Open the security or activity page on each important account, review the recent sessions and devices, and sign out anything you do not recognise.

The record already exists

Email providers, hosting panels, business platforms, and most content systems keep a log of recent access: when, from roughly where, and on what kind of device.

Most also list the sessions currently signed in, with a way to end any of them.

Almost nobody looks, because nothing prompts you to and the page is usually two levels into settings.

It is the only cheap way to answer a question you otherwise cannot: whether somebody else has your credentials right now.

What to look at, and where

The first two are the ones to check first and the ones people check last, since compromising either lets somebody take everything else without needing any other password.

What is normal and what is not

The interpretation matters, since an unfamiliar entry is not automatically an intrusion.

Locations are approximate and derived from the network, so a nearby city rather than your town is ordinary, and a mobile connection can appear somewhere unexpected.

A virtual private network moves your apparent location entirely, which surprises people who forgot they had one running.

Device names are frequently generic, so an unrecognised model may be your own phone described differently.

What is not normal: a country you have no connection to, access at a time nobody was working, a device type nobody in the business uses, and a session you cannot account for that is still active.

Two of those together is worth acting on rather than puzzling over.

Sign out everything

The action that costs almost nothing and settles most uncertainty.

Most accounts offer a single option to end all sessions everywhere, including your own.

Use it whenever anything looks unclear, then sign back in on your own devices, which takes a few minutes and removes anybody who was holding an old session.

Change the password first, since ending sessions without changing the credential lets whoever had it simply sign in again.

Order matters here: change the password, then end all sessions, then re-enable two-step verification if it was off.

A worked example

A business checked their email account's activity page for the first time and found sessions from two countries over several months.

Nothing had appeared wrong. No messages were missing, nothing had been sent from the account, and no customer had complained.

The access had been read-only, which is the common pattern, since a quiet mailbox is more valuable than a noisy one.

They changed the password, ended every session, turned on two-step verification, and reviewed what that mailbox contained: invoices, supplier correspondence, and password reset messages for every other account.

The most useful outcome was realising how much a single mailbox controlled, which changed how they treated it.

Check what else is connected

Since sessions are only half the picture.

Most accounts have a list of connected applications and third-party access, granted at some point and never reviewed.

Those retain access without needing the password, and they survive a password change, which is why they matter.

Remove anything you do not recognise or no longer use, including tools from a supplier you stopped working with.

Look for forwarding rules and filters in email specifically, since a rule quietly copying messages elsewhere is a common way access is retained after a password change.

That last check takes a minute and finds the thing a password change would otherwise miss.

Turn on the alerts

So that this becomes automatic rather than something you remember to do.

Most providers can notify you about a sign-in from a new device or location, and the setting is usually off or set to something minimal.

Enable it on email, hosting, and the registrar at minimum.

Expect some false alarms, which is the cost, and treat that as acceptable rather than as a reason to switch it off.

Send them to an address somebody actually reads, since an alert going to an unmonitored mailbox is the same as no alert.

Make it a routine

Quarterly is enough, and it takes about twenty minutes across every account that matters.

Keep a short list of the accounts to check, since the ones forgotten are the ones nobody thinks of.

Do it at the same time as reviewing who has access, which is the same set of pages and the same twenty minutes.

Note the date each time, so a gap is visible.

Anything longer than quarterly and you are checking after the fact rather than while it matters.

What to do if something is wrong

The sequence matters, since acting in the wrong order lets somebody back in.

Start with the email account, whatever else looks affected, because it can reset everything else.

Change its password, end all sessions, check forwarding rules and connected applications, then enable two-step verification.

Then work outward: registrar, hosting, site, payment platforms, in that order, doing the same on each.

Only then look at what was accessed and what may have been taken, since containment comes before investigation and the investigation is much easier once nobody else is inside.

The counter-case

Logs are not conclusive.

Location data is approximate enough to alarm somebody unnecessarily, and businesses have changed every password over an entry that turned out to be a phone on a mobile network.

A determined intruder may also leave nothing visible, so a clean log is reassurance rather than proof.

And most compromises are found through consequences rather than logs, which is why backups and updates matter more than monitoring.

Check quarterly, enable the alerts, act on the clear cases, and do not treat an unfamiliar city as an emergency.

What to do

  1. Check email and the registrar first.
  2. Review recent access and active sessions.
  3. Change the password, then end all sessions.
  4. Review connected applications.
  5. Check email forwarding rules.
  6. Enable new-device alerts.
  7. Repeat quarterly and note the date.

Step five is the one that catches retained access, since a forwarding rule keeps working after every password in the business has been changed.

The measure that prevents most of this is covered in turning on two-factor everywhere that matters.


Frequently asked questions

What record already exists?

Most accounts keep a log of recent access with time, approximate location, and device, plus a list of sessions currently signed in with a way to end them.

Which accounts matter most?

Email and the domain registrar, checked first. Compromising either lets somebody take everything else without needing any other password.

What looks suspicious but is not?

Locations are approximate, so a nearby city is ordinary, a mobile connection can appear anywhere, a VPN moves you entirely, and device names are frequently generic.

What is the right order to act in?

Change the password, then end all sessions, then re-enable two-step verification. Ending sessions first lets whoever had the password simply sign in again.

What does a password change miss?

Connected applications, which retain access without the password, and email forwarding rules quietly copying messages elsewhere. Both survive a password change.

How often should I check?

Quarterly, which takes about twenty minutes across the accounts that matter. Do it alongside reviewing who has access, since it is the same pages.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Never looked at your email account's activity page?

Open it now and read the recent access list. It is two levels into settings and it answers a question you cannot otherwise answer.

Start a Conversation