Gmail has a new security tool that could actually just be quite annoying

Gmail
(Image credit: Google)

Your Gmail account is set to get a number of welcome security upgrades, but enabling them might mean jumping through several more hoops than expected.

The changes affect what Google calls "sensitive actions" in Gmail, which cover a number of areas, and if the email service detects anything potentially suspicious, the user will be challenged with a "verify it's you" prompt.

In a blog post, Google said the changes will help boost security for users across the platform, but some may find the alerts over-bearing or even suspicious in themselves, potentially leading to even more confusion.

Gmail security boost

Google categorizes sensitive Gmail actions in several categories, each of which it says can allow threat actors or criminals to compromise a user's account:

  • Filters: creating a new filter, editing an existing filter, or importing filters
  • Forwarding: Adding a new forwarding address from the Forwarding and POP/IMAP settings
  • IMAP access: Enabling the IMAP access status from the settingsEmpty list

If any of these are triggered, users will be sent their verification check, which typically takes the form of a two-step verification action such as approving a notification on their paired device, or entering an SMS code.

If the user fails their verification challenge, or doesn't complete it in time,  they are sent a “Critical security alert” notification on their trusted device (pictured below), which the user can employ to lock down their account.

Gmail security alert

(Image credit: Google Workspace)

The feature will be rolling out to all Google Workspace customers and users with personal Google Accounts now, with no end user action required, although Workspace customers will need to have Google as the identity provider, as SAML is not yet supported. 

The news is the latest security update for Gmail in recent months as Google looks to ensure its platform remains safe for users everywhere. Recently, the company added client-side encryption (CSE), a means of protecting and controlling access to personal or corporate data, to Gmail, helping offer an extra layer of protection, as this should mean that no-one can read sent emails or calendar entries but those in an organization and the recipients. 

More from TechRadar Pro

TOPICS
Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Read more
Isometric demonstrating multi-factor authentication using a mobile device.
Google is ditching SMS - and will now use QR codes for Gmail account authentication
Fraude en ligne phishing
Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
Microsoft is changing the way logins work: here’s what that means for you
Android 15 logo on a phone, in a hand
Google is working on its own version of Apple’s Hide My Email, and you might soon be able to try it yourself
A hand reaching out to touch a futuristic rendering of an AI processor.
Google Cloud unveils new AI Protection security tools, no matter which model you use
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Latest in Security
A computer file surrounded by red laser beams
Free online file converters could infect your PC with malware, FBI warns
Close up of a person touching an email icon.
Criminals are using CSS to get around filters and track email usage
DeepSeek on a mobile phone
More US government departments ban controversial AI model DeepSeek
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
NordProtect logo
Standalone identity theft protection from Nord Security is now available
Latest in News
Volvo Gaussian Splatting
Volvo is using AI-generated worlds to make its cars safer and it’s all thanks to something called Gaussian splatting
Image of Asus ROG Ally running Bazzite/SteamOS
This SteamOS update promises a new future for non-Steam Deck handheld PCs – and I can’t wait
Perplexity Squid Game Ad
New ad declares Squid Game's real winner is Perplexity AI
Pedro Pascal in Apple's Someday ad promoting the AirPods 4 with Active Noise Cancellation.
Pedro Pascal cures his heartbreak thanks to AirPods 4 (and the power of dance) in this new ad
Frank Grimes confronts Homer Simpson in The Simpsons' Homer's Enemy episode
Disney+ adds a new continuous Simpsons stream, so you no longer have to spend ages choosing an episode
Helly and Mark standing on an artificial hill surrounded by goats in Severance season 2 episode 3
New Apple teaser for Severance season 2 finale suggests we might finally find out what Lumon is doing with those goats, and I don't think it's anything good