Setting Up Two-Factor Authentication for Your cPanel Login

Two-factor authentication (2FA) adds an extra layer of security to your cPanel account by requiring both your password and a temporary code from your mobile device to log in. This significantly reduces the risk of unauthorized access, even if your password is compromised.

Prerequisites

  • A smartphone or tablet with a 2FA app installed, such as:

Setting Up 2FA in cPanel

  1. Log in to your cPanel account at https://{hostname}.mysecureservers.com:2087
  2. In the search box at the top, type "Two-Factor Authentication" or navigate to the SECURITY section
  3. Click on Two-Factor Authentication
  4. Click Set Up Two-Factor Authentication
  5. The system will display a QR code
  6. Open your authenticator app on your mobile device
  7. Tap the "+" or "Add" button in your authenticator app
  8. Scan the QR code displayed in cPanel
  9. Once the app recognizes the code, it will start generating 6-digit codes that change every 30 seconds
  10. Enter the current 6-digit code from your authenticator app in the "Verification Code" field in cPanel
  11. Click Verify Code
  12. If successful, you'll see a confirmation message that 2FA is now active

Backup Recovery Codes

After setting up 2FA, cPanel will provide you with recovery codes. These are extremely important:

  1. cPanel will display several recovery codes
  2. These codes can be used once each if you lose access to your authenticator app
  3. Important: Save these recovery codes in a secure location (not on your computer)
  4. Consider printing them and storing them in a safe place

Logging In with 2FA Enabled

Once 2FA is set up, the login process will change:

  1. Enter your username and password as usual
  2. You'll be prompted for a verification code
  3. Open your authenticator app and enter the current 6-digit code
  4. Click Log in

Disabling 2FA (If Needed)

  1. Log in to cPanel using your password and verification code
  2. Go to Two-Factor Authentication
  3. Click Disable Two-Factor Authentication
  4. Confirm your decision
If You Lose Access: If you lose your phone and backup codes, contact our support team at https://clients.dotcanada.com/submitticket.php. You'll need to verify your identity before we can disable 2FA on your account.

Setting up 2FA is one of the most effective security measures you can take to protect your hosting account from unauthorized access. We strongly recommend enabling this feature for all your important accounts.

Was this answer helpful? 0 Users Found This Useful (0 Votes)