+254725682556 +254725052660 info@ziprof.co.ke
Client Area

Security

How to Check Your Control Panel's Login History for Suspicious Activity

If you suspect someone has logged into your hosting account without permission, your control panel keeps a record of recent logins you can check. It lists the date, time, and IP address of every login, so you can quickly spot one you don't recognize.

Why Check Your Login History

A login history is the fastest way to confirm whether your account was actually accessed by someone else, or whether an odd file change, a password reset email you didn't request, or a missing message has a more ordinary explanation. It's worth checking any time something on your site or email account looks off, even if you're not sure there's a real problem.

Viewing Your Login History

In cPanel

  1. Log in to your cPanel account.
  2. Scroll to the Security section and click Login History.
  3. Review the list of recent logins. Each row shows the date and time, the IP address used, and whether the login was to cPanel, Webmail, or FTP.
  4. Check for IP addresses or login times you don't recognize, especially outside your normal working hours.

Many cPanel accounts also show a Failed Login Attempts count on the same page. A high number here can mean someone is trying to guess your password, even if they haven't succeeded.

In DirectAdmin

  1. Log in to your DirectAdmin account.
  2. Go to the account's Logs or Session section (the exact label depends on your DirectAdmin theme, but it's usually grouped with account activity or security settings).
  3. Open the login or session log to see recent access attempts, including the IP address and timestamp for each one.
  4. Compare the entries against your own usual login times and locations.

If you can't locate a login log in your version of DirectAdmin, contact ZIPROF support and we can pull the access log for your account from the server side.

What to Do If You Find a Suspicious Login

Act quickly if you spot a login you can't account for. The longer an unauthorized session goes unnoticed, the more time it gives someone to change settings, access email, or plant files on your site.
  • Change your control panel password immediately, and change it again for any email accounts that share the same password.
  • Check for new, unfamiliar FTP or email accounts that you didn't create.
  • Look through your file manager for recently modified files you don't recognize.
  • Contact ZIPROF support with the suspicious IP address and timestamp so we can help investigate further.

Turning on two-factor authentication makes it much harder for anyone to log in even if they get hold of your password. See How to Enable Two-Factor Authentication for Your Control Panel Login for the setup steps.