Turning alerts on takes a few minutes. Doing it well requires understanding a principle almost nobody applies: the alert has to arrive somewhere that does not depend on the account it is watching.
This guide starts there, because it is the difference between a useful configuration and one that merely gives the impression of being one.
It puts into practice the recommendation account login alerts.
The principle: the independent channel
Picture the most common configuration: your email account’s security alerts arrive at your email.
If somebody signs in to that account, they receive the alert before you do — and delete it. The system worked perfectly, and you saw nothing.
| Account watched | The wrong destination | The right destination |
|---|---|---|
| Main email | That same email | Phone, or a second email |
| Bank | Email only | Phone + the bank’s app |
| Social networks | Main email | Phone + a notification in the app |
| Password vault | Main email | Phone + a second email |
The rule in one line: the alert has to travel on a channel that whoever compromised the account does not control.
In practice that almost always means the phone — as an app notification or a message — because it is the channel most independent of online accounts.
Step 1 — The main email
It is the compulsory starting point, because it is the recovery key to everything else.
Where to look. In the account area, look for a section called “Security”, “Sign-in and security” or “Protection”. Inside it you typically find:
- Recent activity or Devices — the list of sessions;
- Security alerts or Notifications — what to report and where;
- Recovery methods — where to check there are no entries that are not yours.
What to turn on. Everything available, in particular: sign-in from a new device, sign-in from an unusual location, password change, change of recovery details, the second factor turned on or off.
Where to have them arrive. Add your phone number as a security contact and, if the service allows it, a second email address — preferably with a different provider.
The final check. Sign in from a device you do not normally use and check the alert really arrives, and where. It is the only way to know whether the configuration works.
Step 2 — Bank and payment services
Here alerts are often already on by obligation, but three things are worth checking.
That they are on for sign-ins too, not only transactions. Many default configurations report payments but not entries: the first useful signal is the sign-in.
That they arrive as an app notification, not only by email. It is the quickest channel and the hardest to intercept.
That the amount threshold is not too high. Some settings notify only above a certain figure: test transactions are typically for the smallest amounts, and those are the ones you want to see.
On the same screen, take a look at the list of authorised devices and remove those you no longer use.
Step 3 — Social networks and messaging
They are often overlooked because they seem less critical. In fact an unauthorised sign-in to a social account produces quick relational damage — messages to your contacts, requests for money in your name.
What to turn on. Alerts for unrecognised sign-ins, notifications in the app, and — where available — the feature listing active sessions with location and device.
A detail to watch. On some platforms sign-in alerts arrive as a message inside the platform itself. That is the worst case: whoever has the access reads them. Look for the option to receive them by text or email as well.
Step 4 — Document storage and password vault
They are the accounts holding the most sensitive material, and they often have the most neglected configuration.
For cloud storage: turn on sign-in alerts and, if available, alerts for file sharing — it is how documents leave without the account showing as compromised.
For the password vault: alerts for access to the store, and for export. An export you did not request is the most serious signal a vault can send.
Step 5 — The contact that depends on nothing
A step worth doing once.
Check the phone number on all your main accounts. It is the most independent contact, but it is also the one people forget to update when they change number.
Consider a second, dedicated email, used only as a security contact and for nothing else. It receives no newsletters, it is known to no commercial service, it appears in no breach. It costs five minutes to create and it changes the robustness of the whole configuration.
Watch out for the vicious circle. If the second email has the first as its recovery, it is not independent: they are the same account with two names. Check that.
How to handle alerts without being swamped
It is the reasonable objection to this recommendation: turning everything on brings many notifications, and many notifications become noise.
A few criteria for keeping it sustainable.
Do not turn on alerts for ordinary activity. Many services offer notifications about things that are not security — successful sign-ins from your usual device, weekly summaries. Those should be turned off: they are what makes the others invisible.
Separate the channels. Security notifications on the phone, everything else by email. If an alert arrives on the phone, it is something worth attention.
Do not create archiving rules. It is the natural reaction to annoyance, and it produces exactly the blindness the alert was meant to avoid.
