.
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
What to do if someone may have accessed your account
Treat unexpected activity, unfamiliar sign-in methods, or changed account settings as a possible security incident. Use Google’s compromised-account guidance. If you are locked out, begin Google Account recovery and answer the prompts as accurately as you can.
- Recover access: If you cannot sign in, use Google’s account recovery process. Do not give your password or verification codes to anyone offering to recover the account for you; Google says it does not work with account- or password-recovery services.
- Review what changed: Once you regain access, inspect recent security activity, account settings, sign-in methods, recovery details, and third-party app access. Remove unfamiliar access.
- Secure sign-in: Change a compromised password to a strong password not used elsewhere. Turn on 2-Step Verification or set up a passkey, and check that your recovery options are still yours.
- Check devices and other exposure: If suspicious activity could involve malware, review the devices and extensions used to access the account. If the account contained saved financial or identity information, consider what additional accounts or records may need attention.
Make protection a routine
After the initial review, revisit Security Checkup when you change devices, phone numbers, recovery addresses, or sign-in methods, and when Google flags activity you do not recognize. Keep backup sign-in options private and accessible to you, not merely stored on the device most likely to be lost.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

