Auditing Third‑Party App Access to Your Email and Calendar

Your email and calendar sit at the center of your digital life. They contain travel plans, invoices, password reset links, meeting invites, contact details, and private messages. When you sign in to third‑party apps using Google, Microsoft, Apple, or a custom email provider, you often grant ongoing access—sometimes far broader than you realize. This guide shows you how to audit, interpret, and revoke third‑party access for major providers, what each permission really means, how to spot risky apps, and how to prevent future exposure.

Why Auditing App Access Matters

Third‑party access is commonly granted through OAuth (“Sign in with Google/Microsoft/Apple”). It’s convenient and safer than sharing your password, but it can still expose sensitive data if you approve broad permissions or forget to remove apps you no longer use. Risks include:

  • Account takeover amplification: If an app is compromised, attackers may gain access to your messages, contacts, and calendars.
  • Silent data exfiltration: Apps with read or manage permissions can copy or forward messages without obvious signs.
  • Business email compromise (BEC): Calendar details and email threads can help craft convincing spear‑phishing campaigns.
  • Privacy creep: Over time, unused apps accumulate, expanding your digital footprint unnecessarily.

What Permissions Really Mean

App consent screens list scopes—specific capabilities the app requests. Common examples:

  • View your email address / basic profile: Lower risk; used for identity. Still remove if unused.
  • Read your email / read your mailbox: Lets the app access message content and attachments.
  • Send email on your behalf: Can send messages as you; dangerous if misused.
  • Read, compose, send, and permanently delete your email: Full control; highest risk.
  • Manage mailbox settings or filters: Can auto‑forward mail to external addresses.
  • Read your calendars / events: Reveals attendees, locations, topics, and links.
  • Create, edit, and delete calendar events: Can inject malicious links or meeting invites.
  • Access contacts: Exposes names, emails, phone numbers, and notes.

Rule of thumb: If an app can send, delete, or manage settings/filters, treat it as high risk. If it can only see your basic profile, it’s relatively low risk.

Before You Start: Prepare for a Clean Audit

  • Set aside 15–30 minutes: You’ll review each provider you use.
  • Have a list of accounts: Google, Microsoft (Outlook/Office), Apple, and any other email provider or calendar service (e.g., Fastmail, Proton, Yahoo, Zoho).
  • Decide your standard: Keep only apps you still use and that request the minimum necessary permissions.
  • Get ready to re‑authenticate: Some services log you out to confirm changes.

Audit Steps for Major Providers

Google (Gmail and Google Calendar)

  1. Go to Google Account at myaccount.google.com and sign in.
  2. Open Security, then select “Third‑party access” or “Manage third‑party access.”
  3. Review apps and services that have account access. Click each app to view scopes such as:
    • “Read, compose, send, and permanently delete your email from Gmail.”
    • “See, edit, share, and permanently delete all the calendars you can access using Google Calendar.”
    • “See your primary Google Account email address” (lower risk).
  4. Remove access for apps you don’t recognize, don’t use, or that request overly broad permissions.
  5. Open Gmail Settings > See all settings > Filters and Blocked Addresses, and Forwarding and POP/IMAP:
    • Delete unknown filters, forwarding addresses, vacation responders, or POP/IMAP connections.
  6. Open Google Calendar Settings > Settings for my calendars > Access permissions and Integrate calendar:
    • Ensure calendars aren’t public unless intended and remove outdated shared access.

Microsoft (Outlook.com, Microsoft 365)

  1. Go to account.microsoft.com, sign in, then open Privacy > Apps and services.
  2. Review apps with access to your account and select any app to see details like:
    • “Read your mail,” “Send mail as you,” or “Read and write to your calendar.”
  3. Revoke access for anything unfamiliar, unused, or with excessive scopes.
  4. In Outlook on the web, go to Settings > Mail:
    • Check Rules, Sweep rules, and Forwarding for unknown entries.
    • Check Mobile devices and Connected accounts for old syncs.
  5. In Calendar (web), review shared calendars and publishing links; remove outdated sharing.

Apple (iCloud Mail and Calendar)

  1. On a browser, sign in to appleid.apple.com.
  2. In the Security or Sign-In & Security sections, review Apps Using Apple ID and third‑party sign‑ins.
  3. Revoke any unused app permissions. Note: Apple’s “Hide My Email” can reduce exposure when signing up for new apps.
  4. On iPhone/iPad: Settings > Privacy & Security > Calendars and Contacts:
    • Review which apps can access your calendars and contacts; toggle off any you don’t trust.
  5. In iCloud.com Mail, check Settings for rules/forwarding; remove any you didn’t create.

Other Email Providers (Fastmail, Proton, Yahoo, Zoho)

  • Fastmail: Settings > Password & Security > Connected services and API tokens. Revoke old app passwords and tokens. Check Rules and Aliases for forwarding.
  • Proton: Settings > Security > Sessions and Devices; Settings > Go to App passwords/Bridge if used. Review Filters and Addresses/Identities.
  • Yahoo: Account Security > Manage app passwords/connected apps. In Mail settings, review Filters and Forwarding.
  • Zoho Mail: Settings > Integrations/Connected apps; Security > App passwords. Check Email Forwarding and Filters.

