Best Practices5 min readJuly 19, 2026

How to Secure Your Google Account: A Complete Checklist

Your Google account is often the recovery point for everything else you own online. Here's the full checklist for locking it down, from 2-Step Verification to passkeys to catching stale third-party app access.

Why Your Google Account Is Worth Locking Down First

For most people, a Google account isn't just Gmail — it's the recovery email for other accounts, the login for Google Photos full of personal images, saved payment methods in Google Pay, location history, and often the account tied to an Android phone itself. Because so many other accounts use your Gmail address as the recovery contact, a compromised Google account can cascade into a compromised everything-else account through simple password reset requests. That makes it one of the highest-value single accounts to secure properly, ahead of almost any individual app or subscription.

Turn On 2-Step Verification First

Google's two-factor authentication, called 2-Step Verification, is the single biggest lever you have. Go to your Google Account security settings, enable 2-Step Verification, and choose either a passkey, a security key, or Google's own Authenticator-style prompt over SMS codes where possible — SMS can be intercepted through SIM-swapping, while a prompt sent to a trusted device or a hardware key cannot. Our 2FA guide covers the setup differences between these methods in more detail if you're deciding which to use.

Passkeys: Google's Newer, Stronger Option

Google has increasingly pushed passkeys as a replacement for passwords entirely — a passkey lives on your device (or a hardware key) and can't be phished the way a typed password can, because there's no password to trick you into typing on a fake site. Setting one up takes a couple of minutes in your Google Account's security settings and works alongside your existing password as a stronger sign-in option. See our passkeys explained guide for how they compare to a traditional password plus 2FA setup.

Run a Security Checkup

Google's built-in Security Checkup tool (in your Account settings) reviews recent sign-in activity, connected third-party apps and their permissions, recovery information, and any recent security events, all in one place. Run it every few months — it's the fastest way to catch a forgotten third-party app with excessive permissions or a sign-in from a device or location you don't recognize. Revoke access for anything you no longer use or don't recognize; a stale integration you signed up for years ago is a common way accounts get quietly compromised.

Common Google Account Weak Points

Weak PointFix
SMS-only 2FASwitch to a passkey, security key, or app prompt
Old recovery phone/emailUpdate to numbers/addresses you still control
Third-party app over-permissionsReview and revoke in Security Checkup
Reused Gmail passwordGenerate a unique password with a manager

Our password reuse risks guide covers exactly why a reused Gmail password is disproportionately dangerous, given how many other accounts point back to it for recovery.

Google Password Manager vs. a Dedicated Manager

Google's built-in password manager, integrated into Chrome and Android, is convenient and better than reusing passwords, but it ties your vault to your Google account specifically and has historically offered fewer security auditing and cross-platform features than a dedicated password manager. If your Google account itself is ever compromised, everything stored in Google's password manager is exposed in the same event — a dedicated manager with its own separate master password adds a layer of separation. Our Google Password Manager review compares it directly against standalone options like NordPass and Bitwarden.

If Your Google Account Is Ever Compromised

Act immediately: use Google's account recovery flow from a device you trust, change your password, revoke all active sessions and connected apps, and check the Security Checkup for anything unfamiliar. Because Gmail is often the recovery address for other accounts, also check your bank, social media, and any account that lists your Gmail as its recovery contact for suspicious activity or unauthorized password resets in the same window. Our identity theft recovery guide covers the broader cleanup if personal information beyond the account itself was exposed.

Shared and Family Devices: A Common Blind Spot

Signing into your personal Google account on a shared family computer, a kid's tablet, or a public library machine is one of the most common ways sessions get left logged in for someone else to stumble into later. Use a separate Chrome profile for shared devices rather than your primary signed-in profile, and get in the habit of signing out fully — not just closing the browser tab — on any device you don't control. If you're setting up a Google account for a child, Google's Family Link lets you supervise the account with appropriate restrictions rather than sharing your own login, which keeps your personal account's security checkup and recovery information untouched by someone else's usage.

Frequently Asked Questions

Does 2-Step Verification slow down everyday sign-in? Only slightly, and mostly on new devices — once a device is marked trusted, you won't be prompted every time, while still getting full protection against someone else logging in from an unrecognized device.

Is Google's Security Checkup something I need to run manually? Yes — it's not automatic. Set a recurring reminder every few months, especially after any password change or major account activity.

Should I use my Google account to log into other sites ("Sign in with Google")? It's convenient and removes one more password to manage, but it also means a compromised Google account can cascade into every site using that sign-in. Reserve it for lower-stakes sites and use a dedicated, unique login for banking and financial accounts.

What's different about a Google Workspace (business) account? Workspace accounts are managed by an organization's administrator, who can enforce 2-Step Verification, set session timeouts, and control third-party app access at the domain level. If you use Google through work or school, check with your IT admin before changing security settings yourself, since some options may be centrally managed and others left up to you individually.

Recommended Tools

A dedicated password manager like NordPass keeps your Gmail password unique and separate from everything else it protects, so a breach elsewhere never touches your Google account. Add NordVPN if you regularly sign into Google on public or unfamiliar Wi-Fi networks. See our full recommended tools guide for the complete lineup.

Recommended next step

Review VPN protection

A password manager protects accounts. A VPN protects traffic when you are on public or untrusted networks.

Review VPN protection

Keep Improving Your Account Security

#google account#2-step verification#passkeys#gmail security#nordpass#nordvpn

🔒 Generate a Strong Password Now

Use our free tool to create cryptographically secure passwords for all your accounts.

Try the Password Generator →
Best for public Wi-Fi

Encrypt traffic on public networks and add threat protection beyond passwords.

Try NordVPN
Most secure

Open-source password manager trusted by millions. Free forever.

Get Bitwarden Free