How to Tell If Someone Is Reading Your Email Without Permission

You have a nagging feeling someone is getting into your email. Maybe a message looked opened before you read it, or you spotted a login you don't recognize, or a person in your life

T

Technobezz

Editorial Team

May 30, 2026
•
8 min read

Contents

Don't Miss the Good Stuff

Get tech news that matters delivered to your inbox.

You have a nagging feeling someone is getting into your email. Maybe a message looked opened before you read it, or you spotted a login you don't recognize, or a person in your life seems to know things only your inbox would reveal.

The good news: most major email services keep an access log you can read in a few minutes. The honest caveat: these logs prove that an access happened and from where, not exactly what was read. You also need to check the quietest sign of all, silent forwarding, because an intruder can set it once and keep reading forever without logging in again.

This guide walks every surface (web, iOS, Android, Windows, Mac) in quickest-first order for Gmail, Microsoft/Outlook, Yahoo, and Apple. Run the checks that match your provider, then act on anything you don't recognize.

Check Gmail's Last Account Activity (Desktop)

This is the fastest Gmail check and shows the last 10 IP addresses that touched your account.

On a computer, open Gmail at mail.google.com.

In the bottom right corner of the inbox, click Details (the small link under "Last account activity").

Read the activity table. The Access type column shows the browser, device, or mail server (POP/IMAP) used. Concurrent session information tells you whether you're signed in on another device, browser, or location right now. The list shows the last 10 IP addresses and approximate locations, plus up to 3 flagged suspicious addresses if Google issued a warning.

If you see a location or access type you don't recognize, treat the account as compromised: change your password immediately and follow Gmail's security tips.

The Gmail mobile app does not show this panel. On a phone, use the Google Account device screen below instead.

Review Devices Signed In to Your Google Account

This works on web and mobile and lets you sign out anything you don't own.

Go to your Google Account at myaccount.google.com.

Open Security (Security and sign-in).

On the "Your devices" panel, select Manage all devices to see everything signed in now or in the last few weeks.

Select a device for details. Look for hardware you don't own, locations you weren't at, an unusual browser, or access times you don't remember.

To revoke access, tap the device, then tap Sign out.

The time shown is the last communication between the device and Google's systems, so it may reflect background sync rather than a person actively using it.

Remove Third-Party Apps With Gmail Access

An app or extension granted mailbox access can read your mail without ever triggering a sign-in alert.

Go to myaccount.google.com/connections (Security tab, "Your connections to third-party apps and services").

Apps grouped under "Access to your Google Account" are the ones that can read your Google data, potentially including Gmail.

Select any app you don't recognize or no longer use, then choose See details.

Next, select Remove access, then Confirm. Google notes that removing access may make some app features unavailable.

Check Gmail for Unauthorized Forwarding

Silent forwarding is the single most reliable sign of compromise and the easiest to miss.

Open Gmail on a computer and click the Settings gear icon (top right).

Click See all settings.

Open the Forwarding and POP/IMAP tab.

Check the Forwarding section for any address you didn't add. If you find unauthorized forwarding, select Disable forwarding.

Finish by clicking Save Changes at the bottom.

A genuine forwarding setup also shows a persistent notice in the inbox that disappears once forwarding is disabled.

Review the Microsoft Account Recent Activity Page

For Outlook.com, Hotmail, and Live accounts, this page covers 30 days of sign-ins.

Go to account.live.com/Activity (reachable from your Microsoft account security settings).

Expand any entry to see date and time, location on a map, IP address, device or operating system type, and the browser or app used.

If an "Unusual activity" section appears, expand the entry and choose This was me or This wasn't me. These buttons appear only in that section.

Selecting "This wasn't me" triggers Microsoft's account-protection steps; also open the Security settings page and change your password.

An "unusual sign-in" email is itself a common phishing lure. A genuine Microsoft alert comes from [email protected]. Don't click links in a suspicious one; navigate to the activity page yourself.

Sign Out Everywhere on Your Microsoft Account

Sign in to Advanced security options on your Microsoft account security dashboard.

Scroll to the Sign out everywhere section and select Sign out.

This is not instant. It can take up to 24 hours to fully propagate, and it does not sign out an Xbox console, which has separate steps.

Check Outlook for Hidden Forwarding and Rules

Check both, since an intruder may use either (or several rules at once).

