Email Security
How to Review Connected Apps in Your Email Account
Connected apps can read, send, or manage email depending on the permissions you granted. This guide explains how to review those permissions, remove unnecessary access, and secure your account.
Connected apps can be a hidden access path
To review connected apps in your email account, open your provider's official security settings and look for third-party access, connected apps, app passwords, delegated access, account permissions, or security checkup. Remove apps you no longer use or do not recognize.
A connected app is not automatically bad. Calendar tools, mail clients, CRM systems, scanners, and productivity apps may need access. The risk comes from old apps, overbroad permissions, compromised apps, or permissions you forgot you granted.
If your email appeared in exposure data or you received a suspicious login alert, connected apps deserve review because they may continue to access data even after a password change.
What email app permissions may allow
Permissions vary by provider and app. Some apps can only read basic profile information. Others may read email, send email, manage labels, access contacts, or maintain offline access. A permission that was reasonable years ago may no longer be necessary.
Google's account security guidance encourages users to review third-party access. Microsoft also provides account recovery and security guidance for removing suspicious access when an account is compromised.
For work accounts, connected apps may be controlled by company policy. Report anything suspicious to IT before making changes that could affect business systems.
- Read profile information.
- Read email contents.
- Send email as you.
- Manage labels, folders, or rules.
- Access contacts.
- Keep access when you are offline.
- Use app passwords or older mail protocols.
Review through official settings only
Do not follow links in random security emails to review connected apps. Open the account from the official provider site or app. Look for security checkup, privacy dashboard, third-party access, connected apps, or sign-in methods.
Click each app and read what access it has. Ask three questions: Do I recognize this app? Do I still use it? Does it need this level of access?
If the answer is no, remove access. You can usually reconnect a legitimate app later if needed.
Remove access you do not need
Start by removing apps you do not recognize, apps from companies you no longer use, old email clients, abandoned productivity tools, and anything with broad access to mail. Removing access does not usually delete your account with that third-party service; it only revokes the connection.
After removing access, watch for account alerts and test important workflows. If a legitimate app stops working, reconnect it from the app's official settings.
- Remove unknown apps.
- Remove unused apps.
- Remove old mail clients.
- Remove apps with broad mail access.
- Reauthorize only what you still need.
Check app passwords and older protocols
Some accounts support app passwords for older devices or mail clients. These can keep working even when you change your main password. If you do not recognize an app password, revoke it.
Also review POP, IMAP, and forwarding settings if your provider exposes them. These features are useful for legitimate mail clients, but unnecessary access can increase risk.
Secure the core account
Connected app cleanup should happen alongside basic account hardening. Change reused passwords, enable MFA, review recovery methods, and sign out of unfamiliar sessions.
NIST recommends password managers for unique passwords. CISA recommends MFA for stronger account protection.
Investigate sensitive access
If an unknown app had permission to read or send email, review sent messages, deleted messages, rules, forwarding, and security alerts. Look for password reset emails or financial messages that may have been accessed.
If work, banking, tax, or identity documents may be involved, use official support and reporting channels. Keep notes about what access existed and when you removed it.
Build a regular review habit
Review connected apps every few months and after any suspicious login, device loss, or exposure result. The review is quick once you know where the settings live.
Use the least access practical. If an app only needs calendar access, it should not have full email access. If you stop using an app, remove it from the account.
Frequently asked questions
Can connected apps access my email after I change my password?
Sometimes yes, depending on how access was granted. Review and revoke connected apps separately from changing your password.
Is every connected app dangerous?
No. Many are legitimate. The risk is unknown, unused, or overly broad access.
Should I remove apps I do not recognize?
Yes. If you do not recognize an app or no longer need it, revoke access. You can reconnect legitimate apps later.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
