Blog/ Gmail how-tos

How to Check If Someone Else Is Reading Your Gmail

Nafiul HasanNafiul Hasan· 10 min read
Gmail security audit showing last account activity panel, connected devices list, and delegated access settings used to detect unauthorized inbox access

The short answer

To check if someone else is reading your Gmail, open Last Account Activity at the bottom of Gmail to review concurrent sessions by location and access type. Then visit myaccount.google.com to audit connected devices, delegated accounts, mail filters that forward externally, and third-party apps holding OAuth tokens. Any unfamiliar entry warrants immediate action.

How to check if someone else is reading your Gmail: five steps covering last activity, connected devices, delegation, filters, and third-party app access.

On this page
  1. 01Before you start: what these checks can and cannot tell you
  2. 02Five checks, in the order they matter
  3. 03Where to find each check across platforms
  4. 04What a secured inbox looks like versus a compromised one
  5. 05What to do when all five checks come back clean
  6. 06A faster way to catch new access as it happens

If you suspect someone else is reading your Gmail — a former partner, a colleague, a family member who once used your device — there are five specific places to look. This guide covers how to check if someone else is reading your Gmail using only Google's built-in settings, in the order a real compromise tends to show up: from the most visible sign to the most subtle.

None of these checks require technical knowledge. All five live in Gmail or your Google Account settings and take roughly ten minutes total on the first pass. The goal is not just to find evidence of access, but to understand every mechanism someone could use to read your mail — and to close each one.

Before you start: what these checks can and cannot tell you#

These five checks reveal who currently has access to your account and what routes exist to redirect your mail. They do not show which specific messages someone has already opened. Gmail does not expose per-message read status to the account holder, so if someone accessed your inbox last week and then lost access, the checks confirm they no longer have it — not what they read while they did.

You also need to be signed in to the account you want to audit. If you have been locked out, use Google's account recovery flow at support.google.com/accounts before attempting the steps below.

Workspace accounts work differently

If your Gmail address ends in a company domain rather than @gmail.com, your Google Workspace administrator can access your mail via Google Vault or the Admin SDK without appearing in any of the user-facing checks below. The five steps here audit third-party and delegated access — not admin-level access. If employer monitoring is a concern, your organisation's acceptable-use policy and employment jurisdiction determine what is permitted.

Five checks, in the order they matter#

  1. 1

    Check Last Account Activity

    Scroll to the very bottom of Gmail on the web and click Details next to Last account activity. A popup shows the IP addresses, access types (browser, mobile app, third-party app), and timestamps for recent sessions. Scan for locations or access types you do not recognise. A concurrent session shown as active from a city you are not in means someone has that session open right now. Use Sign out all other web sessions in that popup to terminate every session except your current one. This is the fastest first signal, and it covers activity across all devices and apps.

  2. 2

    Review connected devices and sessions

    Go to myaccount.google.com, select Security from the left navigation, then scroll to Your devices. This lists every device that has signed in to your Google Account, with the approximate last-active date and device type. Remove any entry you do not recognise by clicking the device name and selecting Sign out. Be aware that removing a device signs it out but does not permanently block it — if the person still has your password, they can sign back in from the same hardware. Changing your password is the necessary follow-up step.

  3. 3

    Check for delegated access

    In Gmail on the web, open Settings using the gear icon, then click See all settings, then go to Accounts and import. Find the section labelled Grant access to your account. Any email address listed there has full read, send, and delete access to your inbox without needing your password — and delegation survives a password change. If you see an address you did not add deliberately, click Remove next to it immediately. This is one of the most dangerous access types because it is invisible to the casual user and persists through credential resets.

  4. 4

    Audit mail filters and forwarding rules

    In Gmail settings, go to Filters and blocked addresses. Look for any filter whose action includes Forward to, particularly filters with broad match criteria such as a blank From field or has:attachment applied to all incoming mail. Then switch to the Forwarding and POP/IMAP tab. If an external email address is listed there as confirmed, every message you receive is being silently copied to that inbox in real time. Delete the forwarding address and remove any suspect filter. A forwarding address shown as pending has not yet received any mail — a confirmed one has been routing your messages since confirmation.

  5. 5

    Review third-party apps with Gmail access

    Go to myaccount.google.com, select Security, then scroll to Third-party apps with account access. This lists every application that holds an OAuth token to your Gmail, along with the access level granted. Look for apps you do not remember authorising, apps with broad scopes such as Manage your mail, or apps that appear to be from providers you no longer use. Click the app name and select Remove Access to revoke the token. The app cannot re-acquire access without your explicit approval. Unlike delegated accounts, revoking an OAuth token takes effect immediately and does not require a password change to be effective.

