Accounts & Identity

How to Perform an Account Security Checkup

A repeatable checkup for important online accounts: sign-ins, recovery methods, MFA, connected apps, alerts and stored devices.

Start with the accounts that unlock others

Review primary email, password manager, mobile carrier, banking, cloud storage and major platform accounts first. These accounts can contain recovery routes or sensitive records.

1. Confirm sign-in protection

  • Unique password or passkey
  • MFA enabled
  • Backup codes stored safely
  • No unexpected app passwords or legacy sign-in methods

2. Review recent activity

Look at recent sign-ins, sessions and devices. Sign out old or unfamiliar sessions. A location mismatch is a clue, not proof by itself, because IP-based locations can be imprecise.

3. Check recovery routes

Verify phone numbers, recovery email addresses and trusted devices. Remove anything obsolete. Make sure you still control the secondary account.

4. Inspect connected applications

Third-party apps can retain account access after you stop using them. Remove integrations you no longer recognize or need, and review the permissions of the ones you keep.

5. Confirm alerts

Security alerts should reach an address or device you actively monitor. Treat unexpected alerts seriously, but open the account through its official app or website instead of using links in the alert.

Make the checkup routine

A quarterly or twice-yearly review is more realistic than relying on memory. Repeat it after changing phones, leaving a job, ending a subscription or responding to suspicious activity.

Use the site tool

The account security scorecard provides a quick starting point. It runs in the browser and does not ask for passwords.

Record decisions, not secrets

A useful checkup note might say “MFA enabled; backup codes stored offline; old tablet removed.” It should not contain the password, code or full recovery answers. This creates a review history without turning the checklist into another sensitive credential store.

Watch for security-setting changes

Providers add new passkey, session, privacy and recovery features over time. A periodic checkup can reveal stronger options that were unavailable when the account was created. It can also identify features that were enabled automatically or permissions granted during a rushed sign-in.

Prioritize by consequence

Not every account deserves the same effort. Start with accounts that can move money, reset other accounts, reveal identity information or control devices. A dormant forum account is less urgent than primary email, but it should still have a unique password so a breach cannot be reused elsewhere.

Close what you no longer need

Old accounts increase the number of places that hold personal data and credentials. Export anything needed, remove stored payment methods and use the provider’s proper closure process. Merely deleting an app from a phone usually does not delete the online account.

Educational scope: This page provides general information, not personalized incident response, legal advice, compliance advice or a guarantee of security.

Related reading