Account Security
How to Investigate an Unknown Login Alert
An unknown login alert may reflect an approximate location, a new device, a VPN, or unauthorized access. Verify the alert through the official provider, inspect device and time details, then secure the account if anything remains unexplained.
Why can login locations look unfamiliar?
Providers often estimate location from an IP address. Mobile networks, VPNs, travel, and internet routing can show a city you did not expect. Compare the device, browser, time, and success status before deciding that access was unauthorized.
- Check the device.
- Check the time.
- Check whether the login succeeded.
Which alerts are more concerning?
A new device combined with a successful login, changed recovery details, or messages you did not send deserves immediate action. Repeated failed attempts may indicate targeting without successful access.
- Unknown successful login
- Recovery settings changed
- Repeated attempts
- Unfamiliar device
How should I open the alert?
Open the provider's official app or type its website manually. Do not use an alert link if the message could be fake. Never share your password or authentication code.
Review sessions and remove unknown devices
Use the provider's security page to inspect sessions and sign out devices you do not recognize. Take a screenshot or note the details before removing them if you may need evidence.
- Record the event.
- Sign out unknown sessions.
- Remove unfamiliar devices.
Change the password and enable MFA
Use a unique password and enable multifactor authentication. Change the old password anywhere it was reused.
- Use a unique password.
- Enable MFA.
- Change reused credentials.
Check recovery and mailbox settings
Confirm recovery email, phone number, forwarding rules, delegates, connected apps, and security notifications. Restore anything that was changed without your permission.
- Review recovery settings.
- Check forwarding rules.
- Revoke unknown apps.
Continue monitoring
Watch for new alerts and suspicious messages. Exposure monitoring can provide context about an owned identifier, but it cannot determine whether a particular login succeeded and a negative result is not proof of safety.
Frequently asked questions
Can an unknown location be harmless?
Yes. IP-based locations can be approximate. Review device, time, and success status as well.
Should I delete the alert?
Save its details first. It may help the provider investigate a suspicious sign-in.
What if I recognize the device but not the location?
The location may be approximate, but review sessions and account settings if anything else is unusual.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