Accept the false positives. An alert for a sign-in of yours from a new device is not a system error: it is proof it works.
What to do when an alert arrives
Three steps, always the same.
1. Do not click the link in the message. Ever. Fake security alerts are among the most widespread phishing messages precisely because they exploit that reflex.
2. Go to the service yourself — opening the app or typing the address — and find the activity or devices section. If the alert was real, the information is there.
3. If the sign-in is not yours: revoke the session, remove any configurations that are not yours, then change the password. In that order.
If the sign-in is yours — a trip, a new device, a different network — nothing needs doing. It is useful to make a mental note, though: you are learning what your normal sign-ins look like, and it is that reference point that makes an anomaly recognisable.
The monthly check: five minutes covering the rest
Alerts do not see everything — the guide above explains why. The periodic check covers the remaining space, and it takes less time than people think.
What to look at, in this order.
- Forwarding rules and mail filters. Thirty seconds. It is the configuration no alert reports and that keeps working on its own.
- Recovery methods. Phone numbers and email addresses associated with the account. Every entry should be yours and recognisable.
- Connected devices. Close the sessions you do not recognise and those of devices you no longer use.
- Authorised applications. Remove the services you do not use: every active authorisation is access that does not require your password.
- The recent sign-in log. A quick look at the last ten: devices, times, locations.
On which accounts. The three or four that count: main email, password vault, bank, document storage. The others can wait.
How often. Once a month is enough. Tie it to something you already do — the bank statement, the first Monday, the day a subscription renews — because a check that depends on remembering does not survive two months.
What to do if you find something. Do not delete it straight away: look at the whole picture first. If there is a forwarding rule that is not yours, there is probably something else too, and it helps to have the picture before acting — the correct order is to remove all the configurations, then revoke the sessions, then change the password.
A twenty-minute plan
Minutes 1-8 — The main email. Alerts on, phone number verified, a second contact set, recovery methods checked one by one.
Minutes 9-13 — Bank and payments. Alerts on sign-ins as well as transactions, app notifications on, authorised devices cleared out.
Minutes 14-17 — Social and storage. Alerts on, with a destination outside the platform.
Minutes 18-20 — The check. Sign in to one of the accounts from a different device and check the alert arrives. If it does not, the configuration is not the one you thought it was.
The most frequent objections
“I already get too many notifications.” The problem is almost never the security alerts — it is the promotional notifications and the summaries. Turning those off and these on improves both things: less noise and more signal.
“I do not always have my phone with me.” Immediate availability is not needed. What is needed is for the alert to arrive somewhere whoever compromised the account does not control. Reading it two hours later is fine; reading it two months later is not.
“I already use two-factor authentication.” Good, and it is the most effective measure. But it covers sign-in with credentials: it does not cover already active sessions, connected apps, or codes obtained by deception. The alert sees all of those, because it reports the result and not the method.
“If I change number I have to redo everything.” Yes, and that is a good reason to do it once, carefully: note which accounts you put the number on, so that on the day you change you have a list instead of a hunt.
“I do not want to give my phone number to a service.” That is a legitimate concern. In that case the dedicated second email is the alternative: less immediate, but just as independent.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Configuring an independent alert channel |
| Secure Behaviour | Checking alerts at the service, never from the link |
| Awareness | Understanding that an alert informs but does not protect |
Reference level: FL2 — Beginner. The step to FL3 comes when the destination is independent on every main account.
Summary
- The part that counts is not turning alerts on: it is where you have them arrive.
- Email alerts sent to that same email are of no use at all.
- Turn off ordinary notifications: they are what hides the important ones.
- An alert is always checked by going to the service, never from the link in the message.
One thing to do today. Check where your main email’s security alerts arrive. If the answer is “at that same email”, you have found the first configuration to change.
Related content
- Account login alerts — the recommendation this guide comes from
- Security alert warning signs — how to read an alert and tell it from a fake one
- How login detection works — how a service decides a sign-in is unusual
- Impact of an undetected login — why the time to discovery is the decisive variable
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



