There’s a line of small gray text at the bottom of Gmail. Most people have never clicked it. It’s the fastest answer to the question that brought you here, and it’s a narrower answer than it looks. A record of who reached your account covers sessions. What someone did while they were inside one is a separate question, and this page takes both.
- Four kinds of mail account keep four different records on four different pages. Which one you can reach depends on whether your mail is personal or runs on a company’s Workspace or Microsoft 365 subscription.
- Every one of those records is a list of sessions. It can show that your account was reached at 3:40 in the morning, from an address in a state you have never worked in. It stops there. Which messages were read sits outside it.
- The damage that outlives a break-in sits in your settings. It’s a forwarding rule, a filter, a delegate or a connected app. All four keep working after you change the password.
- What you can take back depends on custody rather than on how bad it was. Something still inside your own mailbox has a window measured in days or weeks. Once something reaches another company’s server, that window is closed.
Where the record actually is
Start with the page that matches your account. These are four separate systems, and one of the four answers is yours.
A personal Gmail account. Scroll to the bottom of any Gmail page on a computer. There’s a line reading last account activity, with a details link beside it. That opens the record. Google describes it plainly: “You can see your sign-in history, including the dates and times that your Gmail account was used. You can also see the IP addresses which were used to access your account.” The list runs to “the last 10 IP addresses and approximate locations that accessed your Gmail account”. Above it sits a second block. “In the ‘Concurrent session information’ section, you’ll see if you’re signed in to Gmail on another device, browser, or location.” (Google, checked September 7, 2026.)
The column worth reading first is access type. It names the browser, device or mail server the connection came through, including POP and IMAP. A row that says IMAP, on an account where you have never set up a mail program, tells you more than a location you half recognize.
The Google Account underneath it. Gmail’s page is one view of a bigger record. In your Google Account, under security, there’s a list of devices and a list of recent security events. The device list is where you sign something out. Google describes it as “You can see computers, phones, and other devices where you are or were signed in to your Google Account recently”. It covers devices you’re signed in on now, and devices you’ve been signed in on in the last few weeks (Google, checked September 7, 2026). The security events list records password changes, recovery changes and new sign-in methods. That’s where an intruder’s housekeeping shows up.
A personal Microsoft account. The equivalent is the recent activity page, reached from the security section of your account. Microsoft is specific about its reach: “The Recent activity page shows you when and where you’ve used your Microsoft account within the last 30 days.” Each entry carries the date, time, location and type of activity. Open one and it shows the IP address of the device and the operating system it ran. Each entry also carries two buttons, this was me and this wasn’t me. The second one starts the account protection process rather than merely filing a note (Microsoft, checked September 7, 2026).
A Microsoft 365 work or school account. Your own sign-in history lives on the my sign-ins page of the My Account portal. You can open it yourself, as the person whose account it is. It’s the closest Microsoft comes to the Gmail footer link, and hardly anybody knows it’s there.
The administrator records, if you are the administrator. This is where the real material is. On a small firm’s Workspace or Microsoft 365 subscription, the owner usually holds the rights to it. Google Workspace keeps user log events for sign-ins, OAuth log events for what third-party applications did, and Gmail log events for message handling. Email Log Search sits alongside those, for tracing where a specific message went. Microsoft 365 keeps sign-in and audit logs in Microsoft Entra, and a broader search across services in Microsoft Purview.
If your mail is a work account and somebody else administers it, one of those four records is yours to open and the administrator holds the other three. The message to send is short. It gets a better answer when it carries a date and an hour rather than a feeling.
What a sign-in record proves
It’s a record of access. Access is a smaller thing than most people want it to be.
Three limits are worth holding before you read a single row.
The location is inferred. It comes from an IP address. That’s a rough proxy for geography, and a poor one on mobile networks, where a phone can surface a hundred miles from where you’re standing. A city you half recognize is a reason to look further. Treat it as a lead rather than a finding.
Several addresses are normal. Google lists the ordinary explanations itself: reading your mail through POP or IMAP on another service, pulling mail in from another account, and the roaming behavior of a cell carrier. An account with a phone, a laptop, a tablet and one connected tool on it produces a busy page on a quiet week.
