A friend messages you: “You just sent me a strange link — was that you?” You haven’t written anything, and yet the message went out from your account. Quite often the explanation lies in a computer with an open session (a sign-in that stays active and doesn’t ask for your password again), in a device linked to your chat account, or in an email rule that nobody remembers creating.
Linked devices on messaging apps are what let you carry on the same conversation across your phone, computer and tablet: a convenience that is also the point where someone else’s access can stay in place without being noticed.
This post lays out the technologies that help you control who can write in your name, with their real advantages and limits, without pointing to any product. It is the technology side of the recommendation on checking messages sent in your name.
How to read this list
First, the mechanism. In most messaging apps your account is tied to a phone number and to a primary device, usually your smartphone. Other devices — the web version in a browser, the desktop application, a tablet — are added as linked devices, usually by scanning with your phone a QR code shown on the new screen. From then on, the new device receives and sends messages as if it were the phone, often even when the phone is switched off. With email and social media, every sign-in creates a session, and some settings (forwarding rules, authorised apps) keep working even after the session has been closed.
The technologies are organised into four functions, the same ones used in the post on what to do if your account is sending messages:
- prevention — stopping someone from linking up in your place;
- detection — noticing that an extra device or rule is already there;
- response — closing access and regaining control;
- governance — keeping things in order over time, especially when devices are shared.
For each one you’ll find the risk it reduces, its advantages, its honest limits, and how complex it is to use.
1. Prevention technologies
Two-step verification PIN
A code you choose yourself, which the messaging app asks for when your account is registered on a new phone, on top of the code sent by text message (SMS).
- Risk reduced: your account being registered on another phone by someone who has obtained your verification code.
- Advantages: the SMS code on its own is no longer enough; it takes a minute to turn on; you can often add an email address to recover it.
- Limits: if you forget it and have no recovery email, reinstalling becomes complicated; it doesn’t protect against devices linked by QR code.
- Example: someone talks you into reading out the code you’ve just received; they try to use it, but the app also asks for the PIN that only you know.
- Complexity: basic.
A second check on top of the password, such as a temporary code or a confirmation on your phone.
- Risk reduced: sign-ins with a password that has been stolen, guessed or reused elsewhere.
- Advantages: it stops most sign-ins even when the password is already known. For choosing the method and the order of your accounts, see the recommendation on protecting accounts with a second factor.
- Limits: it doesn’t close sessions opened before it was switched on; you need to keep your recovery codes safe; the SMS method is the most fragile.
- Complexity: basic.
App lock and confirmation for new links
Unlocking with your fingerprint, face or PIN, required to open the messaging app or to add a new linked device.
- Risk reduced: an unfamiliar device being linked while your unlocked phone is in someone else’s hands.
- Advantages: only you can confirm a new link; it also protects your conversations from being read.
- Limits: not every app offers it in the same way; without a solid screen lock, the protection is weaker.
- Complexity: basic.
Encrypted chat backups
The copy of your conversations saved to the cloud or to a computer, protected with end-to-end encryption (only whoever holds the key can read the data, not even the service that stores it).
- Risk reduced: your chat history being read by someone who gets into the cloud storage where the backup sits.
- Advantages: your chats stay protected outside the app, and can still be restored on a new phone.
- Limits: encryption often has to be switched on manually; if you lose the key, the backup cannot be recovered; it protects past messages, not future ones.
- Complexity: basic.
2. Detection technologies
List of linked devices and active sessions
The section of your settings that shows every device or browser with an open sign-in.
- Risk reduced: unfamiliar devices silently reading and sending messages.
- Advantages: it’s the most direct check there is; it takes a minute; next to each entry there is almost always an option to sign it out.
- Limits: you have to open it yourself; device names are often generic and not always recognisable.
- Complexity: basic.
Sign-in history
The log, available on many email and social media accounts, of recent sign-ins: date, time, type of device, approximate location.
- Risk reduced: sign-ins that happened and were then closed, which the list of active sessions no longer shows.
- Advantages: it helps you work out when a problem began. The post on how to tell if your account was hacked explains which signs to look for.
