Login-alert controls should be kept separate from marketing-email controls. Login alerts relate to account security, while marketing-email preferences determine whether a reader wants promotional communications. Neither should be treated as evidence of the other.
What login alerts cover
The available help documentation describes alerts for login attempts from an unrecognized location or device. It also states that additional verification can involve approving a request through a mobile app or entering a code sent by email.
These are security checks. Receiving an authentication code does not, by itself, establish consent to receive marketing emails.
Which controls to check separately
| Control | What it concerns | What to confirm |
|---|---|---|
| Login or security alerts | Attempts from unrecognized locations or devices | Whether the alert status is enabled and which verification methods are available |
| Marketing-email preferences | Promotional or marketing messages | Whether the relevant preference is enabled, disabled or separately configurable |
Readers should not infer that a login alert is enabled merely because a marketing-email preference is enabled. The reverse assumption is equally unreliable.
What the available material does not confirm
The available official material does not specify the exact account-settings labels, default states, placement of the controls, or whether a particular interface provides a separate marketing-email option. Those details must be confirmed in the account settings currently shown to the reader.
If the interface presents both options together, the safe boundary is still functional: security-alert status should not be used to judge marketing-email status, and unsubscribing from marketing messages should not be assumed to disable login security alerts.