Where to find each check across platforms#

The steps above use Gmail on the web as the reference. If you are working from a mobile device or need to audit a Workspace account in the admin console, the table below maps each check to its equivalent location.

CheckGmail webGmail mobile appWorkspace admin console
Last Account ActivityBottom of inbox → DetailsNot available — use web browserNot exposed to admins; user-only view
Connected devicesmyaccount.google.com → Security → Your devicesGoogle app → Manage your Google Account → Security → Your devicesAdmin console → Users → select user → Security
Delegated accessGmail Settings → Accounts and import → Grant access to your accountNot configurable on mobile — must use webAdmin SDK only; not visible in standard console UI
Filters and forwardingGmail Settings → Filters and blocked addresses / Forwarding and POP/IMAPNot configurable on mobile — must use webAdmin can enforce no-external-forwarding policy via Gmail routing settings
Third-party app permissionsmyaccount.google.com → Security → Third-party apps with account accessGoogle app → Manage your Google Account → Security → Third-party appsAdmin console → Security → API controls → App access control

What a secured inbox looks like versus a compromised one#

Most unauthorized access does not look dramatic from inside Gmail. The inbox functions normally, mail arrives and leaves, and there are no error messages. The only signs are in settings: a filter with a forward action you did not create, an OAuth grant from an app you authorised years ago and forgot, or a delegated address added from a device that was once shared.

The before-and-after below illustrates the two most common configurations: an inbox with an active forwarding rule and an unfamiliar OAuth grant, and the same inbox after both are removed and two-step verification is enrolled.

Before-and-after diagram of a Gmail security audit showing an active forwarding rule and an unrecognised OAuth token on the left, and the same inbox after both are revoked and two-step verification is enabled on the right
Active forwarding rules and forgotten OAuth grants are the two most common vectors for silent, ongoing access. Both survive a password change unless explicitly removed.

What to do when all five checks come back clean#

If every check returns nothing suspicious but you still believe someone is reading your mail, consider two situations separately.

The first is shared physical access. If another person can unlock the device your Gmail session is open on — a shared family computer, an unlocked phone — they have read access regardless of what account settings show. The five checks above audit remote and delegated access, not physical proximity. Signing out of Gmail on every shared device and changing your Google Account password closes this gap.

The second is a Google Workspace account. As noted above, your administrator can access your mail through tools that do not appear in user-facing security screens. This is not a vulnerability; it is the intended architecture for organisational accounts. If this is the concern, your options depend on what your organisation's policy permits and what jurisdiction you are in.

After finding and removing any unauthorized access, take two additional steps that the in-settings checks do not handle: change your Google Account password immediately, and enroll in two-step verification if you have not already. Two-step verification means that even if someone has your password, they cannot sign in without a second factor from a device only you control.

Revoking access does not prevent re-entry if the password is unchanged

Removing a delegated address, signing out a device, or revoking an OAuth token stops current access. It does not prevent a person who knows your password from creating new access the same way. Change your password as soon as you find any suspicious entry, then enroll in two-step verification to prevent password-only sign-ins going forward.

A faster way to catch new access as it happens#

The five-step routine above is a point-in-time audit. It tells you the current state of your account, but a forwarding rule created tomorrow or a new OAuth grant next week means you need to run the checks again to catch it. For most people, running these checks every few months is sufficient. For anyone who has already found unauthorized access once, a continuous layer makes more sense.

We build AI Emaily, an AI-native email client that adds ongoing detection on top of Gmail's built-in controls. Its spam-protection layer flags phishing attempts — including the type designed to trick you into clicking an OAuth authorisation for a malicious app — before they reach your inbox. Unusual send volume and filter changes surface in the audit log. If you want that continuous layer rather than a periodic manual check, the 7-day free trial at aiemaily.com lets you evaluate it against your own inbox. Pricing details are at aiemaily.com/pricing.

The five checks in this guide remain the authoritative method for a one-time audit. AI Emaily adds detection on top, not instead.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Secure your inbox — then keep it that way

AI Emaily blocks phishing attempts before they grant someone else access to your inbox. Try it free for 7 days, no commitment.

  • 7-day free trial
  • Cancel anytime
  • Every provider