An unexpected login alert deserves an independent check
A message claiming that someone signed into your account may be genuine, or it may be designed to send you to a false login page. You can investigate without using the link in the message.

Open the service yourself
Use the app or type the known address. Look for recent account activity and security notifications. Compare device, time and location information carefully; approximate locations can be imprecise, so do not decide from a city name alone.
Respond within the account
If the activity is unfamiliar, follow the service's documented steps to secure access. Review recovery details, sessions and connected apps. Change credentials through the genuine service and consider any other account where the same password was used.
Preserve useful evidence
Keep a copy of the alert and note what you found if you need support. Avoid forwarding sensitive recovery links to a public group. If the account is important for work, notify the responsible administrator through your normal channel. The practical habit is separating the alert from the route you use to investigate it. That gives you a way to respond promptly without trusting a message simply because it sounds urgent.
Sources & further reading
Source material and official guidance. Original practical suggestions are editorial content, not statements from the organisations below. Checked September 14, 2026.
Have a correction or a question about this article? Contact the editorial team. Read our editorial policy and disclaimer.


