Help Centre  /  Security

Security

Two-Factor Authentication (2FA) on cPanel

3 min read

Two-Factor Authentication (2FA) on cPanel

Two-Factor Authentication adds a second layer of security to your cPanel login — even if someone gets hold of your password, they can't get into your account without also having your authenticator app. It only takes a couple of minutes to set up and it's one of the simplest ways to keep your hosting account safe.

How It Works

2FA on cPanel operates on two levels:

  • Per cPanel Account — Each cPanel user sets up their own 2FA individually. You scan a QR code directly inside your cPanel dashboard, under Security ▸ Two-Factor Authentication, using an authenticator app such as Google Authenticator, Authy, or Microsoft Authenticator. From that point on, logging in requires your password and a rotating 6-digit code from your phone.
  • Root / WHM Control — The root user (server administrator) sets the master security policy in WHM ▸ Security Center ▸ Two-Factor Authentication. This is the switch that governs whether 2FA is available at all. If the root user disables the global policy in WHM, 2FA is switched off server-wide — individual cPanel users won't be able to enable or enforce it on their own accounts, regardless of their personal settings.

In short: your account-level setup only works if the server-level policy allows it.

Setting It Up (cPanel Users)

  1. Log in to cPanel and go to Two-Factor Authentication.
  2. Click Set Up Two-Factor Authentication.
  3. Open your authenticator app and scan the QR code shown on screen (or enter the setup key manually if you can't scan).
  4. Enter the 6-digit code your app generates to confirm the pairing.
  5. Save any backup/recovery codes cPanel gives you somewhere safe — these let you back into your account if you ever lose your phone.

From then on, every login will ask for your password followed by the current code from your app.

Lost Your Device?

If you lose access to your authenticator app, use one of the backup codes generated during setup to log in, then re-pair a new device from the Two-Factor Authentication page. Without a backup code or admin assistance, you won't be able to log in — so keep those codes somewhere safe, not just on the same phone as the app.

Why It Matters

Passwords get reused, guessed, or leaked in unrelated data breaches all the time. 2FA means a leaked password alone isn't enough to get into your hosting account — which matters a lot more once that account controls your website, email, and DNS.

Spam Emails: How to Train, Block and Manage Suspicious emails Managing your Domain Email Setup in Outlook on a PC

Still stuck? We'll sort you out.

Send us a message
← Back to Help Centre

Question 1 of 4

What’s the thing that’s bugging you most right now?