If someone gets into your Gmail, other accounts could be at risk. Your bank. Your GCash wallet. Your job portals. Your OFW remittance apps. One compromised email address triggers a domino effect across everything you own online.
Here’s how to protect it. This guide walks you through how to secure your Gmail account in seven practical steps. No jargon. No corporate hand-waving. What works.
- Why Gmail Security Matters Right Now
- Step 1: Enable Two-Factor Authentication (2FA) with Passkeys
- Step 2: Audit Your Recovery Email and Phone Number
- Step 3: Revoke Access from Apps and Websites You Don’t Use
- Step 4: Sign Out of Unrecognized Devices and Sessions
- Step 5: Upgrade to Google’s Advanced Protection Program
- Step 6: Secure Your Recovery Email with the Same Effort
- Step 7: Use a Password Manager and Stop Reusing Passwords
- The Bottom Line
- FAQ
- Sources
Why Gmail Security Matters Right Now
Your email is the master key. When you click “Forgot Password” on any site, the reset link arrives in your inbox. If someone gains access to your Gmail, they can reset the passwords on your bank account, your GCash wallet, your Shopee and Lazada profiles, and your social media accounts.

Worse, they can lock you out of your own email by changing the recovery options.
A 2024 report from Google found that 99.7% of account takeovers happen because users either reuse passwords, don’t enable two-factor authentication (2FA), or fall victim to phishing. The good news: you can stop 99% of attacks by following these steps.
For Filipinos, this is especially critical. OFW families rely on email to access remittance platforms, online banking, and job applications. Your email is your livelihood.
Related: Google Translate adds 110 new languages including Bikol, Hiligaynon, Kapampangan, Pangasinan, Waray
Step 1: Enable Two-Factor Authentication (2FA) with Passkeys
SMS-based 2FA is outdated. It’s vulnerable to SIM-swapping attacks, where a criminal calls your phone provider, pretends to be you, and transfers your phone number to a new SIM card they control. Then they use that SIM to intercept your 2FA codes.
Switch to passkeys. A passkey is a cryptographic authentication method built into your phone or laptop. It’s faster than typing a code. It’s more secure because it’s immune to phishing.
Here’s how to set it up:
- Go to myaccount.google.com
- Click Security from the left menu
- Scroll to How you sign in to Google
- Click Passkeys
- Follow the on-screen prompts to register your phone or laptop as a passkey
That’s it. Next time you log in, you’ll see your device listed. Tap or click to approve the login. No codes to copy. No SMS required.
If you don’t have a device that supports passkeys yet, use an authenticator app like Google Authenticator, Microsoft Authenticator, or Authy instead. These are far safer than SMS.
Related: Here are some Google’s tools and best practices to be safer online
Step 2: Audit Your Recovery Email and Phone Number
Recovery options are your escape hatch if you get locked out. An outdated or abandoned recovery email is a backdoor for attackers.
Log into your Google Account and go to Security > How you sign in to Google. You’ll see:
- Recovery phone number – Is this still your active number? If you switched telcos or got a new SIM, update it now.
- Recovery email – Can you still access this? If it’s an old Yahoo account you haven’t checked in five years, update it.
Remove any recovery options you don’t recognize or use anymore. Each one is a potential weak point.
Pro tip: Use a recovery email that’s different from your main Gmail address. Use a recovery phone number that’s actively in your name (not a spouse’s or friend’s number). Attackers target the paths of least resistance.
Step 3: Revoke Access from Apps and Websites You Don’t Use
Over the years, you’ve clicked “Sign in with Google” on countless websites. Video streaming sites. Gaming platforms. Weather apps. Fitness trackers. Every connection is a potential breach point.
If the service gets hacked, hackers don’t get your password. They get the app token, which can let them access your account anyway.
Clean this up:
- Go to myaccount.google.com/security-checkup
- Scroll to Your apps and connections
- Review the list. If you don’t recognize the app or don’t use it anymore, click it and select Remove access
You should see fewer than 10 active connections. If you see dozens, you’ve got some cleanup to do.
This takes 10 minutes. It’s worth it.
Step 4: Sign Out of Unrecognized Devices and Sessions
Google lets you see every device currently logged into your Gmail. This includes phones, tablets, laptops, and even someone else’s computer if they’ve hacked your account.
Go to Google Account > Security > Your devices. Click Manage all devices. You’ll see a list of every active session.