The record covers sessions, not contents. This is the limit that matters most, and it’s the one that disappoints most reliably. Every row is a connection: a time, an address, a kind of client. Reading leaves a trace nowhere, on any mail system, so nothing anywhere says that a thread about your client’s settlement was opened at 2:15. That’s why a suspected intrusion is answered by working out what was reachable, rather than by proving what was seen.
Google’s own warning carries the right amount of doubt in it: “If you don’t recognize the activity on the page, like a location or access type, someone might have access to your account because of phishing or malware.” Might. The page gives you a reason to act, and the conclusion stays yours.
Then there’s the complication that catches out anyone who has connected software to their mailbox, which by now is nearly everybody. An application you authorized reaches your mail on an authorized session, because that’s what you told your provider to allow. In the access record, it looks exactly like you. So on a mailbox with an assistant, a CRM, a scheduler or a backup tool attached, the page you just opened holds your work and your software’s in one column. Closing that gap takes a record kept by whatever had the intention. That’s a subject in its own right, and the activity log behind every action is where the two records are set against each other properly.
The changes a sign-in record will never show
A session ends. A setting stays, and that’s the part of an intrusion that survives everything you’re likely to do about it.
Google turns this into a checklist on its own page for a compromised account. Read it as a list of places to look rather than as advice. It tells you to correct the setting immediately if you see unfamiliar changes to mail delegation, automatic mail forwarding, scheduled emails, your name in Gmail, the vacation responder, and the address on outgoing mail. The same goes for blocked email addresses, IMAP or POP remote access, the filters that manage your incoming mail, and the labels that organize it (Google, checked September 7, 2026). Microsoft mailboxes have the same shapes under different names: inbox rules, mailbox forwarding, mailbox permissions and delegates.
Three of those carry almost all of the risk. Check those three first.
Forwarding. A rule that copies everything to another address is the quietest possible outcome of a break-in, because your mailbox looks exactly as it did before. From then on, the mail reaches the intruder on its own. The Federal Trade Commission puts it at the top of its own list: “Check if there are auto-forwarding rules in your email account that you didn’t set up. Hackers might create these rules to forward your emails to another address.” (FTC, consumer alert of October 29, 2024, checked September 7, 2026.)
Filters. More interesting than forwarding, and much less discussed. A filter that archives or deletes anything containing the word invoice, or the name of your bank, or one client’s domain, works on your attention rather than on your money. It edits what you’re able to notice. That’s the mechanism underneath a whole family of payment fraud. The fake invoice arrives, the real one is filed away unread, and nobody in the firm sees the two side by side.
Delegation. A second account granted standing access to yours. It’s a legitimate feature that assistants and partners use. It runs on its own grant rather than on your password, so it survives every password change you make.
Add one more to the list, from a different Google page: the applications currently authorized on your account. A grant is another standing door, issued in your name. Reviewing the list is the ten minutes with the best return in this whole subject. Where that list lives on each platform, and how to read what’s on it, is what to check before you connect your inbox.
The reason for the ordering is one sentence. A password change ends a session. A rule, a delegate and a grant all carry on, and an intruder who left one behind is still reading your mail on Thursday.
How long each record lasts
The record you want is often the one that expired. Every system here has a limit. The limits differ by more than an order of magnitude, and each one is fixed once the time has passed.
A personal Gmail account is measured in rows. It’s ten rows rather than a period of time. On an account with a phone, a laptop and a connected tool on it, ten rows can cover a day and a half. That’s the tightest window on this page, and it belongs to the largest number of people.
The Google device list runs to the last few weeks, in Google’s own words. That’s a soft boundary rather than a published number.
A personal Microsoft account gives you 30 days, stated as such.
Google Workspace gives an administrator 6 months for admin log events, user log events, OAuth token log events and Gmail log events. Where a log sits outside that list, Google says the retention is generally 6 months too (Google, checked September 7, 2026). Email Log Search is the exception, and a sharp one: “Message delivery status isn’t available for messages older than 30 days.” (Google, checked September 7, 2026.)
Microsoft 365 depends on what you pay for, and this is where small firms are caught out. Microsoft Entra keeps audit logs and sign-in logs for seven days on the free tier, and 30 days on P1 and P2 (Microsoft, checked September 7, 2026). Buying the upgrade in a hurry reaches what’s still there and stops at that: “Log retention changes aren’t retroactive. When you upgrade from Microsoft Entra ID Free to P1 or P2, only data still within the free retention period (up to seven days) is available. Data that has already expired can’t be recovered unless it was previously archived.” Separately, the wider audit record in Microsoft Purview runs longer. Microsoft states that “The default retention period for Audit (Standard) changed from 90 days to 180 days”, with logs generated before October 17, 2023 held for 90 days and logs generated on or after that date held for 180 (Microsoft, checked September 7, 2026).
