How to Check If Someone Else Is Reading Your Gmail

The short answer
To check if someone else is reading your Gmail, open Last Account Activity at the bottom of Gmail to review concurrent sessions by location and access type. Then visit myaccount.google.com to audit connected devices, delegated accounts, mail filters that forward externally, and third-party apps holding OAuth tokens. Any unfamiliar entry warrants immediate action.
How to check if someone else is reading your Gmail: five steps covering last activity, connected devices, delegation, filters, and third-party app access.
On this page
If you suspect someone else is reading your Gmail — a former partner, a colleague, a family member who once used your device — there are five specific places to look. This guide covers how to check if someone else is reading your Gmail using only Google's built-in settings, in the order a real compromise tends to show up: from the most visible sign to the most subtle.
None of these checks require technical knowledge. All five live in Gmail or your Google Account settings and take roughly ten minutes total on the first pass. The goal is not just to find evidence of access, but to understand every mechanism someone could use to read your mail — and to close each one.
Before you start: what these checks can and cannot tell you#
These five checks reveal who currently has access to your account and what routes exist to redirect your mail. They do not show which specific messages someone has already opened. Gmail does not expose per-message read status to the account holder, so if someone accessed your inbox last week and then lost access, the checks confirm they no longer have it — not what they read while they did.
You also need to be signed in to the account you want to audit. If you have been locked out, use Google's account recovery flow at support.google.com/accounts before attempting the steps below.
Workspace accounts work differently
Five checks, in the order they matter#
- 1
Check Last Account Activity
Scroll to the very bottom of Gmail on the web and click Details next to Last account activity. A popup shows the IP addresses, access types (browser, mobile app, third-party app), and timestamps for recent sessions. Scan for locations or access types you do not recognise. A concurrent session shown as active from a city you are not in means someone has that session open right now. Use Sign out all other web sessions in that popup to terminate every session except your current one. This is the fastest first signal, and it covers activity across all devices and apps.
- 2
Review connected devices and sessions
Go to myaccount.google.com, select Security from the left navigation, then scroll to Your devices. This lists every device that has signed in to your Google Account, with the approximate last-active date and device type. Remove any entry you do not recognise by clicking the device name and selecting Sign out. Be aware that removing a device signs it out but does not permanently block it — if the person still has your password, they can sign back in from the same hardware. Changing your password is the necessary follow-up step.
- 3
Check for delegated access
In Gmail on the web, open Settings using the gear icon, then click See all settings, then go to Accounts and import. Find the section labelled Grant access to your account. Any email address listed there has full read, send, and delete access to your inbox without needing your password — and delegation survives a password change. If you see an address you did not add deliberately, click Remove next to it immediately. This is one of the most dangerous access types because it is invisible to the casual user and persists through credential resets.
- 4
Audit mail filters and forwarding rules
In Gmail settings, go to Filters and blocked addresses. Look for any filter whose action includes Forward to, particularly filters with broad match criteria such as a blank From field or has:attachment applied to all incoming mail. Then switch to the Forwarding and POP/IMAP tab. If an external email address is listed there as confirmed, every message you receive is being silently copied to that inbox in real time. Delete the forwarding address and remove any suspect filter. A forwarding address shown as pending has not yet received any mail — a confirmed one has been routing your messages since confirmation.
- 5
Review third-party apps with Gmail access
Go to myaccount.google.com, select Security, then scroll to Third-party apps with account access. This lists every application that holds an OAuth token to your Gmail, along with the access level granted. Look for apps you do not remember authorising, apps with broad scopes such as Manage your mail, or apps that appear to be from providers you no longer use. Click the app name and select Remove Access to revoke the token. The app cannot re-acquire access without your explicit approval. Unlike delegated accounts, revoking an OAuth token takes effect immediately and does not require a password change to be effective.
Where to find each check across platforms#
The steps above use Gmail on the web as the reference. If you are working from a mobile device or need to audit a Workspace account in the admin console, the table below maps each check to its equivalent location.
| Check | Gmail web | Gmail mobile app | Workspace admin console |
|---|---|---|---|
| Last Account Activity | Bottom of inbox → Details | Not available — use web browser | Not exposed to admins; user-only view |
| Connected devices | myaccount.google.com → Security → Your devices | Google app → Manage your Google Account → Security → Your devices | Admin console → Users → select user → Security |
| Delegated access | Gmail Settings → Accounts and import → Grant access to your account | Not configurable on mobile — must use web | Admin SDK only; not visible in standard console UI |
| Filters and forwarding | Gmail Settings → Filters and blocked addresses / Forwarding and POP/IMAP | Not configurable on mobile — must use web | Admin can enforce no-external-forwarding policy via Gmail routing settings |
| Third-party app permissions | myaccount.google.com → Security → Third-party apps with account access | Google app → Manage your Google Account → Security → Third-party apps | Admin console → Security → API controls → App access control |
What a secured inbox looks like versus a compromised one#
Most unauthorized access does not look dramatic from inside Gmail. The inbox functions normally, mail arrives and leaves, and there are no error messages. The only signs are in settings: a filter with a forward action you did not create, an OAuth grant from an app you authorised years ago and forgot, or a delegated address added from a device that was once shared.
The before-and-after below illustrates the two most common configurations: an inbox with an active forwarding rule and an unfamiliar OAuth grant, and the same inbox after both are removed and two-step verification is enrolled.

What to do when all five checks come back clean#
If every check returns nothing suspicious but you still believe someone is reading your mail, consider two situations separately.
The first is shared physical access. If another person can unlock the device your Gmail session is open on — a shared family computer, an unlocked phone — they have read access regardless of what account settings show. The five checks above audit remote and delegated access, not physical proximity. Signing out of Gmail on every shared device and changing your Google Account password closes this gap.
The second is a Google Workspace account. As noted above, your administrator can access your mail through tools that do not appear in user-facing security screens. This is not a vulnerability; it is the intended architecture for organisational accounts. If this is the concern, your options depend on what your organisation's policy permits and what jurisdiction you are in.
After finding and removing any unauthorized access, take two additional steps that the in-settings checks do not handle: change your Google Account password immediately, and enroll in two-step verification if you have not already. Two-step verification means that even if someone has your password, they cannot sign in without a second factor from a device only you control.
Revoking access does not prevent re-entry if the password is unchanged
A faster way to catch new access as it happens#
The five-step routine above is a point-in-time audit. It tells you the current state of your account, but a forwarding rule created tomorrow or a new OAuth grant next week means you need to run the checks again to catch it. For most people, running these checks every few months is sufficient. For anyone who has already found unauthorized access once, a continuous layer makes more sense.
We build AI Emaily, an AI-native email client that adds ongoing detection on top of Gmail's built-in controls. Its spam-protection layer flags phishing attempts — including the type designed to trick you into clicking an OAuth authorisation for a malicious app — before they reach your inbox. Unusual send volume and filter changes surface in the audit log. If you want that continuous layer rather than a periodic manual check, the 7-day free trial at aiemaily.com lets you evaluate it against your own inbox. Pricing details are at aiemaily.com/pricing.
The five checks in this guide remain the authoritative method for a one-time audit. AI Emaily adds detection on top, not instead.
Frequently asked
See it in AI Emaily
Keep reading

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.