Account security
How to Review Account Login Activity
Login history is how you tell exposure apart from an actual sign-in. This guide shows where to look, how to read the labels, and how to sign out strangers.
Where the real activity list lives
Every major account family keeps a version of this page. The label changes. The job does not. Typical names:
Start with email. Then open the Apple, Google, or Microsoft account that owns the phone. Then banks, shopping, and social accounts that mailbox can reset. You are not looking for a criminal’s legal name. You are looking for a session that does not belong.
- Your devices
- Recent security activity
- Active sessions
- Sign-in history
- Apps with access
- Connected devices
How to read the list without panicking
Services guess location from network data. A VPN, a mobile tower, a travel day, or a shared family iPad can make the label look wrong. Give more weight to:
Give less weight to:
The FTC notes that a stolen login can be used to sign in, shop, impersonate you, or reach other personal information. The activity page is how you check whether that already happened.
- A brand-new device model you do not own
- A sign-in at an hour that is unlike you, stacked with a reset email
- A recovery address or phone you did not add
- Mail forwarding or filters you did not create
- A session that remains active after you changed the password
- A neighboring city
- “Unknown location” on a day you used public Wi-Fi
- An old tablet you forgot was still signed in
What “review” should include besides dates
How to review account login activity is more than scrolling a timeline. On the same official page, check:
Sign out everything you do not recognize. Keep the current device only after you have changed the password or confirmed a passkey.
- Saved sign-in methods, including passkeys and security keys
- App passwords and third-party access
- Backup codes still sitting in an old screenshot
- Mail forwarding and filters, if the account is email
- Payment methods and shipping addresses, if the account is a store
If a session is not yours
Stay on the official site.
Write down the timestamps and device names you saw. Support teams ask for that later.
- Change the password from a device you trust, or use a passkey you control.
- Turn MFA back on. Prefer an authenticator app, passkey, or hardware key over SMS when you have a choice. CISA recommends that second step on email, social, shopping, and financial accounts.
- Sign out all sessions, then sign back in only where you intend to.
- Remove unknown devices and recovery methods.
- Check sent mail and forwarding if the account is email.
- Call the bank using the number on the card if money movement is possible.
- Report identity theft at IdentityTheft.gov if new credit, tax, or government activity appears.
Make the review a habit, not a one-time scare
A leak check answers “Has this identifier shown up before?” A login review answers “Is anyone inside right now?” You want both, on a calendar. A simple cadence:
Turn on official login alerts so the mailbox tells you about new devices. Then read those alerts on the site, not by tapping the first button in the message.
- After any breach notice that names a password or email
- After a reset message you did not request
- When you get a new phone
- Twice a year even if nothing looks wrong
What a clean activity page does not prove
An empty or familiar list is good news for today. It is not a lifetime guarantee.
Keep unique passwords and MFA even when the list looks boring. That is the setup that makes the next review shorter. Learning how to review account login activity is how you turn a vague fear into a yes-or-no question the official page can answer.
- Not every service keeps a long history.
- An attacker who already left may not still appear.
- A forwarded mailbox can hide the alerts that would have warned you.
Practical checklist
- Type the official domain. Do not use an email link.
- Start with email, then the account that owns the phone.
- Compare devices and recovery methods with what you actually own.
- Sign out unknown sessions.
- Change the password and enable MFA or a passkey if anything is off.
- Inspect forwarding and third-party apps.
- Call banks on known numbers if money is in play.
- Repeat after notices, new phones, and twice a year.
Frequently asked questions
Why does the site say I logged in from another state?
Network labels are estimates. Compare them with travel, VPN use, and whether a new device also appeared.
Should I sign out every device every week?
Not if the list matches your life. Sign out the strangers. Keep the laptop and phone you use daily.
What if there is no activity page?
Use whatever the service offers: signed-in devices, app access, or a password change that invalidates old sessions. Then enable alerts for next time.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