Look for anything you don’t recognize. A city you’ve never visited. A device you don’t own. A browser or app you don’t use.
If you spot something suspicious, click on it and select Sign out. Then change your password immediately.
One gotcha: VPNs and mobile hotspots can mask your real location. If you see a session from a different country but you were using a VPN that day, you can probably ignore it. But if you see a city you’ve never been to and you don’t use a VPN, that’s a red flag.
Step 5: Upgrade to Google’s Advanced Protection Program
Advanced Protection Program (APP) is Google’s strongest security option. It’s designed for high-profile users, activists, journalists, and anyone at serious risk of targeted hacking.
APP does three things:
- Blocks less secure sign-in methods. You must use a hardware security key or passkey to log in. Full stop.
- Restricts third-party app access. If an app was compromised, it can’t access your Gmail or Google Drive.
- Requires hardware verification. Before signing in from a new device, you tap your security key to confirm it’s you.
This is maximum security. The tradeoff is friction. You’ll need a hardware security key like a YubiKey or Google Titan key (around ₱2,500–₱4,000).
If you’re a frequent traveler, a journalist, or you hold sensitive information, this is worth the investment. For most people, passkeys and a strong 2FA method are sufficient.
To enroll, go to Google Account > Security > Advanced Protection Program and follow the prompts.
Step 6: Secure Your Recovery Email with the Same Effort
Your recovery email is only as strong as the password protecting it.
If your recovery email is Gmail, apply these same steps to that account. Enable 2FA. Update recovery options. Revoke unused apps.
If your recovery email is from a different provider (Outlook, Yahoo, etc.), log in now and enable 2FA on that account too. Use a strong password manager to generate a unique password you’ve never used anywhere else.
Think of your recovery email as a second layer of your main account. Protect it accordingly.
Step 7: Use a Password Manager and Stop Reusing Passwords
Password reuse is the #1 reason accounts get compromised. If you use the same password for Gmail as you do for LinkedIn, and LinkedIn gets hacked, attackers will try that password on your Gmail first.
Use a password manager like Bitwarden, 1Password, or Dashlane. These tools:
- Generate strong, random passwords for every site
- Remember them for you
- Encrypt them so even the company can’t see them
- Alert you if one of your passwords appears in a data breach
Pick a strong master password for your password manager. Write it down and store it somewhere safe (not on your computer). Then never reuse it anywhere else.
If you use a password manager, your Gmail password should be something you’ve never typed before and will never type again. That’s the whole point.
The Bottom Line
Securing your Gmail takes two hours of focused work. You’ll spend maybe 30 minutes on the initial setup, then another hour or so over the next few weeks tightening up recovery options and revoking old app connections.
That two hours of work protects your entire digital life. Your bank account. Your business email. Your identity. Your GCash wallet. Everything.
The alternative is one bad day where an attacker gets in and spends three hours locking you out of every account you own. Recovery takes weeks.
Choose the two hours now.
FAQ
Can I use my phone number for both recovery options?
No. Use a phone number for password recovery and an email address for account recovery. If an attacker gains access to your phone, they could potentially use both recovery methods if they’re the same.
What if I lose my security key?
Google lets you register multiple security keys. Register at least two. Also, save backup codes in a secure location. If you lose all your keys and backup codes, account recovery is a slow, painful process.
Is two-factor authentication required for Gmail?
No, it’s optional. But hackers specifically target accounts without 2FA. If you have one account on the internet without 2FA, make it not your Gmail.
Can hackers get my password if I use a password manager?
No. Password managers encrypt passwords on your device before they’re sent anywhere. Even if someone hacks the password manager company’s servers, they’d see encrypted garbage, not your passwords.
What if my recovery email gets hacked?
That’s why you secure your recovery email with 2FA and a strong unique password. Your recovery email is a second-order account. Treat it with the same care as your Gmail.
Should I enable Advanced Protection?
For most people, no. Passkeys and an authenticator app are sufficient. Enable Advanced Protection if you’re a target of harassment, a public figure, a journalist, or you work in security. For everyone else, it’s overkill.
Sources
- Google Account Security Checkup – Official Google security dashboard
- CISA: Multi-Factor Authentication – US Cybersecurity & Infrastructure Security Agency guidance on 2FA and phishing resistance
- Google Advanced Protection Program – Official documentation and enrollment
