Your password is one stolen login away from being someone else’s. The fastest way to know whether that has already happened is to look at who is signed in — and Gmail has shown you exactly that for years, tucked behind a link most people never click. I opened the Details link on my own inbox while writing this and watched the last ten IP addresses scroll out, then cross-checked them against Manage all devices in my Google Account. Here is how to read both screens, sign out anything you do not recognise, and lock the door behind you so a leaked password cannot walk back in.
Two Screens, Two Jobs
Gmail gives you two different windows into who is signed in. The Details link inside Gmail shows recent Gmail access — sign-in history, access type, and the last 10 IP addresses. The Your devices panel in your Google Account shows every device signed in across all of Google, and lets you sign each one out.
People go looking for “active sessions” and expect a single list. Google splits it in two, and the split is logical once you see it. One screen is mail-specific and read-only; the other is account-wide and lets you take action.
The first is Last account activity, reached through the Details link at the bottom of the Gmail inbox. It is the quick pulse check: a sign-in history scoped to Gmail, showing how your account was accessed and from where. The second is Your devices, inside your Google Account’s Security section. That one is the control panel — it lists every phone, tablet, and browser signed in to the whole account and gives you a Sign out button for each. Use the first to spot something off, the second to do something about it.
Last Account Activity: the Details Link
In Gmail on a computer, scroll to the bottom of the inbox and click the Details link at the bottom-right. The Activity information panel opens and shows your sign-in history with the access type (browser, mobile, or a mail server like POP or IMAP), the last 10 IP addresses and approximate locations, and whether you are signed in elsewhere right now.
This is the feature most Gmail users have never noticed. To open it:
- Open Gmail on a computer. The link is web-only — it does not appear in the mobile app.
- Scroll to the bottom of the inbox. Look below the last message in the list.
- Click Details at the bottom-right. Per Google’s Gmail Help, this opens the Activity information panel.
What you get is specific. The panel shows your sign-in history including the dates and times Gmail was used, the access type — “the browser, device, or mail server (like POP or IMAP)” you accessed Gmail from — and the last 10 IP addresses with approximate locations. It also flags if you are currently signed in to Gmail on another device, browser, or location. That last line is the one that catches an active intruder in the act. If you also lean on keyboard shortcuts to move through Gmail faster, this panel is the security counterpart worth bookmarking in your routine.
Your Devices: the Whole Account
Go to your Google Account, open Security, and find the Your devices panel. Click Manage all devices to list every device currently signed in or recently used — phones, tablets, and browsers across all of Google, not just Gmail. Click any device to see its details and recent sessions.
Where the Details link is Gmail-only, Your devices covers everything tied to your Google Account. To reach it, open your Google Account, select Security, and in the Your devices panel choose Manage all devices, per Google Account Help. You will see devices where you are currently signed in or have been recently.
Click into any device to inspect it. One thing surprises people here: a single device can list several sessions. Google defines a session as a period of sign-in activity through a browser, app, or service — and a new one is created each time you sign in on a new browser, re-enter your password, or grant an app access. So two or three sessions on your own laptop is normal, not a red flag. What you are hunting for is a device type, browser, or location that is not yours.
Sign Out a Session Remotely
In Manage all devices, select the device you no longer own or do not recognise and choose Sign out. Google ends that session remotely — no need to physically hold the device. Do this for phones you have sold, shared or public computers, and anything on the list you cannot account for.
This is the action the Details link cannot give you. Open Security, go to Your devices, tap Manage all devices, pick the device, and choose Sign out. Google’s guidance is to do this for devices you no longer own or do not recognise.
The everyday uses are obvious once you have the button. Sold or traded in a phone and forgot to log out? Sign it out. Checked your mail on a hotel-lobby computer or a friend’s laptop and never closed the session? Sign it out. Each removal ends that session cleanly, so the address stays yours and your inbox stays shut to a device you no longer control. One honest caveat, covered in full below: signing a device out does not change your password — so for a device that was lost or stolen rather than merely sold, signing out is only half the job.
When You See a Stranger
If a device or location is genuinely unfamiliar, treat it as a possible breach. Sign that device out, change your Google Account password immediately, turn on 2-Step Verification under Security, and run a Security Checkup to review devices, recent activity, and recovery options in one pass.
Finding something you cannot explain is the whole reason these screens exist. Work through it in order:
- Sign the device out. From Manage all devices, end the session right away so the intruder loses access while you fix the rest.
- Change your password. Google’s first recommendation for unrecognised activity is to change your password — this invalidates the credential the attacker may be holding.
- Turn on 2-Step Verification. Under Security, turn on 2-Step Verification. Per Google Account Help, it adds an extra layer of security in case your password is stolen, requiring a second step in addition to the password — so a leaked password alone stops being enough.
- Run a Security Checkup. It walks you through your devices, recent security activity, and recovery options together, so you can confirm nothing else was changed.
The order matters: signing out buys you a moment, but the password change and 2-Step Verification are what actually close the door. A determined attacker who still knows your password can sign straight back in until you do both.
What These Screens Do Not Tell You
These tools have real limits. Signing a device out does not change your password, so an attacker who knows it can sign back in. Last account activity covers only recent Gmail access — not all Google services. And multiple IP addresses are often harmless, caused by mail clients, Mail Fetcher, or mobile carriers, not intruders.
