Changing your email address solves only half the security equation. If an unwanted party previously compromised your old inbox, their device might still hold a valid session token inside your account.
Navigate to Settings and Privacy, select Security and permissions, and tap Manage devices. This dashboard lists every smartphone, tablet, and desktop browser currently logged in, along with location estimates and login dates.
Scan the inventory. If you spot unfamiliar hardware or older phones you sold or discarded, tap the trash can icon beside each entry. Removing a device instantly revokes its session token, forcing that hardware to present primary credentials before it can access your feed again.
Next, return to Security and permissions and review Two-factor authentication. If this protection is turned off, switch it on immediately. Select at least two distinct authentication methods:
- An authenticator app (such as Google Authenticator, Microsoft Authenticator, or 1Password)
- SMS verification codes
- Primary email codes
Using a hardware-backed authenticator app provides superior defense compared to SMS alone. Even if a threat actor intercepts your telecom carrier routing, they cannot generate the rolling six-digit security codes stored directly on your physical device.