Turning on two-factor authentication

Two-factor authentication means that knowing your password is not enough to get in. It is the single most effective thing you can do to protect your account, and it takes about two minutes to set up.

On your client area account

Log in, open your account security settings, and choose to enable two-factor authentication. You will be shown a QR code to scan with an authenticator app on your phone. From then on you will be asked for a six-digit code as well as your password.

On cPanel

cPanel has its own two-factor setting, separate from the client area. Look for Two-Factor Authentication in the Security section and follow the same process.

Which app

Any standard authenticator app works – there is no need for a specific one. Some password managers can also store the codes, which is convenient and keeps everything together.

Keep your recovery codes

You will be given backup or recovery codes when you set this up. Save them somewhere that is not your phone. If you lose the phone and have no codes, recovering access means proving who you are to us, which is deliberately slow.

Also protect the website itself

Two-factor on your hosting account does not protect the login page of your website. If your site has an administrator login – and most do – secure that separately, with a strong unique password and, where available, its own two-factor.

  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

Recognising a phishing email that claims to be from us

Hosting customers are a standard target for phishing, because an attacker who gets your control...

My website has been hacked: the first things to do

Work in this order. The instinct is to delete the bad files and carry on, which is exactly how...

File and folder permissions, and why 777 is never the answer

Every file and folder has permissions controlling who may read, write and run it. When something...

Why we block IP addresses, and how to get unblocked

Our servers block addresses automatically when they behave like an attack. This is not a...

Choosing and managing passwords

Most compromises we see come down to a password that was weak, reused, or stolen from somewhere...