Your hosting account is the master key to your online presence — websites, email, domains and billing all flow through it. A few minutes spent securing it is some of the best-value time you will ever invest, because recovering from a hijacked account is far more painful than preventing one.

Start with passwords done right

The old advice about swapping letters for symbols is out of date. Modern guidance is simpler and stronger:

  • Length beats complexity. A long passphrase of several random words is both harder to crack and easier to type than a short cryptic string.
  • Never reuse passwords. If one service is breached, attackers try that same password everywhere else. Your Client Area and your cPanel should have different passwords.
  • Use a password manager. It generates and remembers unique passwords for every site so you do not have to. This single habit fixes most password problems at once.

Turn on two-factor authentication

Two-factor authentication (2FA) means that even if someone learns your password, they still cannot get in without a second code from your phone. The Client Area supports 2FA — enable it in your security settings and store the backup codes somewhere safe in case you lose your device. An authenticator app is more secure than SMS, which can be intercepted. For cPanel and WordPress, turn on their 2FA options too.

Protect the recovery path

Attackers often skip the password entirely and go after the way you reset it. Close that door:

  • Keep the email address on your account current and secured — ideally with its own 2FA, since it can reset everything else.
  • Make sure your contact details and domain admin email are up to date so recovery messages actually reach you.
  • Store backup/recovery codes offline, not in the same inbox they protect.

Recognise the scams aimed at you

Hosting and domain customers are a favourite phishing target. Be sceptical of urgent "your domain is expiring" or "verify your account now" emails. When in doubt, do not click the link — type our address yourself or open a ticket. We will never ask for your password, and legitimate account actions can always be confirmed inside your Client Area.

If something looks wrong

Notice an unfamiliar login, an invoice you did not expect, or a setting you did not change? Act quickly: change your passwords, review active sessions and connected details, and open a ticket so we can help you review the account. Fast action limits the damage. For where invoices and payment methods live, see Payment Methods and Invoices in this section.

Was this answer helpful? 0 Users Found This Useful (0 Votes)