Start with the accounts that unlock others
Review primary email, password manager, mobile carrier, banking, cloud storage and major platform accounts first. These accounts can contain recovery routes or sensitive records.
1. Confirm sign-in protection
- Unique password or passkey
- MFA enabled
- Backup codes stored safely
- No unexpected app passwords or legacy sign-in methods
2. Review recent activity
Look at recent sign-ins, sessions and devices. Sign out old or unfamiliar sessions. A location mismatch is a clue, not proof by itself, because IP-based locations can be imprecise.
3. Check recovery routes
Verify phone numbers, recovery email addresses and trusted devices. Remove anything obsolete. Make sure you still control the secondary account.
4. Inspect connected applications
Third-party apps can retain account access after you stop using them. Remove integrations you no longer recognize or need, and review the permissions of the ones you keep.
5. Confirm alerts
Security alerts should reach an address or device you actively monitor. Treat unexpected alerts seriously, but open the account through its official app or website instead of using links in the alert.
Make the checkup routine
A quarterly or twice-yearly review is more realistic than relying on memory. Repeat it after changing phones, leaving a job, ending a subscription or responding to suspicious activity.
Use the site tool
The account security scorecard provides a quick starting point. It runs in the browser and does not ask for passwords.
Record decisions, not secrets
A useful checkup note might say “MFA enabled; backup codes stored offline; old tablet removed.” It should not contain the password, code or full recovery answers. This creates a review history without turning the checklist into another sensitive credential store.
Watch for security-setting changes
Providers add new passkey, session, privacy and recovery features over time. A periodic checkup can reveal stronger options that were unavailable when the account was created. It can also identify features that were enabled automatically or permissions granted during a rushed sign-in.
Prioritize by consequence
Not every account deserves the same effort. Start with accounts that can move money, reset other accounts, reveal identity information or control devices. A dormant forum account is less urgent than primary email, but it should still have a unique password so a breach cannot be reused elsewhere.
Close what you no longer need
Old accounts increase the number of places that hold personal data and credentials. Export anything needed, remove stored payment methods and use the provider’s proper closure process. Merely deleting an app from a phone usually does not delete the online account.