The notification appeared while I was making coffee. “New sign-in to your account.” The location was a city I had not visited. The device was listed as a browser I do not use. For a moment the usual questions arrived at once: Is someone inside the account right now? Did I forget a login? Is this the start of something larger?
Most unrecognized login alerts are not emergencies. A fraction of them are. The useful response is a short, ordered set of checks that quickly separates the two.

Why the Alert Alone Does Not Tell You Enough
Login alerts are designed to be sensitive. They fire for legitimate reasons (a new device, a browser update, a VPN session, a travel login) and for hostile ones. The message itself rarely contains enough information to decide which is which. Acting on panic or ignoring the alert both create problems. A calm sequence of verification steps does not.
The three possibilities behind most alerts
You (or a device you own) signed in from an unfamiliar network or browser.
A service glitch or delayed notification made a normal login look new.
Someone else successfully authenticated and the alert is the first warning.
The checks below are designed to identify which of the three you are dealing with, starting with the fastest actions.
Minimum Effort: The Five-Minute Response
You do not need to change every password or freeze accounts. Start here.
Open the account from a device and network you trust.
Use a phone or computer you already own, on your home or cellular connection. Do not click any link inside the alert message.Look at the recent security or login activity page.
Almost every major service shows a list of recent sign-ins with approximate location, device, and time. Match the alert against that list.If the login is one you recognize, mark it as trusted or simply dismiss the alert.
Update the device name if the service allows it so future alerts are clearer.If the login is not yours, sign out that session immediately and change the password.
Then review the recovery email and phone number to make sure they still belong to you.
That sequence resolves the majority of alerts. Most turn out to be legitimate logins that looked unfamiliar at first glance.
What “sign out that session” actually does
It terminates the active connection associated with the unrecognized login. If an attacker had obtained a session cookie or temporary token, this step cuts it off before you finish the password change. Do it first when the activity is clearly not yours.
If You Want to Go Further
When the alert involves a high-value account (primary email, financial services, cloud storage with irreplaceable files), add these steps after the minimum response:
Review the full list of signed-in devices and active sessions. Remove anything you do not recognize.
Check whether new recovery methods, forwarding rules, or app passwords were added. Remove any that you did not create.
Enable or confirm that login alerts are turned on for every new device or location.
If the account supports passkeys or security keys, add one. It raises the bar for the next attempt.
These actions take a few extra minutes and close the common follow-on paths an attacker might use after an initial login.
A note on location accuracy
The city or country shown in an alert is often approximate. A login routed through a corporate VPN, a mobile carrier gateway, or a cloud provider can appear far from your actual location. Treat the location as one signal among several, not as definitive proof of intrusion.

What I Do When the Alert Arrives
I open the account directly, read the activity list, and decide in under five minutes. If everything matches a device I own, I move on. If anything is clearly foreign, I terminate the session, change the password, and scan for secondary changes. The process is the same whether the account is email, banking, or cloud storage.
The habit removed the background tension that used to accompany every unexpected notification. An alert is now information, not an automatic crisis.
The Next Thing
The next time an unrecognized login alert appears, do not click the link in the message. Open the account the way you normally do and look at the recent activity list. That single independent check tells you almost everything you need to know.
You don’t have to do everything. Just do the next thing.
No notes yet — be the first to inscribe one.