How to Make a Complete List of Every Online Account You Have

Organize your digital life! Learn how to list every online account you own and take control of your digital footprint. Get started now!

Created - Mon Nov 03 2025 | Updated - Thu Aug 27 2026
Cover for How to Make a Complete List of Every Online Account You Have

To find every website where you have an account, check these sources in order: your password manager, every email inbox, browser-saved passwords and history, Google/Apple/Facebook/Microsoft connected apps, app-store subscriptions, bank and card statements, and data-breach notifications. Record each service in the account inventory below, then verify whether it is active before deleting or securing it.

Start with this account-discovery checklist

  1. Review and deduplicate saved logins in your password manager.
  2. Search every current and former email inbox, including archived, spam, and trash folders.
  3. Review browser-saved passwords and search browser history for account-related pages.
  4. Check connected-app dashboards for Google, Apple, Facebook, and Microsoft sign-ins.
  5. Review app-store subscriptions, purchase history, and installed apps on each device.
  6. Scan the last 12 months of bank and card statements for subscriptions and purchases.
  7. Check breach notifications, old devices, receipts, aliases, and other forgotten-account clues.
  8. Verify each candidate, document it, secure important accounts, and close accounts you no longer need.

Quickest method: review your saved logins

Open your password manager and export or review the list of saved website logins. Remove duplicate entries, group related services under one company, and mark each account as active, unused, or closed. Saved logins will not include accounts where you never saved a password, so continue with the checks below.

The hidden risks of unmanaged accounts

Dormant accounts can contain personal data, retain payment details, or use weak or reused passwords. A breach of a forgotten service may expose information or provide a foothold for attacks against more important accounts. An inventory helps you reduce this attack surface while preserving accounts and data that matter.

Blog image

Search every email inbox

Search each inbox for: welcome, verify your email, confirm your account, activate your account, reset your password, receipt, order confirmation, subscription, unsubscribe, and security alert. Also search by common sender domains and review archived, spam, and trash folders. Repeat this process for old email addresses and phone numbers.

Record the service named in each message, the email address or phone number used, and any login or recovery link. A receipt or marketing email is a useful lead, but it does not by itself prove that the account is still active.

Check accounts created with Google, Apple, Facebook, or Microsoft

Review your connected-app dashboards: Google Account → Security → Your connections to third-party apps and services; Apple Account → Sign in with Apple; Facebook → Settings → Apps and Websites; and Microsoft Account → Privacy or Apps and services. Record both the connected service and the sign-in method, then revoke access for services you no longer use.

Review browser passwords and history

Review saved passwords in your browser’s password manager and search browsing history for /login, /signin, /register, and /account. Browser history can reveal sites where you registered, but a visit does not prove that an account exists—confirm each candidate by trying the service’s account-recovery flow without creating a new account.

Blog image

Check app stores and device accounts

Check the Subscriptions and Purchase History pages in the Apple App Store and Google Play, plus the installed-app lists on your phone, tablet, and computer. Review each app’s account settings and identify whether it uses email/password, Google, Apple, or another single-sign-on provider.

Include paid, free-trial, and free apps. An installed app may use a separate account, a device account, or a connected sign-in, so record the method rather than assuming that the app-store account is the service account.

Review bank and card statements

Review the last 12 months of bank and card statements for recurring charges, one-time purchases, payment processors, and free-trial conversions. A charge confirms a billing relationship, but it may not identify the login email or account status; use the merchant’s receipt or support page to verify those details.

Add banking, investment, insurance, tax, utility, and payment accounts to the inventory separately from subscriptions. Prioritize these accounts for a unique password, multi-factor authentication, current recovery details, and careful privacy review.

Use an account-inventory template

Use one row per service with these columns: Service, login URL, sign-in method, email or phone used, username, account status, subscription/payment status, recovery method, last reviewed date, and action needed. Never place passwords, recovery codes, security-answer answers, or seed phrases in this document.

ServiceLogin URLSign-in methodEmail or phone usedUsernameAccount statusSubscription/payment statusRecovery methodLast reviewed dateAction needed
Example servicehttps://example.com/loginEmail/passwordname@example.comusernameNot confirmedNone foundEmailYYYY-MM-DDVerify

Verify every candidate account

For each candidate website, verify the account by locating a confirmation email, finding a saved login, signing in, or using the official “forgot password” process. Do not repeatedly guess passwords. If recovery reveals that no account exists, mark the entry as “not confirmed” rather than creating one.

