Account security
How to Lock Down a Google Account
A Google account often holds mail, photos, and the phone. This guide walks the official security tools without asking you to paste a password into a stranger’s form.
Start on the real Google domain
Type the address. Do not use a “Google security alert — tap to lock” button inside unexpected mail. CISA’s family guidance is to think before you click. The FTC says to look up the company yourself. Once you are in:
Google’s help pages also describe at-risk sign-in methods that the company may restrict if they look suspicious. Review those flags on the official security page, not in a chat window.
- Security & sign-in
- Recent security activity
- Your devices
- 2-Step Verification
- Recovery phone and email
Turn on a second step that is hard to steal
Google’s consumer help says you can turn on 2-Step Verification under Security & sign-in, and that a passkey can replace the extra step because it proves you have the device. If you still use a password, Google recommends prompts on a signed-in phone rather than codes that travel by SMS. Prompts are harder to steal with a swapped SIM. CISA still prefers phishing-resistant options — passkeys and security keys — when they are available. Use SMS only if nothing else works. Add a backup method you control: a second passkey, a hardware key, or saved backup codes in a password manager. Do not keep the only copy in the same inbox.
Clean devices, apps, and mail rules
How to lock down a Google account is incomplete if a forgotten tablet stays signed in. On official pages:
Google Workspace administrators have a longer checklist for compromised users, including forwarding and filters. The same items matter on a personal Gmail account.
- Sign out devices you do not recognize
- Remove third-party apps with account access
- Check Gmail forwarding and filters
- Confirm the recovery phone is yours
- Review saved passwords in the Google Password Manager if you use it, and retire reused ones
If you think someone already got in
Follow the FTC path for a hacked email account: change the password, sign out all devices, turn on 2-Step Verification, and fix recovery information. Then look at sent mail and filters. If you cannot sign in, use Google’s official account recovery on a typed URL. A person who emailed you first is not Google support. After you are back in, change reused passwords on banks and other sites that use that Gmail address for resets. That is the blast radius.
What this lockdown does not finish
A hardened Google account does not freeze your credit. It does not delete old exposure files. It does not fix an Apple ID or a bank login that still shares the old password. If identity data may also have been exposed, use AnnualCreditReport.com and IdentityTheft.gov. If you gave a scammer the password, the FTC’s “what to do if you were scammed” page still applies: unique new password plus two-factor authentication on the real site. Learning how to lock down a Google account is a single afternoon. Leaving 2-Step Verification off after an exposure is how the next stuffing attempt succeeds.
Practical checklist
- Type myaccount.google.com.
- Run Security Check-Up.
- Add a passkey or 2-Step Verification with prompts or a key.
- Remove unknown devices and apps.
- Fix Gmail forwarding and recovery options.
- Replace reused passwords.
- Store backup codes offline or in a manager.
- Recover only through official Google pages if you are locked out.
Frequently asked questions
Is the Advanced Protection Programme required?
No. Google describes it as extra protection for people at higher risk of targeted attacks. Most people should start with Check-Up, a passkey or 2-Step Verification, and clean devices.
Should I turn off SMS codes?
If you have a passkey, a security key, or prompts on a phone you control, those are stronger. Leave a backup you still control so you are not locked out.
What should I do first?
Use the official account or service website, change affected credentials, review recent activity, and enable multifactor authentication where available.
Can a clean check guarantee that I am safe?
No. A clean result only means the available sources did not show a match. Continue using unique credentials and account security alerts.
Should I enter my password into a checker?
No. Use an identifier such as an email address or username, and never share a password or authentication code with an untrusted checker.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
