Changing your cPanel password regularly is one of the simplest ways to keep your Instant Access Internet Services hosting account safe. This guide shows how to change your cPanel password from inside cPanel, how to generate a strong one, and what the change does and doesn't affect.
How to change your cPanel password
- Log in to cPanel. If you've forgotten the current password, log in through the client area instead (Services > My Services > your plan > Log in to cPanel).
- Go to Preferences > Password & Security.
- Enter your current password, then type your new password in both new password boxes - or use the Password Generator to create a strong random one (see below).
- Click Change your password now!
cPanel may sign you out after the change. Log back in with the new password.
Use the password generator
- Click Password Generator.
- A random password appears. Click Generate Password again for a different one. Under Advanced Options you can set the length and choose uppercase letters, lowercase letters, numbers and symbols.
- Copy the password into your password manager, then tick I have copied this password in a safe place.
- Click Use Password, then click Change your password now!
A good cPanel password is long (at least 14 characters), unique to this account, and stored in a password manager rather than a sticky note. cPanel rejects passwords that are too weak, so if the save fails, make it longer or add numbers and symbols.
What changing your cPanel password affects
| Login | Changes? |
|---|---|
| cPanel (direct login) | Yes - use the new password |
| Client area "Log in to cPanel" button | No change - it keeps working |
| FTP or SSH using your main cPanel username | Yes - update FileZilla and other saved logins |
| Email accounts (you@example.com) | No - each mailbox has its own password |
| Extra FTP accounts you created | No - they have their own passwords |
| WordPress admin | No - WordPress has separate logins |
| Client area / billing login | No - that's a separate account |
Your website and databases keep working as normal. Database users have their own passwords, so WordPress won't lose its connection when you change the cPanel password.
Troubleshooting
The new password is rejected as too weak
Make it longer and mix in numbers and symbols, or use the generator. Avoid your domain name, username and dictionary words.
I changed my password and now FileZilla won't connect
If FileZilla logs in with your main cPanel username, update the saved password in its Site Manager. Don't let it keep retrying with the old one - repeated failed logins can get your IP address temporarily blocked by the firewall.
Should I also turn on two-factor authentication?
Yes. A password plus a code from your phone is far harder to break into. See the 2FA guide below.
I think someone else has my password
Change it right away, then check Last Login IP Address in the General Information panel on the cPanel home page. Turn on login notifications in Preferences > Contact Information so you're emailed when someone logs in. If you see anything suspicious, open a ticket.
Related guides
- How to Set Up Two-Factor Authentication (2FA) in cPanel
- How to Log In to cPanel Directly and Reset a Forgotten Password
- How to Update Your Contact Email and Notifications in cPanel
- How to Log In to cPanel from the Client Area
Still stuck? Open a support ticket and the Instant Access Internet Services team will help.