- Limits: the location is only indicative, and mobile networks or VPNs (services that route your connection through another point) shift it; messaging apps often don’t have one at all.
- Complexity: basic.
New sign-in and new device alerts
Automatic notifications that arrive when a new device is linked to your account or signs in to it.
- Risk reduced: links that go unnoticed for weeks.
- Advantages: they reach you without your having to check anything. How to turn them on and read them is the subject of the recommendation on account login alerts.
- Limits: they arrive afterwards, not beforehand; if there are too many, people stop reading them; a fake alert is a classic phishing trick (a message designed to get you to click or hand over details): always check from inside the app, never through the link.
- Complexity: basic.
Verification codes you didn’t ask for
A message with a registration or sign-in code that arrives without your having done anything.
- Risk reduced: attempts to register your account elsewhere, before they succeed.
- Advantages: it’s a signal that is already switched on: someone has entered your number somewhere.
- Limits: it doesn’t tell you who did it. That code must never be read out or passed on to anyone, not even to a contact who says they received it “by mistake”.
- Complexity: basic.
3. Response technologies
Signing out linked devices and sessions
The option that closes one or all of your linked devices and open sessions, from the panel described above.
- Risk reduced: access that carries on after you’ve noticed the problem.
- Advantages: it’s immediate; a device that has been signed out has to be paired again from your phone. The everyday habit is covered in the resource on how to log out of your accounts.
- Limits: for email and social media it has to be done after changing the password, otherwise anyone who knows it can get back in; it also signs out your own devices, which you’ll need to link again.
- Complexity: basic.
Checking email forwarding rules and filters
The mailbox settings that automatically forward messages to another address, or that move and delete certain messages as soon as they arrive.
- Risk reduced: copies sent elsewhere and replies from your contacts hidden, even after the password has been changed.
- Advantages: it takes a few minutes to check; removing an unfamiliar rule closes a leak that no other measure can see.
- Limits: rules sit in different sections (forwarding, filters, automatic replies) and all of them need looking at.
- Example: you find a filter that sends every email containing the word “strange” straight to the bin: that explains why no contact warned you sooner.
- Complexity: basic.
The panel that lists the applications you’ve given permission to read, send or manage messages on your email or social media account.
- Risk reduced: third-party services writing in your name even after a password change, through a separate authorisation.
- Advantages: it withdraws permissions you’d forgotten about; it’s useful even when nothing has gone wrong. The signs of an app that shouldn’t be there are covered in the post on signs of suspicious connected apps.
- Limits: app names aren’t always clear; it needs to be done calmly.
- Complexity: basic.
Account recovery and re-registration
The official procedures for getting back into an account you’ve lost control of.
- Risk reduced: losing the account and its history for good.
- Advantages: they exist on all the major services; registering your number again on your own phone usually pushes out the other phone that was using it.
- Limits: if the other person has set a verification PIN, you may have to wait several days; only ever follow official channels, never links you receive.
- Complexity: variable.
4. Governance technologies
These become relevant when the devices or accounts aren’t only yours: a family, a small practice, an association, work phones.
Distinct user accounts on the home or office computer, each with its own password.
- Risk reduced: chats and email left open and used by whoever sits down after you.
- Advantages: everyone sees only their own conversations; the profile locks by itself.
- Limits: it takes a little setting up and needs explaining to everyone.
- Complexity: basic.
Automatic sign-out after a period of inactivity
The setting that closes sessions and linked devices on its own when they haven’t been used for a while.
- Risk reduced: old, forgotten sessions that stay open for months.
- Advantages: it keeps things tidy without your having to think about it.
- Limits: it isn’t available everywhere; a device that someone else uses every day is never signed out.
- Complexity: basic.
A few written rules on who links devices to the accounts used with clients, and who looks after the PIN.
- Risk reduced: linked devices belonging to people who no longer work with you.
- Advantages: it clarifies responsibilities and steps before they’re needed.
- Limits: a rule that isn’t followed is worse than no rule at all; too many rules push people to work around them.
- Complexity: intermediate.
A short, recurring check of devices, sessions, forwarding rules and authorised apps, together with an explanation of why it matters.
- Risk reduced: links that pile up over time.
