Blog/ Mobile email

Lost Your Phone? Secure Your Email in the Right Order

Nafiul HasanNafiul Hasan· 9 min read
Six-step email security checklist for a lost phone: remote lock, revoke sessions, revoke app access, change password, check forwarding rules, remote wipe decision

The short answer

If your phone with email on it is lost or stolen, lock the device remotely first. Then revoke active sessions in your Google or Microsoft account, change your password, and check for forwarding rules an intruder may have added. Changing your password does not remove a forwarding rule that is already there.

What to do if you lose your phone with email on it: lock it, revoke sessions, rotate your password, check forwarding rules. Steps in damage-prevention order.

On this page
  1. 01Before You Start
  2. 02How to Secure Your Email When Your Phone Goes Missing
  3. 03How the Steps Differ by Email Provider
  4. 04What to Do When the Standard Steps Do Not Work
  5. 05A Faster Way to Reduce Your Email Exposure

If your phone has email on it and it is gone — left on the train or taken from a bag — the question is not whether to act but in what order. Most accounts are not compromised within the first hour because of the phone itself. They are compromised because the default response is to change the password and stop. What to do if you lose your phone with email on it is a specific six-step sequence, ordered by what stops damage fastest.

The check that almost every lost-phone article skips is the forwarding rule. An intruder with a few minutes of access to an unlocked inbox can add a silent rule that routes a copy of every incoming email to an address they control. Changing your password after the fact does not remove a rule that is already in place.

The steps below cover Gmail and Microsoft 365 accounts. The paths differ slightly by provider — there is a reference table after the steps. Do not skip Step 5.

Before You Start#

Have a second device or a trusted computer available before you begin. These steps require signing into your account settings from somewhere other than the lost phone. If the lost phone was your only device, use a browser on a computer.

Check whether you have a backup verification method on the account. If your account requires a code sent to the lost phone for two-factor authentication, you may be locked out before you can lock the attacker out. If that is already the case, jump to the section below on what to do when the standard steps fail.

The attack that survives a password reset

Changing your password revokes active sessions in Google and Microsoft accounts. It does not remove forwarding rules, email filters, or OAuth app grants that were created during a window of access. Those persist through a password change and are the main reason an account continues leaking after a password reset. Check forwarding rules and app access explicitly — Settings > Forwarding in Gmail and Settings > Mail > Rules in Outlook — after every other step.

How to Secure Your Email When Your Phone Goes Missing#

  1. 1

    Lock the device remotely

    Go to android.com/find and sign in with the Google account on the phone, or go to appleid.apple.com and open Find My for an iPhone. Select Secure Device or Mark as Lost. This sends a remote lock command that requires a PIN to dismiss, even if the screen was already locked. On Android, you can display a message and callback number on the lock screen. Do this before anything else — it buys time for the remaining steps without permanently destroying the device.

  2. 2

    Sign the phone out of your email accounts

    Go to myaccount.google.com, then Security, then Your devices. Find the lost phone and select Sign out. For Microsoft, go to account.microsoft.com, then Devices, and remove or sign out the device. This terminates the live session token stored on the phone. The phone will no longer have access to your email even if the screen lock is bypassed. Repeat for every account the phone had access to, including secondary accounts.

  3. 3

    Revoke connected app access

    Sessions and OAuth grants are separate things. A session is the app or browser being signed in. An OAuth grant is permission given to an email client app to access your account independently of the session. Both can exist simultaneously. In Google: myaccount.google.com > Security > Third-party apps with account access. Remove any app you do not recognise or that was only used on the lost phone. In Microsoft: account.microsoft.com > Privacy > Apps and services connected to your account.

  4. 4

    Change your email account password

    After revoking sessions and app access, change the password. This order matters. Revoking sessions terminates tokens already issued. Changing the password prevents new tokens from being issued with the old credentials. In Google accounts, a password change automatically signs out other devices but does not remove existing OAuth grants, which is why Step 3 comes before this one. Enable two-factor authentication now if you do not already have it, and set up a backup method that does not depend on the lost device.

