Lost Your Phone? Secure Your Email in the Right Order

The short answer
If your phone with email on it is lost or stolen, lock the device remotely first. Then revoke active sessions in your Google or Microsoft account, change your password, and check for forwarding rules an intruder may have added. Changing your password does not remove a forwarding rule that is already there.
What to do if you lose your phone with email on it: lock it, revoke sessions, rotate your password, check forwarding rules. Steps in damage-prevention order.
On this page
If your phone has email on it and it is gone — left on the train or taken from a bag — the question is not whether to act but in what order. Most accounts are not compromised within the first hour because of the phone itself. They are compromised because the default response is to change the password and stop. What to do if you lose your phone with email on it is a specific six-step sequence, ordered by what stops damage fastest.
The check that almost every lost-phone article skips is the forwarding rule. An intruder with a few minutes of access to an unlocked inbox can add a silent rule that routes a copy of every incoming email to an address they control. Changing your password after the fact does not remove a rule that is already in place.
The steps below cover Gmail and Microsoft 365 accounts. The paths differ slightly by provider — there is a reference table after the steps. Do not skip Step 5.
Before You Start#
Have a second device or a trusted computer available before you begin. These steps require signing into your account settings from somewhere other than the lost phone. If the lost phone was your only device, use a browser on a computer.
Check whether you have a backup verification method on the account. If your account requires a code sent to the lost phone for two-factor authentication, you may be locked out before you can lock the attacker out. If that is already the case, jump to the section below on what to do when the standard steps fail.
The attack that survives a password reset
How to Secure Your Email When Your Phone Goes Missing#
- 1
Lock the device remotely
Go to android.com/find and sign in with the Google account on the phone, or go to appleid.apple.com and open Find My for an iPhone. Select Secure Device or Mark as Lost. This sends a remote lock command that requires a PIN to dismiss, even if the screen was already locked. On Android, you can display a message and callback number on the lock screen. Do this before anything else — it buys time for the remaining steps without permanently destroying the device.
- 2
Sign the phone out of your email accounts
Go to myaccount.google.com, then Security, then Your devices. Find the lost phone and select Sign out. For Microsoft, go to account.microsoft.com, then Devices, and remove or sign out the device. This terminates the live session token stored on the phone. The phone will no longer have access to your email even if the screen lock is bypassed. Repeat for every account the phone had access to, including secondary accounts.
- 3
Revoke connected app access
Sessions and OAuth grants are separate things. A session is the app or browser being signed in. An OAuth grant is permission given to an email client app to access your account independently of the session. Both can exist simultaneously. In Google: myaccount.google.com > Security > Third-party apps with account access. Remove any app you do not recognise or that was only used on the lost phone. In Microsoft: account.microsoft.com > Privacy > Apps and services connected to your account.
- 4
Change your email account password
After revoking sessions and app access, change the password. This order matters. Revoking sessions terminates tokens already issued. Changing the password prevents new tokens from being issued with the old credentials. In Google accounts, a password change automatically signs out other devices but does not remove existing OAuth grants, which is why Step 3 comes before this one. Enable two-factor authentication now if you do not already have it, and set up a backup method that does not depend on the lost device.
- 5
Check for forwarding rules and filters
In Gmail: click the gear icon, then See all settings, then Forwarding and POP/IMAP. Remove any forwarding address you did not add. Then go to Filters and Blocked Addresses and look for filters that include a forward-to or delete action that you did not create. In Outlook: go to Settings, then Mail, then Rules, and sort by date created. Any rule that forwards to an external address and was not created by you is a sign the account was accessed. Delete it. This step is the one most people skip, and the one that matters most after the password is changed.
- 6
Decide whether to wipe the device
A remote wipe is permanent. It erases everything: photos, messages, app data. It is the right choice if the phone was stolen rather than lost, if the screen was not locked, or if the device had no PIN. Once you wipe, Find My and Find My Device will no longer show the location. Do not wipe until Steps 2 through 5 are complete — account-level revocation protects you regardless of whether the hardware is ever found, and wiping too early removes the ability to locate the device.
How the Steps Differ by Email Provider#
The procedure above applies to any email provider. The exact paths depend on whether the account is Google or Microsoft.
| Action | Google / Gmail | Microsoft / Outlook 365 |
|---|---|---|
| Lock device remotely | android.com/find — Secure Device | account.microsoft.com/devices for Windows phones; appleid.apple.com for iPhones running Outlook |
| Revoke device session | myaccount.google.com > Security > Your devices > Sign out | account.microsoft.com > Devices > Sign out or Remove |
| Revoke app access | myaccount.google.com > Security > Third-party apps with account access | account.microsoft.com > Privacy > Apps and services connected to your account |
| Change password | myaccount.google.com > Security > Password | account.microsoft.com > Security > Change password |
| Check forwarding rules | Gmail Settings > See all settings > Forwarding and POP/IMAP, then Filters and Blocked Addresses | Outlook Settings > Mail > Rules — sort by date created; also check connected accounts for external forwarding |
| Enable two-factor authentication | myaccount.google.com > Security > 2-Step Verification | account.microsoft.com > Security > Advanced security options > Two-step verification |
What to Do When the Standard Steps Do Not Work#
The most common failure point is two-factor authentication. If the account requires a code sent by SMS or an authenticator app that was only installed on the lost phone, you may be locked out before you can lock the attacker out. Google's account recovery flow is at accounts.google.com/signin/recovery. Microsoft's equivalent is at account.live.com/acsr. Both ask identity questions — previous passwords, trusted devices you have used, account creation details. Start immediately rather than waiting, and answer as many questions as possible.
If a forwarding rule is already routing copies of your mail to an attacker and you cannot revoke it right away, move your most sensitive correspondence to a second email account at a different provider while you work through recovery. This does not stop the forwarding on the compromised account but removes the value of what is being intercepted.
If the device is not appearing in Find My Device or Find My, it is powered off, in airplane mode, or the battery is dead. The remote lock command queues server-side and executes the next time the phone connects to a network. Do not wait for the device to appear before revoking sessions — account-level revocation works regardless of whether the phone is online.

A Faster Way to Reduce Your Email Exposure#
The steps above respond to an incident. Credential phishing — emails that impersonate login pages, cloud services, or banks — is how attackers most often obtain account access in the first place, sometimes weeks before a device is physically lost or stolen. If credentials were already compromised before the phone went missing, the steps here are necessary but the window opened earlier and through a different channel.
We build AI Emaily. Its spam and phishing filter intercepts credential-phishing attempts before they reach your inbox, identifying the domain patterns and sender behaviour that characterise phishing campaigns rather than relying on a blocklist of known addresses. It also blocks tracking pixels that confirm an email address is active, reducing the value of your address to spammers running targeted campaigns. The forwarding-rule check in Step 5 is a manual step you run once after an incident; a phishing filter runs on every message. If you want to see what continuous coverage looks like, start a 7-day free trial at aiemaily.com or compare plans at aiemaily.com/pricing.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.