In Outlook on the web or new Outlook, select Settings (gear icon, top right).

Go to Mail > Forwarding. If forwarding is enabled to an address you don't recognize, toggle Disable forwarding and select Save. Also check whether "Keep a copy of forwarded messages" was left on so mail leaves unnoticed.

Then go to Settings > Mail > Rules (older path: Options > Mail > Automatic processing > Inbox and sweep rules). Selecting a forwarding rule shows a description containing the forward-to address.

Delete any rule you didn't create.

After cleanup, reset your password at account.live.com/password/reset and choose "I think someone else is using my Microsoft account."

Find and Remove Unusual Activity on Yahoo

On desktop or mobile web, sign in to the Yahoo Account security page. In the mobile apps, tap the Profile icon > Settings > "Manage account privacy" or "Your privacy controls" > Security.

Review Current sign-ins, the devices signed in now. To remove one, click the device and select Sign out; make sure "I don't recognize this session" is checked for it first (and unchecked for devices you do recognize).

Review External connections, third-party apps signed in to your account. To revoke one, open App passwords, find the app, and select Delete app password.

Review Recent account activity for changes like a phone number added or an email address removed, which can reveal tampering.

If anything looks suspicious, change your password immediately rather than relying only on signing devices out.

Check Your Apple Account Device List

Apple does not offer a mail-specific access log, but you can see every device signed in with your Apple Account.

Web: sign in at account.apple.com and select Devices (click "View Details" to authenticate if needed). Click a device name to see model, serial number, software version, and whether it's a trusted device for two-factor codes.

iPhone or iPad: open Settings, tap your name, and scroll to the device list; tap a device for details.

Mac: choose Apple menu > System Settings, click your name, and scroll to the Devices section.

Windows: open iCloud for Windows and click Account Details.

To remove a device you don't recognize, open it and select Remove from Account, then confirm. Removed devices lose access to iCloud, Find My, and other Apple services and stop receiving verification codes.

What These Checks Cannot Tell You

Know the limits before you trust a clean result.

You cannot reliably tell if someone read a message and then marked it unread to cover their tracks. Read/unread status leaves no forensic trail; activity logs show that an access happened, not what was read.

Timestamps can mislead. The time on a session is the last communication with the provider's systems and may be automatic background syncing, not a person at the keyboard. This applies to Google, Microsoft, and Yahoo alike.

Forwarding and inbox rules let an attacker keep reading without logging in again, so a quiet account does not mean a safe one. Always check forwarding and rules, not just login history.

A provider employee or law enforcement with a court order can read mail server-side with no trace, and malware or a keylogger on your own device defeats every check above.

Because detection has hard limits, the practical defense is prevention: change your password, turn on two-factor authentication, and encrypt sensitive mail.

Frequently Asked Questions

Can I tell exactly which emails someone read?

No. Sign-in and activity histories show that an access happened and from where, but they reveal nothing about what was opened or done during that session. Read/unread status leaves no trail, so someone can read a message and mark it unread without a record.

I see a strange location in my activity log. Was my account hacked?

Treat it as compromised and act. Change your password immediately, sign out all devices, and check forwarding and inbox rules. Remember the listed time may reflect background sync, but an unfamiliar location or access type is enough reason to lock things down.

Why should I check forwarding and rules if my login history looks clean?

Because forwarding is the most reliable sign of compromise and the easiest to miss. An attacker can set auto-forwarding or an inbox rule once and then keep reading your mail forever without logging in again, so it never reappears as a new suspicious sign-in.

I got an "unusual sign-in" email. Should I click the link?

No. That email is a common phishing lure. A genuine Microsoft alert comes from [email protected], but rather than trusting any message, navigate to your provider's activity page yourself and review sign-ins there.

I clicked "Sign out everywhere" on my Microsoft account. Why is a device still in?

The action is not instant; it can take up to 24 hours to fully propagate across browsers, apps, and devices. It also does not sign out an Xbox console, which uses separate sign-out steps.

If someone has malware on my computer, will these checks catch them?

No. Malware or a keylogger on your own device defeats all of these provider-side checks, and a provider employee or court order can read mail server-side with no trace. In those cases, prevention (a new password from a clean device, two-factor authentication, and encrypting sensitive mail) is the real defense.