If you suddenly can't reach your website, your cPanel, or your DirectAdmin login even though your password is correct, your IP address may have been blocked. This is a common security feature, not a sign that something is broken with your hosting account, and in most cases you can check for it and remove it yourself in a couple of minutes.
Why Your IP Gets Blocked
A few things usually cause this:
- You (or someone using your computer or network) typed the wrong password too many times in a row. Brute-force login protection then locks out that IP address automatically to stop anyone guessing your password.
- An IP address was added manually to a block list on your account, for example while testing a security feature, and it was never removed.
- Your internet connection uses a shared or changing IP address (common with mobile data or some home broadband), so a block set for a "suspicious" address ends up matching you later.
If you can't even reach the cPanel or DirectAdmin login page at all, not even to see an error, the block may be happening at the server firewall level rather than inside your account. In that case, open a support ticket with ZIPROF so it can be checked from the server side.
How to Check and Remove the Block
In cPanel
- Log in to cPanel.
- Under the Security section, click IP Blocker.
- Look through the list of blocked addresses for your current IP address. You can search "what is my IP" in your browser to confirm what it is.
- If you find it, click Delete next to that entry to remove the block.
In DirectAdmin
- Log in to DirectAdmin.
- Go to IP Access Control (sometimes listed as Brute Force Monitor or under Extra Features, depending on your account's theme).
- Check the list of denied addresses for your current IP.
- Select it and remove or delete the entry to restore access.
Preventing It From Happening Again
- Save your control panel password in a password manager so mistyped attempts don't trigger repeated failed logins.
- If several people on your team log in to the same account, make sure everyone is using the correct current password before trying more than once or twice.
- If you're on a mobile connection or a network with a changing IP address, expect that a block set for one session might reappear if your address changes back later, and check the same list again if it does.
Brute-force login protection is what's usually behind this kind of automatic block, and it's worth understanding how it's configured on your account. See How to Enable Brute-Force Login Protection for Your Control Panel for more on how it works.