- Advantages: it’s what makes all the other technologies stick; it’s the pillar on which the Cyber Welfare Framework rests.
- Limits: it requires continuity; a one-off check has a short-lived effect.
- Complexity: basic.
Comparison table
| Function | Technology | Risk reduced | Main advantage | Main limit | Complexity |
|---|---|---|---|---|---|
| Prevention | Verification PIN | Registration on another phone | The SMS code alone isn’t enough | Must be remembered or recoverable | Basic |
| Prevention | MFA on email and social media | Sign-ins with a stolen password | Works even if the password is known | Doesn’t close existing sessions | Basic |
| Prevention | App lock | Stolen links | Only you confirm | Depends on the screen lock | Basic |
| Prevention | Encrypted backups | Chat history read in the cloud | Chats protected outside the app | Lose the key, lose the backup | Basic |
| Detection | Device and session list | Unfamiliar devices | Direct check | Generic names | Basic |
| Detection | Sign-in history | Sign-ins already closed | Reconstructs the timeline | Approximate location | Basic |
| Detection | New sign-in alerts | Unnoticed links | Arrive without your looking | Imitated by phishing | Basic |
| Detection | Unrequested codes | Registration attempts | Signal already on | Doesn’t say who | Basic |
| Response | Signing out | Access that carries on | Immediate | After the password change | Basic |
| Response | Forwarding rules and filters | Hidden copies and replies | Closes an invisible leak | Several sections to check | Basic |
| Response | Revoking authorised apps | Sending by third-party services | Withdraws forgotten permissions | Unclear names | Basic |
| Response | Account recovery | Losing the account | Available everywhere | Can take a long time | Variable |
| Governance | Separate profiles | Sessions open to everyone | Each person sees only their own | Needs setting up | Basic |
| Governance | Automatic sign-out | Forgotten sessions | Tidiness without effort | Not available everywhere | Basic |
| Governance | Rules for work accounts | Devices of former colleagues | Clear responsibilities | Ineffective if not applied | Intermediate |
| Governance | Regular review | Links piling up | Makes the rest stick | Needs continuity | Basic |
How to choose
If you’re an individual. A verification PIN on your messaging app, MFA on email and social media, and an app lock if one is available. Once a month, a quick look at your linked devices.
If you’re helping a family member. Open the linked devices and email sessions together, remove anything neither of you recognises, and set up the PIN. One simple rule: verification codes are never read out to anyone, not even to a relative.
If you use messaging apps for work. Keep your personal and work numbers separate where you can; check linked devices whenever a colleague joins or leaves, along with the forwarding rules on the mailbox you use with clients.
A rule of thumb. No technology removes risk on its own. The combination that gives the best result for the effort involved is verification PIN + MFA on your email + a monthly check of linked devices and forwarding rules.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Knowing where to find linked devices, sessions, forwarding rules and authorised apps, and what each entry means |
| Awareness | Recognising that an account lives on several devices, and that access can stay active after a password change |
| Secure Behaviour | Checking links regularly, not only when a contact reports a strange message |
Reference level: FL3 — Autonomous. This is the level at which you know your accounts’ control panels well enough to use them on your own, and to understand which tool is needed at which moment.
Conclusion
A message sent in your name is not your fault, and it is rarely a mystery: usually there is a linked device, an open session or an extra rule, and each of them can be seen and closed. If you’d like to know where to start, the digital resilience self-assessment gives you a reference point.
What to do next. Today, open the list of linked devices in your messaging app and the active sessions on your email: sign out anything you don’t recognise, and turn on the verification PIN if you haven’t already.
Related content
- Checking messages sent in your name — the recommendation this belongs to
- What to do if your account is sending messages — how to put these technologies into practice, in order
- Messaging account takeover — the attacks these technologies are designed against
- Signs of messages you did not send — what to look out for when something doesn’t add up
- Risks of your account being used for spam — what is at stake when someone writes in your place
Related resources
Short guides from the Resources section, for anyone who wants to focus on a single aspect:
- The Final Step: How to Log Out of Your Accounts
- Multi-Factor Authentication: Which Accounts, In Which Order
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