One habit follows from all of that, and it costs about two minutes. The window that governs you is the shortest one holding the thing you’ll actually need. That’s usually the sign-in record rather than the audit record. So export or screenshot on the day you notice, rather than the day somebody asks. Disputes about what happened in a mailbox surface late, in an insurance question, a client complaint or a professional body’s inquiry. By then the row is gone from every system described above.
When something in the list was not you
Order matters here. Two of these steps undo each other if you take them the wrong way around.
- Change the password from a device you trust. Use a second machine rather than the one you suspect. The FTC’s version of the instruction is worth following literally: “Create a unique and strong password that is hard to guess. Aim for 12 to 15 characters.”
- Sign out everything else. A session that’s already open can survive a password change, and that’s exactly the situation you’re in. Both providers give you a way to end other sessions from the security section of the account. It’s a separate act from changing the password.
- Turn on two-step verification, then check the recovery address and phone. People skip this step, and it decides whether the rest holds. The FTC: “Check your account recovery information and make sure the email address and phone number listed are correct.” An attacker who owns the recovery route can walk back in through the front door, however many times you change the password. Why the mailbox was always the master key is the longer argument for putting two-step verification on the provider account itself.
- Walk the settings list from the section above. Forwarding, filters, delegates, then the rest. This is where the persistence lives, and it’s the one part of this list that finds something after the intruder has gone.
- Withdraw the app grants you can’t account for. Each one is a door somebody was given in your name. The list on your account is almost always longer than you expect.
- Read your own sent folder and your trash. What went out from your address is the part that reaches other people. The trash is where a careful intruder puts the replies, so the thread stays hidden.
- Tell whoever would act on a message from you. The bookkeeper, the bank contact, the client with a payment in flight. Money is what this is for, and a message from your real address is the most convincing instrument anyone will ever aim at them. If a payment was requested or moved, the reporting route and the phone-call rule are both in when an email is written for the AI and not for you. If personal information was taken, the FTC’s recovery process starts at IdentityTheft.gov.
One honest note about the shape of this. Most of the list gets finished by judgment rather than by evidence. You’ll reach a point where the record has run out and you’re deciding under uncertainty about how far to go. That’s normal, and it’s why steps four through seven matter more than the log reading. They stand on their own, whatever the record turned out to hold. They close the doors either way.
What can be taken back, and what cannot
Reversal follows custody rather than severity. A message you’d be embarrassed by is gone the moment it lands. A mailbox somebody emptied in a rage often comes back in full. What decides it is whose hardware the copy is sitting on.
Still in your own mailbox. Deleted mail has a recovery window, and the two platforms measure it differently. Gmail holds a deleted message in Trash for up to 30 days. After that, “The message is permanently deleted” and cannot be recovered (Google, checked September 7, 2026). Google Workspace adds a second window behind that one. In Google’s words, “When the 30-day period after deleting ends, admins have an additional 25 days to restore messages”. After that, “messages are permanently deleted from your Google Workspace account and can’t be restored by an admin or by Google” (Google, checked September 7, 2026). Exchange Online runs shorter by default. Microsoft states that “The default deleted item retention period for Exchange Online is 14 days. You can modify this period for mailboxes up to a maximum of 30 days”, and when it expires “the item is removed from Exchange Online” (Microsoft, checked September 7, 2026).
Fourteen days on one platform against fifty-five on the other is a wide enough gap to be worth knowing which number governs your mailbox. On both, it’s a default an administrator can change. That’s a question you can answer today. On the afternoon it matters, the time to ask has passed.
The pause that gets mistaken for a recall. Gmail’s undo send is a real control, and it’s narrower than people think. The setting is worded exactly right: “Next to ‘Undo Send,’ select a Send cancellation period of 5, 10, 20, or 30 seconds.” (Google, checked September 7, 2026.) It works because the message is still sitting with Gmail. It cancels a send rather than retrieving a message. Thirty seconds is the longest any of it runs for, and that’s the real measure of this instrument. What you spot within half a minute of pressing send is what you catch.
