Guides

Suspicious Login and Unknown Device Alerts: How to Respond

A suspicious login or unknown device alert on your business email can be genuine or a phishing lure. How to tell which, what to check, and when to escalate.

"New sign-in from an unrecognised device" is one of the most useful alerts a mail provider can send, and also one of the most copied by phishers. The correct response is the same either way: do not touch the email, go to the account directly, and look at the facts. Here is a ten-minute routine that separates a genuine alert from a lure and tells you when a real alert needs action.

Quick answer

Never act through the alert itself. Open a new browser tab, type your provider's address, sign in, and look at the account's own activity or devices page. If it shows a login you do not recognise, end that session, change the password, and enable two-factor authentication. If it shows nothing unusual, the alert email was probably phishing; report it and delete it.

Is the alert real or a lure? Check these

  • The From address. Genuine alerts come from your provider's own domain. A display name of your provider with a random domain behind it is the giveaway.
  • The link. Hover or long-press. A genuine alert links to your provider's site; a lure links to a lookalike or a shortened URL.
  • The ask. Genuine alerts say "if this was you, no action is needed". Lures demand you "verify", "confirm", or "secure your account now" through their link.
  • The details. Real alerts typically name a device type, an approximate location, and a time. Lures are vague or wildly specific in ways your provider could not know.
  • Timing. Did you or a teammate just add a phone, reinstall a mail app, change networks, or travel? Genuine alerts follow those events closely.

The ten-minute routine

  1. Close the email. Do not click anything in it.
  2. Open a new tab and go directly to your mail provider's sign-in page by typing the address or using a saved bookmark.
  3. Find the security, activity, or devices page. Read the list of recent sign-ins and connected devices.
  4. For each entry, ask: is this a device I own, a location I or a colleague have been in, an app I installed? IP-based locations are often a city or two off, so a nearby city is normal; another country is not.
  5. If everything is yours, the alert was either accurate and harmless or a phishing lure. Report the lure to your security address and delete it.
  6. If something is not yours, end that session, change the password to a generated one, revoke app passwords, enable two-factor authentication, and follow the account-hacked recovery steps: check rules, forwards, recovery contacts, and sent mail.

Alerts that are almost always benign

  • A login from your own mail app immediately after an app update or phone restore.
  • A sign-in from your office IP that a provider labels with a different city because the ISP registers it elsewhere.
  • A "new device" that is actually a new browser or a cleared cookie on the same laptop.
  • A login that matches a colleague who legitimately uses the same shared role mailbox, which is itself a reason to give people individual logins.

Alerts that need escalation today

  • A successful sign-in from a country nobody on your team is in.
  • A login at 3 a.m. local time from an unfamiliar device, followed by any change to rules or recovery settings.
  • Repeated "sign-in attempt blocked" alerts. Blocked attempts are not a breach, but they mean someone has your password and is being stopped only by the second factor. Change the password.
  • Any alert on the owner, finance, or admin mailbox, which deserve a lower threshold for action.

Reduce the noise so real alerts stand out

Alert fatigue is how genuine ones get ignored. Give every person their own mailbox rather than sharing a login, so each account has one device pattern. Name devices and app passwords after the device and the person. Keep the number of connected apps small. With OquMail, each person on your team can have their own mailbox on the free plan (up to 15), and any mail app connects over IMAP on 993 and SMTP on 587, so there is no reason for two people to sign in as one account.

Common questions

Should I click "this was not me" in a genuine alert?

Genuine alerts often include such a button, and it usually works. The safer habit is still to go to the account directly and perform the same action from the security page, so you never have to judge a link under pressure.

What if I cannot find a login activity page?

Check your provider's help documentation for the exact path; the feature and its name vary. If your provider offers no activity view at all, rely on the other controls: a strong unique password, two-factor authentication, and a monthly check of rules and forwards.

Can I turn these alerts off?

Do not. They are free early warning. Reduce false positives with individual logins and named devices instead.

Free business email on your own domain

OquMail gives you up to 15 mailboxes on your domain — free — with guided SPF/DKIM/DMARC, webmail, IMAP/SMTP for any mail app, and a send API. Most teams are live in under fifteen minutes. Start at oqumail.com.

Get started free

Ready for business email on your domain?

Up to 15 free mailboxes, guided DNS, webmail, and a transactional API — start in minutes.

Create your free workspace