Knowing the boundaries keeps you from a false sense of safety — and from false alarms:
- Sign-out is not a lockout. Ending a session does nothing to the password. If the password is compromised, the attacker simply signs in again. The fix is always password change plus 2-Step Verification, not sign-out alone.
- Last account activity is Gmail-scoped. The Details panel shows recent Gmail access, not every sign-in to every Google service. For the full picture across Drive, Photos, YouTube, and the rest, use Your devices in the Google Account, which is account-wide.
- Multiple IPs are usually innocent. Per Google, extra IP addresses appear because POP and IMAP clients each connect, Mail Fetcher surfaces Google’s own servers, and mobile carriers can report a location far from where you are. A long list is not proof of a breach.
- A clean list today is not a guarantee. Check periodically, not once. New sessions appear whenever you sign in somewhere new — and so would an intruder’s. If your address has ever been exposed in a data leak, make this check a recurring habit rather than a one-off.
Verdict
Checking who is signed in to Gmail comes down to two screens: the Details link for a quick Gmail-scoped pulse, and Your devices in your Google Account for the full list plus a remote Sign out button. Pair sign-out with a password change and 2-Step Verification and you have actually secured the account, not just glanced at it.
Best for: anyone who wants a two-minute security check they can repeat — after travelling, after using a shared computer, or after hearing about a breach. The Details link tells you fast whether something is off; Manage all devices lets you act on it. Run both, sign out anything unfamiliar, and you have closed the most common way an account stays quietly compromised.
Skip if: you are looking for a single deep audit log of everything across every Google product — these screens give you recent activity and current devices, not an exhaustive forever-history. For a one-off password and recovery review, the Security Checkup tool is the better starting point.
Open the Details link now, then walk through Manage all devices. If everything is yours, it is a thirty-second peace-of-mind check. If it is not, you have caught it early — and the change-password-plus-2-Step-Verification sequence above turns the catch into a fix.

Alexis Dollé, email expert for 10+ years. Founder of Email Tools. I test every email client and utility myself, then write about them the way I’d explain them to a friend — no marketing fluff, no sponsored rankings, every claim sourced.
LinkedInSources & references
- Google Gmail Help, “See Gmail activity on your account” — the Details link at the bottom-right of the inbox, the Last account activity / Activity information panel, the access type (browser, device, or mail server like POP/IMAP), the last 10 IP addresses and approximate locations, and the concurrent-session notice. Accessed 2026-06-20. support.google.com — See Gmail activity on your account
- Google Account Help, “See devices that have used your account” — Security → Your devices → Manage all devices, the definition of a session, signing a device out remotely, and reviewing unfamiliar devices. Accessed 2026-06-20. support.google.com — See devices that have used your account
- Google Account Help, “Turn on 2-Step Verification” — an extra layer of security in case your password is stolen, requiring a second step in addition to the password, turned on under Security. Accessed 2026-06-20. support.google.com — Turn on 2-Step Verification
Frequently Asked Questions
How do I check what devices are logged in to my Gmail?
Two places cover it. For Gmail itself, open Gmail on a computer and click the Details link at the bottom-right of the inbox — the Last account activity panel shows recent access, the access type, and the last 10 IP addresses. For every device across your whole Google Account, go to your Google Account, open Security, and click Manage all devices under Your devices. That second screen lists every phone, tablet, and browser signed in and lets you sign any of them out.
Where is the Details link in Gmail?
On a computer, open Gmail and scroll to the very bottom of the inbox, below the last message. The Details link sits at the bottom-right corner. Clicking it opens the Activity information panel with your sign-in history, the access type for each entry, and the last 10 IP addresses and approximate locations that accessed Gmail. The link only appears in the web version of Gmail on a computer, not in the mobile app.
How do I sign out of Gmail on another device remotely?
Go to your Google Account, open Security, and click Manage all devices under Your devices. Select the device you want to remove and choose Sign out. Google ends that session remotely, so a phone you sold or a shared computer you forgot to log out of is signed out without you touching it. Signing a device out does not change your password, so for a lost device, also change the password.
Why do I see multiple IP addresses or locations in Last account activity?
It is usually normal. The panel can show several IP addresses because POP and IMAP clients like Apple Mail or Outlook each connect, Mail Fetcher shows Google’s own servers, and mobile carriers sometimes report a location far from where you actually are. Multiple entries are not automatically a breach. Worry when you see an access type, device, or location you genuinely cannot explain — then change your password and review your devices.
Does signing out a device change my Gmail password?
No. Signing a device out under Manage all devices only ends that session — it does not change your password. Someone who already knows your password can simply sign back in. If you suspect your password is compromised, change the password and turn on 2-Step Verification under Security so a password alone is no longer enough to get in. Signing out is the first move, not the whole fix.
What should I do if I see an unrecognised device on my Google Account?
Treat it as a possible compromise. Sign that device out from Manage all devices, then change your Google Account password right away. Turn on 2-Step Verification under Security so a stolen password cannot sign in on its own, and run a Security Checkup to review devices, recent security activity, and recovery options. If anything still looks wrong after that, repeat the checkup until every device and session is one you recognise.
Related: Set up 2-Step Verification on Gmail — the lock that makes a stolen password useless. Gmail keyboard shortcuts — move through the inbox faster. What to do when your Gmail address is exposed — the next step after a leak. Whitelist an email address in Gmail — keep the mail you want flowing.