How to find accounts you may have forgotten

Check breach-notification services such as Have I Been Pwned for exposure of your email address, but treat results as leads rather than a complete account list. Also review old phones and computers, browser profiles, downloaded apps, receipts, cloud-storage activity, domain registrations, and email aliases.

Breach results may identify a service even when the account is now closed, and they may omit services that have never appeared in a reported breach. Never enter a password into a breach-notification search.

Secure or close accounts safely

First export any data, cancel payments, remove stored payment methods, and check the provider’s official deletion instructions. Request deletion through the account settings or privacy contact where available, and retain the confirmation. If deletion is unavailable, use a unique randomly generated password stored in your password manager, remove personal data and payment methods, revoke connected apps, and set the account to its most private state. Do not intentionally discard a password and lose control of the account.

One end-to-end process

  1. Discover: Search saved logins, inboxes, browsers, connected apps, app stores, statements, breach notices, and old devices.
  2. Verify: Confirm each lead through a saved login, confirmation message, sign-in, or official recovery flow.
  3. Document: Add one row per verified or unconfirmed service and record the sign-in and payment details.
  4. Secure: Use unique passwords, enable 2FA on important accounts, update recovery methods, and review privacy settings.
  5. Close: Export data, cancel payments, remove payment methods, revoke access, request deletion, and retain confirmation.
  6. Review: Add new accounts as you create them and repeat the inventory at least every six months.

Digital legacy and privacy

Your inventory should identify accounts and instructions, not expose credentials. Store it in an encrypted password manager or encrypted document, share access through an estate-planning or emergency-access feature when appropriate, and document what should be deleted, preserved, transferred, or memorialized.

Include domains, photos, cloud storage, financial assets, social profiles, intellectual property, and cryptocurrency in your instructions. Consider legal advice for integrating digital assets into your estate plan. Cipherwill can help organize and share digital-asset instructions with trusted people through a secure planning process. Learn more in The Role of Digital Assets in Estate Planning.

Conclusion: complete your first 30-minute pass

Start with a 30-minute pass: review saved logins, search your inbox for “welcome” and “receipt,” and check connected apps. Add every candidate to the inventory, verify it, enable 2FA on important accounts, and schedule a six-month review. This produces a reliable list without requiring you to remember every account at once.

FAQ

Q: How can I see all accounts linked to my email address?

A: No single tool can discover every account. Search every inbox, including archived, spam, and trash folders, for “welcome,” “verify your email,” “receipt,” “subscription,” “reset your password,” and “security alert.” Repeat the search for old addresses, phone numbers, sender domains, aliases, saved logins, browser history, connected-app dashboards, app stores, statements, and breach notifications. Verify each result before adding it as active.

Q: How do I find websites where I used Sign in with Google or Apple?

A: In Google Account, open Security and “Your connections to third-party apps and services.” In Apple Account, open “Sign in with Apple.” Also review Facebook Settings → Apps and Websites and Microsoft Account → Privacy or Apps and services. Record each service and sign-in method, verify the account, and revoke access you no longer need.

Q: Does my password manager show every account I have?

A: No. It shows saved credentials, not accounts where you never saved a password, used a different browser or device, or signed in through another provider. Review its entries first, then search email, browser history, connected apps, app stores, statements, old devices, and breach notifications.

Q: How do I verify that a suspected account exists?

A: Find a confirmation email or saved login, sign in, or use the service’s official forgot-password or account-recovery process. Do not repeatedly guess passwords or create a new account. If recovery says no account exists, mark the entry “not confirmed.”

Q: What should I do before deleting an account?

A: Export needed data, cancel subscriptions, remove payment methods, check official deletion instructions, revoke connected apps, and request deletion through account settings or the provider’s privacy contact. Keep the confirmation. If deletion is unavailable, retain control with a unique randomly generated password in your password manager, remove personal data, and set the most private available settings.

Q: How often should I update my account inventory?

A: Update it whenever you create or close an account and perform a complete review every six months. Keep the inventory encrypted and exclude passwords, recovery codes, security answers, and seed phrases.

Q: How does an account inventory help with digital legacy planning?

A: It gives trusted people instructions for accounts and digital assets without exposing credentials. Store it securely, use an emergency-access or estate-planning feature where appropriate, and specify what should be deleted, preserved, transferred, or memorialized.

Cipherwill Promo Image
Hey, we've written this blog post.
Here's what we do. If you're interested.
We ensure your data reaches your loved ones when you pass away. Cipherwill is an automated and end-to-end encrypted digital will platform.

Be ready for tomorrow.

Legacy planning isn't about the end; it's about giving your loved ones complete clarity. Create a secure, automated plan for your digital assets in under three minutes.