The recall that almost never applies to the message you care about. Outlook has a message recall feature, and that’s where the folk belief that email can be unsent comes from. Microsoft’s own conditions set the boundary: “You can recall an email from new or classic Outlook for Windows or Outlook on the web only if both you and the recipient have a Microsoft 365 work or school email account in the same organization”. The recipient must still have it unopened. Personal accounts, Microsoft adds, sit outside message recall entirely (Microsoft, checked September 7, 2026). A colleague inside your own company’s mail system is in scope. A client sits outside it.
Delivered mail. The copy that matters is on hardware belonging to somebody else’s provider, inside an account that’s theirs rather than yours. No product reaches in there, and any product that could would be able to do the same to your mail on a day nobody asked it to. So the instrument becomes a correction, and the only variable left is speed. A second message in the same hour reads as ordinary correspondence. The identical words on Monday read as a discovery, and the conversation turns from the content to how long it took you to notice.
And nothing un-reads a message. If what worries you is that a thread was seen, rather than that something was done with it, every platform gives you the same answer at every price. Reading stands. What’s left to work on is what happens next.
If a tool was connected while it happened
This changes two things, and both are easy to miss.
The first is that your provider’s record holds the tool’s work and yours in the same column for the period in question, for the reason set out two sections ago. If you’re trying to establish what happened in your mailbox on a particular afternoon, the connected tool’s own log is where the two come apart. Open it alongside the provider record rather than instead of it. On Google Workspace an administrator has a third view of the same question. OAuth log events record which users are using which third-party applications, and “each time a third-party application is authorized to access Google Account data” (Google, checked September 7, 2026). They’re held for six months like the rest.
The second is that stopping a tool and reversing a tool are two different acts, and people reach for the wrong one about half the time. Withdrawing the grant at your provider ends everything from that moment forward, and it leaves what already happened exactly as it is. Undo works the other way. It puts back something already done, and the tool carries on afterwards. They answer different questions, so you’ll often want both. Where the switch lives, and why it’s the one control that stays with you rather than with a vendor, is where your email credentials are kept, and what a reversal reaches is undoing what Point did.
One habit to keep while you’re working through it. Handle a suspicious message yourself, rather than handing it to an AI tool to ask whether it’s genuine. That instinct is common, and it’s wrong for two separate reasons. Both are in when an email is written for the AI and not for you.
What Point’s record shows, and what it can put back
Point is an AI email client, so the whole of this page applies to a mailbox with Point connected. The two halves land in different places.
- The provider’s record stays the provider’s job. Point’s log says what Point did. Who reached your Google or Microsoft account is answered on the pages named at the top of this one, and those are the pages to read for it.
- What Point did is written down completely. The benefit inventory puts it in one sentence: “A clear log shows every action taken on your behalf, and what Point did for you can be approved, turned down or reversed.” Work done at a setting you raised produces a row exactly as work you approved does.
- A row is a sentence with a time, and it opens. You get the action, the message it touched one link away, and the underlying entry beneath the plain wording. That last one is there for the day you’d rather check the record than take a summary on trust. The activity log behind every action is where the reading habits live.
- Undo hangs off the row rather than off a strip that fades. That’s what makes it usable on Thursday about something that happened on Tuesday, and the actions most worth reversing are the ones nobody was watching.
- A reversal adds a line rather than erasing one. The action and the taking back of it stand in the record together, each with its own time. That’s the property that makes the record worth producing later.
- Reversal reaches what stayed in systems you own. A thread Point filed comes back. Point writes those decisions into your real mailbox rather than a private view of one, so the reversal travels the same road back. A delivered message sits outside that boundary. Point leaves sent mail where it landed, as every product does, and undoing what Point did sets out where the line falls.
- How much could ever need reversing is a setting you hold. The autonomy setting is kept separately for each kind of action, and every kind starts on review. Out of the box, Point prepares and waits. Setting how much your inbox does on its own is where each position is argued out, and approving anything new before it acts covers the gate in front of a kind of work that’s new to Point.
- Two handles end the connection, and only one is Point’s. Disconnecting inside the product is the ordinary route. Withdrawing the authorization at Google or Microsoft is the one that still works on a day you’ve stopped trusting anything the product tells you.
