Skip to main content

Walkthrough · Beginner · 15 minutes

How to Enable Two-Factor Authentication

Render a stolen password worthless on every login worth defending — a hands-on walkthrough in plain words that names the classic mistake before you reach it.

The short answer

The job: render a stolen password worthless on every login worth defending. Time to set aside: 15 minutes. Skill needed: beginner.

Below is the full run of steps, the error most people trip over, and the short cut worth remembering. On Hosting & Domains plans several steps are already automated away — the guide marks each one.

By the Hosting & Domains team · Reviewed 18 August 2026

Beginner

Experience required

5

Stages, start to finish

Free

Support included

Proven

On the platform itself

No technical background needed. This walkthrough was written for first-timers, proven on our own hardware, and honest about which parts are genuinely tricky rather than merely unfamiliar.

First rule: read the snag section before you start, not afterwards. It was distilled from the tickets of everyone who tried the other order.

The outline first, then the detail

The work falls into a few clean stages: pick an authenticator app, turn it on in the client area first, then turn it on in cpanel, save the recovery codes there and then and extend it along the chain.

No part of this needs code or a terminal unless the guide says so plainly — and where it does, the exact commands are printed. The step-by-step is below, with the surrounding sections supplying the context that makes it hold.

Where it comes off, and how to stay on

Switching two-factor on and walking past the recovery codes. A lost or wiped phone then shuts you outside your own defences, which turns a security feature into a support ticket with identity checks attached.

It earns a section of its own because it is no obscure edge case — it is the single commonest reason this task reaches a support queue. Knowing it in advance turns the whole job from risky into routine.

What we tell every customer

Move the authenticator across before wiping an old phone. The app exports its secrets, and two minutes of preparation saves you re-enrolling every account you hold from scratch.

A minute spent now repays itself every time this job comes round again — and like almost every hosting job, come round it will.

What a Hosting & Domains plan spares you

Some steps in this guide exist only because hosting traditionally forced them on you. Here the SSL issues itself, the copy is taken daily without being asked, and one-click installers remove the manual setup. What is left is the part that was always genuinely yours.

Should a step still misfire, support answers at any hour with an actual fix rather than a knowledge-base link and a shrug. Half the guides on this site began as repeat patterns in our ticket queue.

The filtering that absorbs an attack well before it reaches the site

A quick platform makes for a short guide

Every walkthrough in this library is run on the platform we actually operate — cPanel, LiteSpeed, NVMe, one-click installs — so the instructions match your screen rather than gesturing at it from a distance.

NVMe storage and LiteSpeed caching sit under every tier, the smallest plan included — that is the floor here, not an upgrade.

  • Every step checked exactly as published
  • The snag named before it arrives
  • The dull steps taken out of your way
  • People reachable at any hour you stall

Why Hosting & Domains

Standard on every plan

5 steps, nothing padded

Each stage is a few minutes of steady clicking, and the fiddly moments are labelled fiddly.

The snag, flagged up front

The classic error for this particular task is named before step one, which is how 15 minutes stays 15 minutes.

Taken from real tickets

These guides came out of the support queue, so every snag flagged is one people genuinely hit.

Help that keeps your hours, not ours

Stuck on step three at midnight? Support answers at any hour, mid-walkthrough included.

Works exactly as printed

Every step is proven on the platform we run — none of the 'your host may vary' hedging.

Every undo written out

Any step that could bite is marked, together with the exact way to wind it back.

Quick Start

Order placed to site online

  1. 1

    Pick an authenticator app

    Any TOTP app will do, whether Aegis, Google Authenticator or 1Password. App-generated codes beat SMS, which falls to anybody who ports your number away.

  2. 2

    Turn it on in the client area first

    Open security settings, scan the QR code into the app, confirm with a code. The billing account governs services and domains, which makes it the first thing worth locking.

  3. 3

    Then turn it on in cPanel

    cPanel offers Two-Factor Authentication as well, switched on through the same short ritual. Anybody inside the panel can reshape everything you host, which is reason enough to enrol it separately.

  4. 4

    Save the recovery codes there and then

    The backup codes shown during setup belong in your password manager. They are the way out when a phone is lost, and setup is the only moment they are ever offered.

  5. 5

    Extend it along the chain

    WordPress admin, the registrar if your names live elsewhere, and the mailbox that can reset the lot. Two-factor grows in value with every link it covers.

Built In

Fitted to every plan

  • cPanel, which is what most of the industry already runs
  • People on the support desk every hour of every day
  • No set-up charge at any point, and no joining fee
  • WordPress Toolkit, with the updates seen to for you
  • WordPress and 400+ further applications installed in one click
  • LiteSpeed caching in the server itself rather than bolted on by plugin
  • Staging copies for trying a change before it goes live
  • NVMe SSD storage on every tier, not only the dear ones
  • Upgrades applied in place, with no migration when you change plan
  • PHP versions set per site from the control panel

Frequently Asked

The questions that come up most

Is two-factor excessive on a small site nobody is aiming at?

It is the highest-value minute in security. Credential dumps arrive constantly and entirely automatically, and two-factor demotes every leaked password from incident to non-event. The question is never how big you are; it is whether losing the account would hurt.

What if the phone with my codes disappears?

The recovery codes you filed at setup let you back in, and you enrol the replacement device from there. Without them, support verifies your identity and resets it, which is deliberately slower because that same route is the one an attacker would take.

Is the free SSL certificate genuinely free?

Entirely, on every plan. The certificate is issued as soon as the name points here and reissues itself well before it lapses. On encryption it matches any paid DV certificate — the paid options exist for wildcard coverage or organisation validation, which most sites never need.

Is there a safe place to try changes?

Yes — plans with staging let you copy the live site, work on the copy, then publish it once it behaves. That turns 'hope the update works' into 'know it works' before a single customer meets it.

Keep reading

Changing hosts? Run through our checklist first.

A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.

What arrives is the checklist, and then the occasional note on keeping a site quick. Leave whenever you like; the privacy policy covers the rest.

Register it, then build on it.

From a first website to a rack of machines, moving up is a change to the account rather than a migration.

View Domain Names plans