Knowledgebase / Security & SSL
Turn on two-factor authentication in cPanel
Protect your cPanel login with two-factor authentication using an authenticator app, so a stolen password on its own will not let anyone in.
Two-factor authentication (2FA) adds a second check to your cPanel login: your password, plus a six-digit code that changes every thirty seconds. If your password is guessed, reused somewhere else, or captured by malware on a device you use, the code is the part an attacker still does not have. This guide walks through switching it on for your own cPanel user.
You will need to log in to cPanel, and you will need a phone or computer with an authenticator app installed. Any app that supports standard time-based codes will work.
Get an authenticator app ready
- Install an authenticator app on your phone or computer if you do not already have one.
- Open the app and find its option to add a new account, usually a plus button or "Scan QR code".
- Leave the app open while you work through the next section, since the setup screen in cPanel only shows the code once.
If you use a password manager, many of them can store 2FA codes as well. Keeping the code in the same place as the password reduces the benefit somewhat, so a separate app is the safer choice.
Switch it on in cPanel
- Log in to cPanel.
- In the Security section, open Two-Factor Authentication.
- Select Set Up Two-Factor Authentication.
- Scan the QR code with your authenticator app. If your app cannot scan, type in the account security key shown beside the code instead.
- Your app will start showing a six-digit code for the account. Enter the current code in the Security Code box in cPanel.
- Select Configure Two-Factor Authentication to finish.
cPanel confirms that 2FA is active. From your next login onward you will be asked for the code after your password.
Keep a way back in
Write down or safely store the account security key from step 4, or take a screenshot of the QR code and keep it somewhere private. If you lose or replace the phone that holds the code, that key is what lets you set the app up again.
If you no longer have either, contact us through /support and we can clear the 2FA setting on your cPanel account so you can configure it again. We will confirm your identity first, since that is exactly the sort of request an attacker would make.
If it didn't work
The most common cause of a rejected code is clock drift. Time-based codes depend on your device clock being accurate to within a few seconds, so set your phone or computer to sync time automatically and try again.
If the Two-Factor Authentication icon is not in your cPanel Security section, the feature may not be enabled for your account or your hosting package. Reach out and we will check.
If you scanned the QR code twice, your app may hold two entries for the same account. Delete the older one and use the code from the newest entry.
Still stuck? Open a ticket at /support with your domain name and we will take a look.
More in Security & SSL
Stuck partway through? Support is answered by the engineers who run the servers, around the clock.