GEEKSPIN

  • Tech
  • Reviews
  • Deals
  • Lists
  • TV
  • Food
  • Culture
  • Science
  • Gift Guides
Follow us
  • Facebook
  • Twitter
  • instagram
  • Pintrest
  • YouTube
Search
Menu

GEEKSPIN

You are here:

  1. Home
  2. Tech
  3. Hidden Gmail setting lets strangers read your emails 

Hidden Gmail setting lets strangers read your emails 

Check this Gmail setting to stop strangers from reading your email

by Mary Dada September 29, 2026, 6:00 pm

A forgotten Gmail delegate can retain access to your inbox even after you change your password | ©Image Credit: Unsplash / Justin Morgan
A forgotten Gmail delegate can retain access to your inbox even after you change your password | ©Image Credit: Unsplash / Justin Morgan

You can have a strong password, two-factor authentication and a spotless Google Security Checkup and still have another person quietly sitting inside your Gmail inbox. The culprit is a little-known Gmail feature called delegation. It lets you give another Google account direct access to your inbox without sharing your password.

That person can read your emails, send messages from your account and delete messages. And because they sign in through their own Google account, changing your password or turning on 2FA won’t kick them out. The really sneaky part is that Gmail doesn’t automatically expire the permission, and personal accounts don’t show you when a delegate opens your inbox.

Table of Contents show
Your Gmail password is not the whole story
Someone could be reading your inbox without you knowing
Here is what to do
Changing your password is not a fix

Your Gmail password is not the whole story

Gmail delegation is designed for legitimate situations. Maybe you are sharing a business inbox with a colleague or letting an assistant manage your email. The problem is forgetting that you ever turned it on.

A delegate can access your entire inbox from their own Gmail profile. They don’t need your password, and they don’t have to pass through your two-factor authentication. So if you gave someone access years ago for a project that no longer exists, that permission can just sit there. And Google’s regular Security Checkup won’t necessarily flag it.

Someone could be reading your inbox without you knowing

Delegates can read conversations, send emails and delete messages. Gmail also has a setting that determines whether messages opened by a delegate are marked as read. If that option is enabled, someone could potentially browse through your inbox without leaving the usual “unread” clues.

It gets worse for personal Gmail accounts, as you can’t see whether a delegate has actually been reading your messages. The Last account activity page does not record delegate sessions, either. Google Workspace accounts have more auditing capabilities, but personal Gmail users don’t get the same visibility.

Here is what to do

To start, know that you will need to do this from Gmail on the web. The delegation setting isn’t available in the mobile app. On a desktop or laptop, open Gmail and click the gear icon in the top-right corner. Select See all settings and navigate to Accounts and Import. Find Grant access to your account and look through the list of delegates. If you see someone you don’t recognize or simply don’t need anymore, click delete next to their address. The change takes effect immediately.

While you are there, check the options underneath the delegation section. They control things like whether messages opened by a delegate are marked as read and how messages sent by a delegate appear.

Changing your password is not a fix

Because a delegate uses their own Google account, their access isn’t dependent on your Gmail password. That means changing your password won’t remove them. Enabling two-factor authentication would also not help.

So you can spend five minutes strengthening your login security and still leave an old delegate with access to your inbox. That is why this particular setting is worth checking every so often, especially if you have ever shared an inbox with a coworker, friend, assistant or collaborator.

Source: Make Use Of

You May Also Like

  • Experts warn that malware could potentially bypass Google Chrome-based passkeys on infected devices | ©Image Credit: Unsplash / Adarsh Chauhan

    Experts warn that one virus can unlock every future Google passkey

  • Meta’s Muse AI assistant was hit by a zero-day vulnerability that could allow attackers to abuse its access to a Mac | ©Image Credit: Unsplash / Azamat E

    Experts warn Meta’s new AI assistant exposes Macs to hackers 

  • Security researchers uncover AI-built fake cancellation pages that use flawless design and targeted forms to set up remote-access phone scams. ©Image Credit: Chirayu Trivedi

    New AI scams are tricking people with fake software bills

  • Chrome users should check for the latest update, which includes a patch for a vulnerability already being exploited by attackers | ©Image Credit: Unsplash / Zulfugar Karimov

    Why millions of Chrome users need to manually update their browser today

  • If you flew through Vietnam between 2017 and 2026, your passport details and flight history may have been exposed in a massive cloud leak. ©Image Credit: Unsplash / Oxana Melis

    Massive airline leak exposes 210 million passenger records

  • A staggering trove of more than 150 million driver's licenses has reportedly surfaced on the dark web | ©Image Credit: Facebook / New York State Department of Motor Vehicles

    Over 150m driver’s licenses posted on dark web after data breach 

  • Facebook
  • Twitter
  • instagram
  • Pintrest
  • YouTube

Copyright @2026 CIRBS LLC

  • About
  • Contact
  • Disclosure Statement
  • Editorial Policy
  • Privacy Policy
  • Cookie Policy
  • Choice & Consent
  • Accessibility Commitment
  • Terms
Close
  • Tech
  • Reviews
  • Deals
  • Lists
  • TV
  • Food
  • Culture
  • Science
  • Gift Guides
  • Facebook
  • Twitter
  • instagram
  • Pintrest
  • YouTube

Add to Collection

  • Public collection title

  • Private collection title

No Collections

Here you'll find all collections you've created before.

Mastodon Skip to content