The Apps That Can Read Your Mail

Time: ten minutes a year. Repeat: whenever you stop using an app, and immediately after any break-in.

Revoke the access instead of deleting the app

Open your provider's list of applications with access to the account and revoke the ones you no longer use. Deleting the app from your phone does not do this.

Permission was granted to the developer's service, not to the icon on your screen. The service keeps a token that identifies it to your provider, and that token keeps working until you withdraw it or the provider expires it. A mail reader you tried for a weekend in 2021 can still be authorised to read everything that has arrived since, and nothing about your phone tells you so.

Tell apart three things that look identical

Learn which of the three you are looking at, because only two of them touch your mail and they are revoked in different places.

An app password is a long string your provider generates so that an older program can sign in with something other than your real password. It usually grants full mailbox access and it bypasses the second factor, because the program asking for it cannot show you a prompt.

A granted authorisation is what happens when you click a consent screen listing what an app wants: read your mail, send as you, see your contacts. No password changes hands. The app holds a token instead, and that token is what you revoke.

Signing in to a third-party site with your mail account is the one people confuse with the other two. That site learns your address and usually your name, and it can check that you are still you. It does not get your mail. Revoking it logs you out of that site; it does nothing to your mailbox.

Assume a read grant means everything

Treat any app with read access as having seen the entire mailbox, including things you would never have shown it deliberately.

There is no partial read. An app permitted to read your mail can read the password reset links, the codes from your bank, the messages from your doctor, the archive from six years ago and every attachment. Most apps do exactly what they advertise. The point is that the permission does not distinguish between a well-behaved app and one that changed hands after the founder sold it, and you are not told when that happens.

Send access adds the ability to write mail that comes from you, with your address in the sender field and no sign of a third party. That is worth more to an attacker than reading, and it is why an unexpected grant with send permissions is treated as a break-in rather than as clutter, using the order that keeps the damage contained.

Find the list without guessing at menu names

Look in your account settings, not in the mail interface, and search the settings for words rather than following remembered clicks.

The useful words are security, privacy, connected, third-party, apps with access, linked accounts, and permissions. Every large provider has this list and every one of them has moved it at least once, renamed it, or split it into two pages, which is why no honest guide gives you a click path that will still be right next year. If your provider offers a search box inside settings, type one of those words into it and you will land on the page in a few seconds.

While you are there, look for a separate page listing app passwords. It is almost never the same page as the authorised apps, and forgetting it is the most common way a cleanup ends up incomplete.

Kill the app passwords first

Delete every app password you cannot immediately account for, before you touch anything else on the list.

They come first for a reason: they skip the second factor, they rarely expire on their own, and they are typically created once and forgotten. The ones people find are for a mail program on a laptop replaced two jobs ago, a printer with a scan-to-mail feature, a backup script, an old phone. Each is a working key.

There is no way to tell from the list what a given app password is doing, which is the argument for deleting first and rebuilding what breaks. Nothing is lost permanently: you can generate a new one for the program that genuinely needs it, in a minute, once it complains.

Expect three things to break, and put them back

Revoke first, repair afterwards, because the fear of breaking something is the only reason most of these lists are years out of date.

Mail on your phone stops syncing, and you sign in again through the normal prompt. A calendar or contacts sync goes quiet, and it comes back the same way. An automation you set up once stops firing, and you either rebuild it or notice you had stopped caring about it long ago.

One thing genuinely worth checking before you clear the list: a mail program holding a local copy of your archive over a standing connection. Revoking its access does not delete what it already has, but it does stop it refreshing, and if that program was your only copy, sort out a backup you have actually tested before the cleanup rather than after.

Keep the list short from now on

Grant access as narrowly as the consent screen allows, and go back through the list once a year.

Read the consent screen for the line about sending. Plenty of apps ask for send access when their function only requires reading, and some providers let you decline the extra permission and continue.

Revoke on the way out, not later: when you uninstall an app, when you stop using a service, when you sell a device. Revoke everything after any incident, since a token granted by an intruder is invisible to a password change and is the most common thing left behind after a rushed cleanup, which is why it appears again in the settings worth fixing while nothing is wrong.

At work, this list is usually not yours to manage. Your employer's administrators can approve, block and revoke app access on the whole domain, and they can see what you approved, which is one more reason the work mailbox is not the place for personal accounts.

Notice how much of this you avoid by not connecting anything

The mailbox that has never been linked to an app has no list to audit, and that is a real advantage rather than a rhetorical one.

The temporary inbox this site opens is deliberately in that category: it holds no attachments worth syncing, it lives in a browser tab, and it deletes itself. Nothing to authorise, nothing to revoke, nothing left behind. It is a small illustration of the general rule that the safest permission is the one that was never granted.

The checklist

  • Delete every app password you cannot account for, before anything else.
  • Revoke authorised apps you no longer use, including the ones you recognise.
  • Check the app password page separately; it is rarely on the same screen.
  • Reconnect mail, calendar and contacts through the normal sign-in prompt when they break.
  • Read the consent screen for send permission, and decline it where the app does not need it.
  • Repeat once a year, and immediately after any suspected break-in.

Read next

All guides