The logins are often hard to grok if it's a third party API-level access. For example, I believe if you're using a mail plugin that uses App Engine, it will appear to have generated a login from a Google IP block.
Would Google service trigger the unusual alert?