How to Judge Risk: A Simple Decision Framework

Use this checklist on each app you find:

  1. Do I still use it? If not used in the last 60–90 days, remove it.
  2. What does it need vs. what it asks for? If a calendar tool requests full email deletion rights, that’s a mismatch—remove it.
  3. Who makes it? Prefer reputable vendors with clear privacy policies and active support; be cautious with unknown publishers.
  4. What data leaves my account? Check if the app stores messages, events, or contacts on its servers.
  5. If compromised, what could happen? Could it forward all your emails? Invite colleagues to malicious meetings? If yes, remove or reduce scopes.

Reduce Exposure: Least‑Privilege Alternatives

  • Limit to read‑only where possible: Many integrations offer a read‑only option—choose it unless you truly need write access.
  • Use per‑feature scopes: If an app lets you disable email sending or calendar modification, do so.
  • Prefer local or client‑side tools: Browser extensions or desktop apps that don’t sync to a third‑party server often expose less data.
  • Use separate accounts: Connect third‑party apps to a less‑sensitive email/calendar when feasible.
  • Create filtered mailboxes: Forward only specific categories instead of your entire inbox.

Detecting Abuse: Signs Your Email or Calendar Is Being Misused

  • New forwarding addresses, rules, or filters you didn’t create.
  • Outbox or Sent items contain messages you didn’t send.
  • Calendar events appear or change without your action.
  • Colleagues receive unexpected invites with links or attachments.
  • Security alerts about new sign‑ins or consent grants you don’t recognize.

What To Do If You Find a Suspicious App

  1. Revoke access immediately from your account’s third‑party access page.
  2. Remove hidden persistence: Delete unknown filters, forwarding rules, and delegated access.
  3. Change your account password and verify multi‑factor authentication is enabled with a strong method (hardware key or app‑based TOTP).
  4. Check connected devices and sessions and sign out everywhere if needed.
  5. Notify affected contacts if messages or invites may have been sent from your account.
  6. Monitor for downstream impact: Watch for password‑reset emails, bank alerts, or new credit inquiries.

Enable Strong Protections After the Audit

  • Turn on multi‑factor authentication (MFA): Prefer authenticator apps or security keys over SMS.
  • Set up security alerts: Opt in to notifications for new sign‑ins, new app consents, and forwarding rule changes.
  • Regularly review access: Put a quarterly reminder on your calendar to re‑audit third‑party access.
  • Use aliases or masked emails: Reduce exposure by giving each app a unique address so you can disable it without impacting your main inbox.
  • Harden calendar sharing: Keep calendars private by default; share with named people only; disable public links.

Privacy‑Preserving Workflows for Common Use Cases

Scheduling Tools

  • Grant read‑only calendar access when possible; if write access is needed, limit to a single sub‑calendar dedicated to scheduling.
  • Disable contact uploads; paste links manually or use one‑time invites.

Email Productivity Apps

  • Choose tools that process messages locally or via browser with minimal scopes.
  • If server‑side processing is required, restrict to specific labels/folders and remove “send as you” permissions.

Travel and Expense Apps

  • Use mailbox rules to auto‑forward only travel receipts to a unique alias rather than giving full mailbox access.
  • Periodically delete the forwarding rule and alias when the trip or project ends.

Make It a Habit: A 10‑Minute Quarterly Checklist

  1. Review third‑party access on Google/Microsoft/Apple and your primary email provider.
  2. Delete unknown or unused apps; reduce scopes where possible.
  3. Check email rules, forwarding, delegates, and connected devices.
  4. Review calendar sharing links and remove public access.
  5. Confirm MFA and security alerts are enabled.
  6. Create or update a note with the apps you intentionally allow (date, scopes, purpose).

When to Add Extra Monitoring

If you discover broad email access or suspicious forwarding, it’s smart to increase monitoring for a period. Email is the gateway for password resets and financial communications. If an attacker accessed your mailbox, they may attempt account takeovers or open fraudulent lines of credit. Consider enabling dedicated credit and identity monitoring to catch unusual activity early. A practical resource for this is available here: privacy, credit monitoring, and identity‑protection.

FAQ

Does revoking access break the app?

Yes—until you re‑grant permissions. If you’re unsure, remove access and see what stops working. Reconnect later with the minimum scopes needed.

Is “Sign in with” safer than a password?

Generally yes, because the app never stores your main password. But it can still access your data if you approve broad scopes, so audits remain essential.

What about shared or workplace accounts?

Follow your organization’s policies, use admin‑approved apps, and ask IT to enforce conditional access, consent policies, and logs for app grants.

How often should I audit?

Quarterly is a good baseline, plus after any security alerts, job changes, travel, or when you test new apps.

Conclusion

Your email and calendars reveal far more than most people realize. A simple, repeatable audit—revoking unused apps, minimizing permissions, checking rules and sharing settings, and enabling strong authentication—dramatically reduces your exposure. Make this review part of your regular privacy routine, and be selective about what you approve going forward. Thoughtful, least‑privilege access keeps your communications useful to you and far less useful to attackers.

Good to Know

Apps that say they need “read, send, delete, and manage your email” can usually act like a full desktop client—forwarding messages, creating filters, and exfiltrating data invisibly. Treat broad scopes as high risk and remove them unless absolutely necessary.