  5. 5

    Check for forwarding rules and filters

    In Gmail: click the gear icon, then See all settings, then Forwarding and POP/IMAP. Remove any forwarding address you did not add. Then go to Filters and Blocked Addresses and look for filters that include a forward-to or delete action that you did not create. In Outlook: go to Settings, then Mail, then Rules, and sort by date created. Any rule that forwards to an external address and was not created by you is a sign the account was accessed. Delete it. This step is the one most people skip, and the one that matters most after the password is changed.

  6. 6

    Decide whether to wipe the device

    A remote wipe is permanent. It erases everything: photos, messages, app data. It is the right choice if the phone was stolen rather than lost, if the screen was not locked, or if the device had no PIN. Once you wipe, Find My and Find My Device will no longer show the location. Do not wipe until Steps 2 through 5 are complete — account-level revocation protects you regardless of whether the hardware is ever found, and wiping too early removes the ability to locate the device.

How the Steps Differ by Email Provider#

The procedure above applies to any email provider. The exact paths depend on whether the account is Google or Microsoft.

ActionGoogle / GmailMicrosoft / Outlook 365
Lock device remotelyandroid.com/find — Secure Deviceaccount.microsoft.com/devices for Windows phones; appleid.apple.com for iPhones running Outlook
Revoke device sessionmyaccount.google.com > Security > Your devices > Sign outaccount.microsoft.com > Devices > Sign out or Remove
Revoke app accessmyaccount.google.com > Security > Third-party apps with account accessaccount.microsoft.com > Privacy > Apps and services connected to your account
Change passwordmyaccount.google.com > Security > Passwordaccount.microsoft.com > Security > Change password
Check forwarding rulesGmail Settings > See all settings > Forwarding and POP/IMAP, then Filters and Blocked AddressesOutlook Settings > Mail > Rules — sort by date created; also check connected accounts for external forwarding
Enable two-factor authenticationmyaccount.google.com > Security > 2-Step Verificationaccount.microsoft.com > Security > Advanced security options > Two-step verification

What to Do When the Standard Steps Do Not Work#

The most common failure point is two-factor authentication. If the account requires a code sent by SMS or an authenticator app that was only installed on the lost phone, you may be locked out before you can lock the attacker out. Google's account recovery flow is at accounts.google.com/signin/recovery. Microsoft's equivalent is at account.live.com/acsr. Both ask identity questions — previous passwords, trusted devices you have used, account creation details. Start immediately rather than waiting, and answer as many questions as possible.

If a forwarding rule is already routing copies of your mail to an attacker and you cannot revoke it right away, move your most sensitive correspondence to a second email account at a different provider while you work through recovery. This does not stop the forwarding on the compromised account but removes the value of what is being intercepted.

If the device is not appearing in Find My Device or Find My, it is powered off, in airplane mode, or the battery is dead. The remote lock command queues server-side and executes the next time the phone connects to a network. Do not wait for the device to appear before revoking sessions — account-level revocation works regardless of whether the phone is online.

Before and after diagram for lost-phone email security: left side shows open account access via active session token on a lost device; right side shows session revoked, password changed, forwarding rules cleared, and two-factor authentication set on a backup device
The six steps move the account from the exposed state on the left to the secured state on the right. Forwarding rules must be cleared explicitly — they survive a password reset.

A Faster Way to Reduce Your Email Exposure#

The steps above respond to an incident. Credential phishing — emails that impersonate login pages, cloud services, or banks — is how attackers most often obtain account access in the first place, sometimes weeks before a device is physically lost or stolen. If credentials were already compromised before the phone went missing, the steps here are necessary but the window opened earlier and through a different channel.

We build AI Emaily. Its spam and phishing filter intercepts credential-phishing attempts before they reach your inbox, identifying the domain patterns and sender behaviour that characterise phishing campaigns rather than relying on a blocklist of known addresses. It also blocks tracking pixels that confirm an email address is active, reducing the value of your address to spammers running targeted campaigns. The forwarding-rule check in Step 5 is a manual step you run once after an incident; a phishing filter runs on every message. If you want to see what continuous coverage looks like, start a 7-day free trial at aiemaily.com or compare plans at aiemaily.com/pricing.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Catch phishing before it becomes an incident.

AI Emaily's spam and phishing filter runs on every message, not only after something goes wrong. Start a 7-day free trial at aiemaily.com or review the full feature set and pricing at aiemaily.com/pricing.

  • 7-day free trial
  • Cancel anytime
  • Every provider