Website Security & SSL

How to Enable Two-Factor Authentication (2FA) in cPanel

Your cPanel account controls your website, email and files, which makes it a prime target if your password is ever guessed or leaked. Two-factor authentication (2FA) closes that door by asking for a one-time code from your phone every time you log in.

Even if someone has your password, they cannot get in without your phone. Setting it up takes about two minutes.

Before you start

Install an authenticator app such as Google Authenticator, Microsoft Authenticator or Authy on your phone. It generates the rotating codes you will use.

Enable 2FA in cPanel

  1. Log in to cPanel.
  2. Open Security → Two-Factor Authentication.
  3. Click Set Up Two-Factor Authentication.
  4. Scan the QR code with your authenticator app.
  5. Enter the 6-digit code from the app to confirm, then save.

From now on, cPanel asks for a code each time you sign in.

Don’t stop at cPanel

Protect your other logins too:

Frequently asked questions

What if I lose my phone?

You can lose access if you have no backup, so save any recovery codes offered. If you are locked out, we can verify your identity and reset 2FA — open a ticket.

Can I use one authenticator app for everything?

Yes. A single app can hold codes for cPanel, your client area, WordPress and countless other services.

Is 2FA really necessary if I have a strong password?

A strong password is great, but passwords can still leak in data breaches. 2FA protects you even when your password is compromised.

Was this article helpful?