An email account deserves a deliberate security review because it often supports many other parts of your digital life. This guide proposes a practical checklist for reviewing access, recovery, connected services, and your response to unexpected requests. It is a maintenance routine, not an audit certificate. Completing it cannot guarantee that an account is secure, and InboxGrade.com does not inspect your settings or verify your identity.
Work through the checklist using your email provider's legitimate account pages, opened through a route you already trust. For a work or school account, follow your organization's requirements and ask the administrator before making changes outside your authority. The aim is to understand the protections and recovery paths you actually have, rather than collecting a series of green checkmarks whose meaning is unclear.
Start from the provider's real security settings
Open your usual app or a known bookmark, then navigate to the account's security area. Do not begin from an unexpected email that tells you to “complete a security check.” The checklist itself should not become a reason to trust a new link. Make sure you are reviewing the intended account, especially when your browser holds several personal and work sessions at once.
Google's guidance on making an account more secure covers a Security Checkup, software updates, unique passwords, and reviewing unnecessary apps or extensions. That is a primary reference for the kinds of controls discussed here. Our ordering, note-taking suggestions, and examples are an original review routine, not a replacement for provider-specific instructions. Use the current instructions from your own provider for each setting and any recovery action.
Review the sign-in method you actually use
Identify how you sign in and which protections are enabled. Where the provider supports passkeys or multi-factor authentication, review its explanation of the available methods and recovery implications. Avoid approving unexpected sign-in prompts merely to make them disappear. If a password remains part of the account's authentication, use a unique password rather than reusing one from another important service. Follow your organization's approved password-management approach for managed accounts.
Record the existence of the protection, not the secret itself, in your checklist. A useful note might say “Second-factor method reviewed” or “Recovery procedure saved in approved location.” Do not create a convenient public document containing passwords, authentication seeds, or backup codes. The maintenance process should improve your understanding without assembling a new collection of sensitive information. If you are unsure what a setting changes, read the provider's explanation before altering it.
Check that recovery options are usable
Review the recovery addresses, phone numbers, and other recovery methods associated with the account. Ask whether you still control them and whether the instructions make sense if your usual device is unavailable. An old address or a forgotten phone number can make a future problem more difficult. Follow the provider's process for updating recovery information; do not assume every service applies changes immediately or in the same way.
Think through a fictional lost-phone scenario without actually locking yourself out. How would you reach the recovery instructions? Where would an approved backup method be available? Who would you contact for a managed account? The purpose is to discover unclear steps while you still have normal access. Do not intentionally remove your only working sign-in method to test resilience. A safe rehearsal is a review of the documented route, not an experiment that risks losing access.
Review devices and recent account activity
Where your provider exposes device or session information, inspect it for entries you recognize. Read its explanation of dates, locations, and device names before drawing conclusions. A label can be unfamiliar without proving compromise, and a familiar label does not explain every action associated with a session. If something looks wrong, use the provider's official account-security guidance or contact your administrator rather than improvising based on a single screenshot.
Make the review specific. Ask whether you still use an old phone, whether a shared computer should retain access, and whether a recently replaced device needs attention. Record the changes you make and why. For devices you do not control or work equipment, follow the organization's process. Do not sign out an entire team or remove shared access simply because you are conducting a personal cleanup. The scope of your authority matters as much as the technical option on the screen.
Inspect connected applications and mailbox settings
Review third-party services that have access to the account, using the provider's own permission-management interface. Ask whether you still use each service and whether its requested access fits its purpose. Reading mail, sending mail, and modifying messages are distinct capabilities. If you remove access, consider which legitimate workflow will stop working and whether an administrator or colleague needs to know. Keep the change understandable rather than treating every integration as automatically good or bad.
Also review forwarding and organizational rules when your provider offers them. Confirm that you recognize the destinations and intended behavior. An unexplained forwarding destination deserves investigation through the appropriate support process. At the same time, do not assume that every unfamiliar setting is malicious; an administrator or prior authorized workflow may explain it. Record the observation, avoid exposing private destinations publicly, and get help when the purpose or origin cannot be established.
Keep the devices used for email maintained
Review the update status of the operating system, browser, and email app you use. Follow the vendors' update instructions rather than downloading a supposed update from an unsolicited email. Consider the basic physical-access question as well: can someone use a shared or unattended device to access your account? Use the device protections appropriate to your situation and organizational requirements. A secure account workflow needs to account for the places where you actually read mail.
This is also a good time to review extensions or applications that interact with the browser or mailbox. Keep tools you understand and need, and use the relevant approved process for anything uncertain. The checklist does not require installing another security product. Its purpose is to bring existing controls and dependencies into view. Adding software simply to feel more protected can make the setup more complicated without answering the questions that prompted the review.
Prepare for suspicious requests before they arrive
Choose a verification rule for unexpected, consequential email requests. For example, confirm account changes or unusual payment instructions through a known independent channel. Decide where you will report suspected phishing and how to contact support without relying on details inside the suspicious message. Keep those routes easy to find. Our phishing recognition guide develops this decision process in more detail.
If you think an account is already being misused, treat that as a different task from routine maintenance. Stop following the questionable message, use the provider's legitimate recovery or security route, and involve your organization's support team promptly for a managed account. Describe what happened accurately, including whether you entered credentials, approved a prompt, or ran a file. Do not assume deleting an email or completing a general checklist resolves an active incident.
Finish with a short, useful record
Write down the date of the review, which areas you checked, what you changed, and any unresolved questions. Keep the record free of passwords, recovery codes, and confidential message contents. A small record helps the next review start from facts rather than memory. It also lets you distinguish a new issue from a setting you intentionally changed. Decide when another review would be useful, such as after replacing a device or changing an important service.
The value of this checklist is not a perfect grade. It is a clearer understanding of how you sign in, recover access, recognize unexpected changes, and obtain help. Keep those responsibilities separate from inbox organization: a tidy mailbox and a protected account are different goals. Visit Email Security for the wider learning path, and return to your provider's official instructions whenever a setting or recovery step needs precise, current guidance.



