Skip to content
All guides

Account security

How to Turn On Login Alerts

Login alerts tell you about new devices and sign-ins. This guide shows where to enable them and how to treat the message without clicking a trap.

By the 4safer teamUpdated August 29, 20267 minutes read

What a login alert is supposed to do

A real alert says that a sign-in, a new device, or a recovery change happened. You then open the official site — typed by you — and compare that event with your own phone and laptop. CISA tells households to be careful with unexpected messages. The FTC says to type known websites instead of using a number or link inside a surprise text. Those two habits decide whether an alert helps or becomes a phishing hook. How to turn on login alerts is the setup step. Reading the alert on the official page is the safety step.

Where to find the setting

Labels differ. Look for:

Turn them on for:

Use an address you actually read. An alert that lands in an abandoned mailbox is decoration.

  • Login alerts
  • Security alerts
  • New device notifications
  • Account activity emails
  • Sign-in notifications
  • Email
  • The account that owns the phone
  • Banks and payment apps
  • Password manager
  • Shopping accounts that store cards

How to treat the message when it arrives

Travel, a VPN, and shared family tablets create extra alerts. That is inconvenient. It is still better than silence.

  • Do not tap “Wasn’t me — secure account” inside the email if you can avoid it
  • Open a new tab and type the real domain
  • Read devices and sessions there
  • If the device is yours, you can ignore the scare
  • If it is not, change the password, sign out all sessions, and enable MFA or a passkey

Pair alerts with a stronger login

Alerts tell you after the fact. Multifactor authentication and passkeys try to stop the sign-in. The FTC recommends two-factor authentication on sensitive accounts and notes that a code by text is the least secure common option when an authenticator app or security key is available. CISA makes the same preference. Turn on the alert, then raise the login bar on the same page. One visit, two controls.

When alerts go quiet

If you stop getting notices you used to get, check forwarding, filters, and the recovery address. Attackers who enter a mailbox often hide the mail that would warn you. Also confirm that the alert setting did not reset after an app update. Official pages, not inbox rumors, are the source of truth. If money moved and you never saw an alert, call the bank on the number on the card. An alert failure does not make the charge legitimate.

Make a small monthly habit

Once a month, open email security settings and glance at devices. After any breach notice, do it the same day. Alerts work best when you already know what your own devices look like. Learning how to turn on login alerts is a ten-minute job. Leaving them off after an exposure is how a second sign-in happens in silence.

Practical checklist

  • Enable alerts on email first.
  • Point them at an inbox you read.
  • Type official sites when an alert arrives.
  • Compare the device list with what you own.
  • Change passwords and MFA if a session is foreign.
  • Check filters if alerts suddenly stop.
  • Add the same setting on banks and the phone account.
  • Keep unique passwords so one missed alert is not a full takeover.

Frequently asked questions

Are text-message alerts better than email alerts?

Email alerts are fine if the mailbox is locked down. Texts can help, but a swapped SIM can intercept them. Prefer app or email alerts plus a strong login.

What if I get too many alerts?

Keep them on for new devices. You can often reduce “every sign-in from this home laptop” noise without turning the whole feature off.

Does an alert prove my password leaked?

No. It proves a sign-in attempt or success. Use the official activity page and, separately, an identifier check for exposure.

What should I do first?

Use the official account or service website, change affected credentials, review recent activity, and enable multifactor authentication where available.

Can a clean check guarantee that I am safe?

No. A clean result only means the available sources did not show a match. Continue using unique credentials and account security alerts.

Should I enter my password into a checker?

No. Use an identifier such as an email address or username, and never share a password or authentication code with an untrusted checker.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.