+254725682556 +254725052660 info@ziprof.co.ke
Client Area

Security

What to Do If You're Locked Out of Your Control Panel After Too Many Failed Logins

Entering the wrong password too many times in a row triggers your host's automatic brute-force protection, which temporarily blocks your IP address from reaching the login page. This is a security feature working as intended, not a fault on your account, and in most cases you don't need help to get back in.

Why This Happens

Both control panels watch for repeated failed login attempts from the same IP address in a short window. Once that threshold is crossed, the system assumes it could be an attacker guessing passwords and blocks further attempts for a set period, even if the next attempt would have been correct.

Retrying immediately, over and over, usually resets the timer or extends the block. Stop attempting to log in as soon as you see the lockout message.

In cPanel

cPanel's built-in protection (cPHulk) tracks failed logins per IP and temporarily blocks the address once the limit is reached.

  1. Wait before trying again. Lockout periods are usually short, often somewhere between 15 minutes and an hour depending on how your account is configured.
  2. Double-check you're using your correct cPanel username, not your email address or domain name, along with the current password.
  3. If you're on mobile data or a shared office network, your IP address may already have been blocked by someone else's failed attempts. Switching to Wi-Fi or a different network can sometimes get you past the block sooner.
  4. If you still can't get in after waiting, contact ZIPROF support with the approximate time of the lockout and, if you know it, your current IP address, so it can be cleared manually.

In DirectAdmin

DirectAdmin relies on its login failure protection to block an IP address after repeated incorrect login attempts, usually for a fixed cooldown period.

  1. Stop attempting to log in and wait out the cooldown period before trying again.
  2. Confirm you're entering your correct DirectAdmin username and the current password, not an old saved one.
  3. If the block persists longer than expected, reach out to ZIPROF support with your username and, if known, your IP address so the block can be removed.

Avoiding This in the Future

  • Save your control panel login details in a password manager so you're never guessing or mistyping.
  • Bookmark the correct login URL for your account instead of retyping it, to avoid landing on the wrong login form.
  • If you share access with a team, make sure everyone is using their own login rather than one shared password, so one person's mistakes don't lock everyone out.

If you'd like to understand how this protection is configured in the first place, see How to Enable Brute-Force Login Protection for Your Control Panel.