Two-factor authentication (2FA) adds a second lock to your cPanel login: after your password, cPanel asks for a six-digit code from an app on your phone. Even if someone steals your password, they can't get in without your phone. Setting up 2FA in cPanel takes about two minutes.
Before you start
Install an authenticator app on your phone. Any standard time-based code app works, for example:
- Google Authenticator (Android and iPhone)
- Microsoft Authenticator (Android and iPhone)
- Duo Mobile, or a password manager with a built-in authenticator such as 1Password or Bitwarden
Apps that back up or sync your codes to the cloud make life easier if you ever lose or replace your phone.
How to turn on two-factor authentication in cPanel
- Log in to cPanel.
- Go to Security > Two-Factor Authentication.
- Click Set Up Two-Factor Authentication.
- Open your authenticator app, choose to add an account, and scan the QR code shown on screen. Can't scan? Choose the app's option to enter a key manually and type in the Account and Key shown under the QR code.
- The app now shows a six-digit code for your cPanel account that changes every 30 seconds.
- Type the current code into the Security Code box in cPanel before it changes.
- Click Configure Two-Factor Authentication.
You'll see a confirmation that 2FA is on. From now on, each time you log in to cPanel you'll enter your username and password, then the code from the app.
Keep a way back in
Do these now, before you need them:
- Turn on backup or sync in your authenticator app (if it offers it), so a new phone can restore your codes.
- Save the setup key. The text key shown during setup can recreate the code on another device. Store it in your password manager, not in your email.
- Remember the client area. Your client area login is a separate account, so you can always reach it to open a support ticket even if your phone is gone.
How to change phones or turn 2FA off
- Go to Security > Two-Factor Authentication.
- To move to a new phone, click Reconfigure and repeat the setup with the new device. This replaces the old code, so the old phone stops working for cPanel, and you'll be signed out of other open cPanel windows.
- To switch 2FA off completely, click Remove Two-Factor Authentication.
Troubleshooting
cPanel says the security code is invalid
The codes depend on your phone's clock. Make sure your phone's date and time are set automatically (in your phone's settings, turn on automatic date and time / "Set automatically"). Then wait for a fresh code and try again. Enter it quickly - each code only lasts about 30 seconds.
Does 2FA affect my email or FTP?
No. cPanel two-factor authentication protects the cPanel login only. Email apps, webmail and FTP keep using their own passwords.
I lost my phone
See our guide to getting back into cPanel without your 2FA device (linked below). In short: restore your authenticator app from its backup, or add your saved setup key to a new phone. The Instant Access Internet Services support team doesn't turn 2FA on or off for customers, so save the setup key (in a password manager or somewhere safe) when you set 2FA up.
Too many failed attempts and now I can't connect
Repeated failed logins can make the firewall temporarily block your IP address. Stop trying, get your IP from whatismyipaddress.com, and include it in a support ticket.
Related guides
- Lost Your 2FA Phone? How to Get Back Into cPanel
- How to Change Your cPanel Password
- How to Update Your Contact Email and Notifications in cPanel
- How to Log In to cPanel Directly and Reset a Forgotten Password
Still stuck? Open a support ticket and the Instant Access Internet Services team will help.
