Two-factor authentication (2FA) adds a second check to your control panel login. Even if someone gets hold of your password, they still can't log in without a one-time code from an authenticator app on your phone. It takes a few minutes to set up and significantly lowers the risk of your hosting account being accessed by someone else.
The steps differ slightly depending on whether your account is on cPanel or DirectAdmin.
Before you start
Install an authenticator app on your phone if you don't already have one. Google Authenticator, Microsoft Authenticator, and Authy are common choices, and any app that supports standard TOTP (time-based one-time password) codes will work.
In cPanel
- Log in to your cPanel account.
- Under the Security section, click Two-Factor Authentication.
- Click Set Up Two-Factor Authentication.
- Open your authenticator app and scan the QR code shown on the screen. If you can't scan it, use the text key provided to add the account manually.
- Your app will now show a 6-digit code that refreshes every 30 seconds. Type the current code into the Security Code field.
- Click Configure Two-Factor Auth to confirm and save.
From your next login onward, cPanel will ask for this 6-digit code in addition to your password.
In DirectAdmin
- Log in to your DirectAdmin account.
- Go to Account Settings, then open Password / 2FA (sometimes shown as Two-Step Authentication depending on your skin).
- Click Generate Secret to create a new key and QR code.
- Scan the QR code with your authenticator app, or enter the text key manually if scanning isn't possible.
- Enter the current 6-digit code from your app and click Test Code to confirm it matches.
- Tick Require valid Two-Step Authentication Code to login to this account, then click Save.
Log out and log back in to confirm DirectAdmin now asks for your authentication code.
Save any backup or scratch codes shown during setup somewhere safe, separate from your phone. If you ever lose access to your authenticator app, these are usually the only way back into your account without contacting support.
What to do if you lose access to your authenticator app
If you can't generate a code and don't have a backup code saved, you'll need to contact your hosting provider's support team to verify your identity and have two-factor authentication reset on your account.