Fix Fake Login Notification Emails From Unrecognized Devices

Got an email saying someone logged into your account from a weird device? Don't panic — it's almost always a scam. Here's how to check and stop it for real.

You're sitting there, phone buzzes, email pops up: "New login from an unrecognized device" — Mac, Windows, some phone you've never seen. Heart rate jumps. You're not alone. Everyone gets these. 99% of the time it's a scam, but the 1% where it's real requires a quick check. Let's fix it now.

The Real Fix First – Check Your Actual Login History

Do not click any link in the email. Not even the "This wasn't me" button. That's how they grab your password. Instead, go directly to the service's website yourself.

  1. Open a new browser tab. Type https://myaccount.google.com/device-activity for Google, https://account.microsoft.com/security for Microsoft, or https://www.facebook.com/settings?tab=security for Facebook.
  2. Look for a section called "Recent activity" or "Login history". It's usually under Security settings.
  3. Check the device, location, and time. If you see a login you don't recognize — a weird IP or a device you never owned — that's real. If the email says a login happened but you see nothing in the real history, the email is fake.
  4. If you see a real unknown login: change your password right there. Enable two-factor authentication (2FA) if you haven't. Log out all other sessions.
  5. If history is clean: mark the email as phishing. Done.

Why This Works

What's actually happening here is simple: scammers send these emails from fake addresses that look like the real service. The email says security@google.com but if you check the full headers (usually by clicking "Show original" or "View details" in your email client), the real sender is something like security@phishsite123.ru. The link in the email goes to a page that looks identical to the login page. You type your password, and they steal it. Then they log in for real and drain your account or send spam from your name.

The reason step 3 works is that the real service keeps a server-side log that the scammer cannot touch. If the email was legitimate, the login would show in that history. If it doesn't show up, the email is a spoof. No exceptions. Scammers can't fake server logs. They can only fake the email you see in your inbox.

Less Common Variations of This Scam

  • "Security code" trick: You get a notification saying someone tried to log in, plus a real 2FA code. They're hoping you'll panic and send them the code. Never share any code with anyone who asks, even if they say they're support. Real support never asks for your 2FA code.
  • Apple ID scam: Email says "Your Apple ID was used to sign in on a Windows PC." Same deal — go to https://appleid.apple.com and check login history there.
  • Instagram / LinkedIn / Twitter: They all have a similar pattern. The scam email looks official but the URL in the link is slightly different — instagr4m.com or linkdln.com. Hover over the link before clicking to see the real destination.
  • Bank login alerts: Your bank might send real login notifications, but never ask you to click a link to verify. Real banks tell you to call them if something looks wrong. If the email says "Click here to review your recent activity" and you didn't just log in, it's fake.

How to Prevent This From Happening Again

  • Use a password manager — it won't autofill on fake login pages because the URL won't match. That's your first clue.
  • Enable two-factor authentication (2FA) — preferably using an authenticator app like Google Authenticator or Authy, not SMS. SMS 2FA can be intercepted via SIM swapping.
  • Check email sender headers regularly — Gmail and Outlook both have a "Show original" option. Look for SPF, DKIM, and DMARC results. If they say FAIL, the email is forged.
  • Never reply to these emails — even to say "stop." That tells the scammer your email is active and you'll get more of them.
  • Report phishing — in Gmail, click the three dots > Report phishing. In Outlook, click Junk > Report as phishing. This helps train the spam filters for everyone.
Bottom line: if an email scares you, don't click. Go straight to the service yourself. Real threats show up in the server logs. Everything else is noise.
Related Errors in Cybersecurity & Malware
0X80092027 Fix CRYPT_E_NO_VERIFY_USAGE_DLL (0x80092027) Error 0X00000511 ERROR_INCOMPATIBLE_SERVICE_PRIVILEGE (0x00000511) Fix 0X0000216F Fix ERROR_DS_SRC_DC_MUST_BE_SP4_OR_GREATER (0X0000216F) 0XC0000388 Status_Downgrade_Detected 0xc0000388: Real Fix

Was this solution helpful?

EP
Erropedia Team
Tech Support Editors
The Erropedia editorial team researches and documents real-world tech errors from across Windows, Linux, macOS, networking, databases, cloud platforms, and more. Every solution is reviewed for accuracy and updated as software and systems evolve.