Google account security checkup: a step-by-step walkthrough
Password & accounts. Updated 2026-09-13. About 4 minutes to read.
Create a passkey, confirm your recovery phone and email are current and yours, and remove any linked app you no longer use.
Google builds two free reviews into every account. Security Checkup, at myaccount.google.com/security-checkup, looks at your devices, sign-in methods and recent security events. Privacy Checkup, at myaccount.google.com/privacycheckup, covers what Google saves and what others can see.
Together they take about 15 minutes. This guide walks through each one, then covers the settings worth changing that the checkups only hint at: passkeys, recovery options, apps linked to your account, and automatic deletion of Web and App Activity.
Run Security Checkup
Go to myaccount.google.com/security-checkup and sign in.
Review each area Google flags. The checkup is organised around securing your data and devices, adding extra protections, and checking recent security events.
Under your devices, sign out of any phone, computer or tablet you do not recognise or no longer own.
Review recent security events. If something was not you, select that it was not you and follow the prompts to secure the account.
Confirm your sign-in and recovery methods, and add 2-Step Verification if it is off.
Review apps with access to your account and remove any you do not use.
Open Password Checkup if it is offered and change any saved password Google reports as compromised, reused or weak.
Google's settings tab formerly called Security is now labelled Security & sign-in. If an older guide sends you to Security, that is where to look.
Recovery options that will actually get you back in
Open your Google Account, select Security & sign-in, and find your recovery phone and recovery email.
Make sure the recovery phone is a number you will keep, not a work phone or a partner's number.
Set a recovery email that is a different account only you control, protected by its own two-step verification.
Generate backup codes and store them offline, in case you lose your phone.
Put a yearly reminder in your calendar to check these details again.
Switch to a passkey
A passkey lets you sign in with your phone's fingerprint, face or screen lock instead of a password. It is tied to Google's real website, so a fake login page cannot capture it.
Go to myaccount.google.com/signinoptions/passkeys.
Select Create a passkey and unlock your device when asked.
To use a hardware security key instead, choose Use another device, insert the FIDO2 key and enter its PIN.
Leave Skip password when possible turned on under How you sign in to Google, so the passkey is offered first.
To remove an old passkey, open Security & sign-in, select Passkeys and security keys, choose it, and remove it.
Review apps linked to your account
Google now calls these linked apps. There are two kinds: apps you sign in to with Sign in with Google, and apps you have given access to parts of your Google data, such as Gmail, Drive or Calendar. The second kind deserves the closer look, because an app with Gmail access can read your email.
Remove access for anything you no longer use or do not recognise. Deleting a Sign in with Google link stops automatic sign-in to that app, but Google notes it does not delete your data in the app itself. If an app you still use asks for broad access, such as reading all your email, consider whether the feature is worth it.
Run Privacy Checkup and set auto-delete
Go to myaccount.google.com/privacycheckup and review what is public on your profile and which activity settings are on.
In your Google Account, select Data & privacy, then under History settings choose Web & App Activity.
Select Auto-delete and choose how long to keep activity: 3, 18 or 36 months.
Select Next, then Confirm to save.
Repeat for YouTube History, and review location settings in Google Maps.
Since June 2020, Web & App Activity auto-delete defaults to 18 months for new accounts, and YouTube History to 36 months. Google also says location and IP address details are deleted from Web & App Activity after 30 days.
What the checkups do not cover
Passwords you reused on other sites. Change those on the sites themselves.
Your phone carrier account. Add a port-out PIN so nobody can move your number and receive Google's text codes.
Gmail forwarding and filters. Check Settings, See all settings, Forwarding and POP/IMAP, and Filters and Blocked Addresses yourself.
Chrome profiles still signed in on old or shared computers.
If you are a journalist, activist, executive or other likely target, Google's Advanced Protection Program adds stronger restrictions on sign-in and app access.
Frequently asked questions
How often should I run Google Security Checkup?
Every few months, and immediately after a suspicious sign-in alert, a lost phone or a data breach involving a password you used with Google.
Is a passkey safer than 2-Step Verification codes?
Yes, for phishing. A passkey only works on Google's real site, so a fake page cannot capture it. Codes sent by text or typed from an app can be phished.
Will auto-delete remove my Gmail or Google Photos?
No. Auto-delete applies to activity history such as Web & App Activity and YouTube History. Your emails, photos and files are not affected.
What does Skip password when possible do?
Once you have a passkey, it lets Google sign you in with the passkey instead of asking for your password. Turn it off if you prefer to be asked for the password.
Does Google still offer the dark web report?
No. Google ended its dark web report in February 2026. Use breach alerts from Have I Been Pwned or your password manager instead.
Security Checkup shows a device I do not recognise. What should I do?
Sign that device out from Your devices, change your Google password straight away, and check your recovery phone, recovery email and Gmail forwarding settings. Then review recent security events for other sign-ins you did not make. If you cannot tell whether a device is an old phone of yours, sign it out anyway, because you can always sign back in.