- A record follows the business it belongs to. If you operate more than one, each keeps its own feed, which is keeping one business isolated from another.
What sits on the other side of the connection, and how long each piece of it lives, is where your mail goes when AI reads it. The full inventory of what Point would be doing on your behalf is on the benefits page.
Common questions
How do I check whether someone else has been in my email?
There are four records, and the one to look at is the one that matches your account. A personal Gmail account keeps its history behind the last account activity line at the bottom of any Gmail page on a computer. It shows the last 10 IP addresses and approximate locations, the access type for each, and whether another session is open right now. A personal Microsoft account keeps 30 days of the same material on its recent activity page. A work account carries your own sign-in history on the my sign-ins page, and the fuller record belongs to whoever administers the mail. Whichever one you land on, read the access type column before the location. An IMAP or POP row on an account that has never used a mail program says more than a city you half recognize.
Does an email activity log show what someone read?
No, and the same is true of every mail system. Every one of these records is a record of access: which session, from which address, at what time, through what kind of connection. Which messages were opened sits outside all of them. That’s why a suspected intrusion is worked out from what was reachable rather than from what was seen. The useful response is to close the standing doors: forwarding rules, filters, delegates and connected app grants. The log has already told you everything it holds.
How far back does email login history go?
It depends on the account, and the range is wide. A personal Gmail account gives you ten rows rather than a period of time, which on a busy account can be a day and a half. A personal Microsoft account gives 30 days. A Google Workspace administrator gets 6 months of sign-in, OAuth and Gmail log events, with Email Log Search limited to 30 days for delivery status. Microsoft 365 gives seven days of Entra sign-in logs on the free tier and 30 days on P1 or P2, and Microsoft states that upgrading is not retroactive. Take the screenshot on the day you notice something. Each of these windows is fixed once it has passed.
Can an email be unsent after it has been delivered?
No. Two narrower things exist, and they get confused with it. Gmail’s undo send holds your outgoing message for a cancellation period of 5, 10, 20 or 30 seconds, and it works because the message is still with Gmail. Outlook’s message recall works only where both you and the recipient have a Microsoft 365 work or school account in the same organization, and where the recipient still has it unopened, so a message to a client stays outside it. Once mail is delivered, the copy sits inside somebody else’s account on somebody else’s hardware, and the remaining instrument is a correction sent quickly.
I use an AI email assistant. Does its log replace my provider’s?
No. The two records answer different questions. Your provider knows who reached the account and when. The assistant’s log holds the reason behind each action, and the sign-ins stay with the provider. The complication worth understanding is that a tool you authorized appears in the provider’s record as an ordinary authorized session, so on a connected mailbox the access record holds your work and your software’s in one column. Keep reading both, and if you suspect an intrusion, open them side by side for the same afternoon.
The short version
- Four accounts, four pages. Personal Gmail keeps the last 10 addresses behind the details link at the bottom of the page. A personal Microsoft account keeps 30 days. A work account gives you your own sign-in history on the my sign-ins page, and the deep record belongs to whoever administers the mail.
- Every one of them records access, and reading leaves a trace in none of them. Treat a strange location as a reason to look further rather than as a finding. Read the access type column first.
- The break-in ends. The forwarding rule, the filter, the delegate and the app grant carry on, and they survive every password change. Google’s own compromised-account list is the checklist to walk, and forwarding and filters are the two that cost real money.
- Retention decides what you can show later, and the shortest window is usually the one that matters. Screenshot on the day you notice. Seven days, ten rows and 30 days all run out before a dispute surfaces.
- Change the password from a device you trust, sign out the other sessions, fix two-step verification and the recovery route, then walk the settings. That last step is the one that finds something after the intruder has left.
- Reversal follows custody. Gmail holds deleted mail 30 days and a Workspace administrator gets 25 more. Exchange Online defaults to 14 days and can be set as high as 30. Delivered mail sits outside all of it.
- Undo send is a pause of up to 30 seconds rather than a recall. Outlook’s recall covers a colleague in your own organization, and a client stays outside it. After delivery, speed is the instrument you have.
If you came here on the way to deciding whether to put an AI tool on a mailbox full of client business, what to check before you connect your inbox is the twenty minutes that come first. The same two instruments come up from the other end in a record of what it did, and a way back, as a question about trust rather than about intrusion.