See Where Your Google Account Is Signed In
Short answer
Go to myaccount.google.com/device-activity, or Security → Your devices → Manage all devices. Each entry shows a device name, location and last activity, and clicking one gives you a Sign out button that revokes the session immediately. Nothing on the device is deleted when you sign it out.
On this page
You get an email from Google saying there was a new sign-in, or you simply want to know whether the laptop you sold last year still has access to your Gmail. Either way the answer is in one place, and it takes about two minutes to read properly.
Google keeps a live list of every device holding a valid session for your account, with the device name, approximate location and when it was last active. You can revoke any of them from your phone without touching the device itself.
Open the device list
There are two routes to the same page:
- Go directly to
myaccount.google.com/device-activity. - Or open
myaccount.google.com, choose Security from the left-hand menu, and scroll to Your devices, then click Manage all devices.
The result is a grid of entries. Each shows a device name, the browser or app where relevant, a location, and a timestamp. Clicking one expands it into detail — the session’s first sign-in, the last activity, and the sign-out button.
Note that one physical device can appear several times. A single laptop running Chrome, Gmail in another browser and the Drive desktop app will show as multiple sessions, because each is a separate access grant. That is normal and is not a sign of duplication or compromise.
Reading the list without panicking
Most “unfamiliar” entries turn out to be ordinary. Before you treat anything as an intrusion, check it against the common explanations.
| What you see | Usually means | Action |
|---|---|---|
| A city 50–150 miles away | Your ISP or mobile carrier’s routing hub | None |
| A generic name like “Linux” or “Android” | A smart TV, console or older device | Identify, then sign out if unused |
| The same laptop listed three times | Separate browser and app sessions | None |
| A device you sold or recycled | A session that survived the handover | Sign out |
| A country you have no connection to | Possible compromise, or a VPN you use | Investigate properly |
| A sign-in at a time you were asleep | Background app sync, or a real intrusion | Investigate properly |
The two rows worth acting on are the last two. Everything above them is noise that trips people into unnecessary password resets.
One useful cross-check sits on the same Security page under Recent security activity. It lists sign-ins, password changes, recovery-option edits and new app connections with timestamps. If an unfamiliar device appeared at the same moment as a recovery phone number you did not add, that combination is a genuine warning sign — far more meaningful than a location estimate on its own.
Signing a device out remotely
Click the device, then Sign out. Google revokes the session’s token immediately. On that device, Gmail and the other Google apps will show a sign-in screen the next time they try to sync.
Nothing is deleted. Files already on the device remain there, and your account is unchanged. If the device belongs to you and you still want it, you simply sign in again.
For a phone you have genuinely lost, go further. The Find My Device link in the same area lets you locate it, lock it with a message on the screen, or erase it entirely. Signing out of Google alone does not protect anything stored locally on the phone.
When to change your password
Change it if any of the following is true:
- A device or location you cannot explain, and which is not covered by the table above.
- Recent security activity shows a change you did not make — a new recovery email, a new phone number, a forwarding rule in Gmail.
- You entered your Google password on a page you reached from a link in an email or a pop-up.
- You used the same password on another service that has since been breached.
Change it from Security → Password. Use something long and unique, and store it in a password manager rather than reusing a variation of the old one.
Changing the password signs out most other sessions automatically, which is the fastest way to eject an intruder. It does not sign out everything: the device you change it from stays signed in, and some sessions you have previously verified can persist. Return to the device list afterwards and confirm what is left.
The two things people forget after a password change
An attacker who had access long enough may have left a door open that a new password does not close.
App passwords. These are 16-character codes generated for older software that cannot handle 2-Step Verification — legacy mail clients, some scanners, older calendar apps. They work indefinitely and are never challenged for a second factor. Open Security → 2-Step Verification → App passwords and revoke anything you do not actively recognise. If you rely on one, generate a fresh one rather than keeping the old.
Third-party access. Over the years you have likely granted dozens of sites and apps permission to read your contacts, calendar or Drive. Those grants are separate tokens that survive a password change. Open Security → Your connections to third-party apps and services, read through the list, and remove anything you no longer use — paying particular attention to anything with full Gmail access or Drive write permission.
Turn on 2-Step Verification
If it is not already on, this is the single change that matters most. With 2-Step Verification enabled, a stolen password alone is not enough to sign in.
Go to Security → 2-Step Verification and follow the setup. The strongest practical options are:
- Passkeys, which use your phone or laptop’s own biometric unlock and cannot be phished.
- Google prompts, the “Yes, it’s me” tap sent to a signed-in phone.
- An authenticator app generating six-digit codes offline.
SMS codes are better than nothing but are the weakest option, because they can be intercepted through SIM-swap attacks. Use them only as a backup.
While you are there, save your backup codes somewhere outside your Google account — printed, or in a password manager. They are what gets you back in if you lose the phone.
Run the Security Checkup
Google bundles all of the above into a single guided review at
myaccount.google.com/security-checkup. It walks through your devices, recent
activity, sign-in methods, connected apps and recovery options in order, flagging
anything it considers weak.
It takes a few minutes and is worth running twice a year, or immediately after any suspicious sign-in alert. Nothing in it is destructive — every step asks before it changes anything.
A note on storage and access
While you are inside your account settings, the storage page is a short detour worth taking. A compromised or forgotten third-party app with Drive access can quietly accumulate files against your quota — if your storage total looks higher than it should, our guide on what is using your Google storage shows how to break the figure down by service. The same reasoning applies on your phone, where what is taking up iPhone storage covers the equivalent breakdown locally.
Realistic expectations
For most people the device list contains nothing alarming — a handful of forgotten browsers, an old tablet, and a location estimate that looks wrong because IP lookup is imprecise. Signing out what you no longer use is good hygiene rather than an emergency.
The genuinely useful outcome of this exercise is usually not catching an intruder. It is noticing that 2-Step Verification was never switched on, or that an app you stopped using in 2021 still has permission to read your entire mailbox. Fix those two things and the account list stops being something you need to worry about.