Skip to main content

Ownership & control · Beginner · 30 minutes

How to secure your hosting account — The Account That Can Move Your Domains Deserves Your Strongest Password

One login stands between an attacker and the auth code that would move every name you own to a registrar you have never heard of.

The short answer

Start with the client area rather than with cPanel: that is the account holding the registrations, issuing auth codes, setting the transfer lock and changing the nameservers, which makes it the one login whose loss costs you the names themselves rather than a weekend restoring files. Give it a generated password, switch two-factor on, and only then work downwards.

Below: the logins ranked by what losing each one actually costs, the recovery mailbox trap that catches careful people, and the credentials that quietly outlive the work they were created for.

By the Hosting & Domains team · Reviewed 24 August 2026

Beginner

Level assumed

30 minutes

Time to set aside

5

Stages in the procedure

24/7

Desk hours

No technical background needed. This was written for people who manage names rather than servers, proven on the platform we actually run, and honest about which parts are genuinely fiddly rather than merely unfamiliar.

Read the trap section before you start rather than afterwards. It was assembled from the tickets of everybody who tried the other order.

Rank the logins by what losing them costs

Four layers, and they are not equal. The client area holds the registrations: it can issue an auth code, lift the transfer lock and repoint the nameservers, and losing it can cost you the name permanently. The mailbox on that account can reset it, so it sits above rather than below. cPanel controls the files and the DNS zone, which is serious but recoverable. The application's own admin account is the least of the four, and the one everybody secures first.

Secure them in the order of the damage, not in the order you happen to open them. Most people spend an afternoon hardening WordPress and leave the account that could give the whole name away on a password they also use elsewhere.

The recovery mailbox is the real root, and where people put it is the trap

Account recovery runs through your contact address, so that mailbox quietly caps the security of everything beneath it. The trap is subtle: if the contact address is a mailbox hosted inside the very account it recovers, then losing the account loses the mailbox too, and the reset link has nowhere to arrive.

Keep the registrant and administrative contact on an address you can still reach when this account is unavailable, on a mailbox with its own strong password and its own second factor, and read regularly enough to notice a transfer notification. An unread role address is not a safe place for the only warning you will get.

The transfer lock is a second factor for the name itself

A registrar lock is a status flag on the registration telling the registry to refuse transfer requests. With it engaged, even somebody holding an auth code cannot start a move until the lock comes off, and lifting it is a deliberate action taken inside the account you have just secured.

Treat the auth code as a credential rather than a convenience. Request one when you actually intend to move a name, use it, and do not leave it sitting in an email thread afterwards. Where a name matters, keep the lock on between transfers as a matter of routine.

Credentials that outlive the work

FTP logins, API keys and extra panel users accumulate. The classic exposure in small-business hosting is the contractor credential issued for a fortnight of work and still functioning two years later — nobody revoked it because nobody was keeping a list.

Write the list. Every credential, who holds it, what it reaches and when it should end. Then delete the stale ones today rather than at some tidier future moment.

One minute a month on the login history. Wherever a login history is available, glance at it. Oddities are cheapest to catch early, and an unfamiliar location a fortnight after the fact is far harder to act on than the same entry noticed the week it appeared.

Add one more habit to the same minute: confirm the transfer lock is still engaged and the registrant email is still the address you think it is. Both are things an intruder changes first and neither shouts about having been changed.

The filtering that absorbs an attack well before it reaches the site

Why the job is shorter when the name is here

Every walkthrough here is run on the platform we actually operate — cPanel with a full zone editor, LiteSpeed, NVMe, one-click installs — so the screen the words describe is the screen in front of you.

NVMe storage and LiteSpeed caching sit under every tier, the smallest included — the floor here rather than something to upgrade towards.

  • Written against the real zone editor, not a generic one
  • What the registry decides, and what the panel decides
  • The reversal written next to the risk
  • People reachable whenever a name goes wrong

Why Hosting & Domains

Standard on every plan

The trap named before step one

The classic mistake on this particular task is named before you begin, which is the difference between the time estimate above and a lost evening.

Five stages, none of them filler

Each stage is a short spell of deliberate clicking, and the ones that are genuinely fiddly are labelled fiddly.

Registry, registrar, reseller, host

The four words most guides use interchangeably are kept apart here, because which one you are dealing with decides who can actually fix the problem.

Screens that match the words

Written against the panel your own account opens, so the buttons sit where the page says they sit.

Written from the ticket queue

Every trap named here came out of a real support ticket, which is why the awkward ones get named at all.

The clerical half is already done

Certificates issue themselves, the daily copy is taken without being asked, and the records are written when a name is added — so the guide covers only the decisions that are genuinely yours.

Quick Start

Order placed to site online

  1. 1

    Secure the client area first

    Generated password, two-factor on. This is the account that issues auth codes, sets the transfer lock and controls delegation, so it outranks every other login you hold.

  2. 2

    Move the contact address out of the blast radius

    The registrant and administrative addresses should live on a mailbox you can reach when this account is unavailable, protected as strongly as the account itself, and actually read.

  3. 3

    Engage the transfer lock and leave it on

    The lock instructs the registry to refuse transfers. Lift it only when you genuinely intend to move a name, and put it back afterwards rather than eventually.

  4. 4

    Give cPanel its own password, and its own second factor

    Anyone inside the panel can rewrite the zone, read the mail and reshape every site on the account. It deserves separate credentials rather than a copy of the ones above.

  5. 5

    Audit every credential you ever issued

    FTP accounts, API keys, additional panel users, developer access. Grant the least that does the job, record what was granted, and revoke it the day the work ends.

Built In

Fitted to every plan

  • cPanel, the panel most of the industry already runs
  • Spam and virus screening on every mailbox as standard
  • Mailboxes answering at the name on your registration
  • A staffed desk every hour of every day
  • A free certificate on every plan, reissued before the current one lapses
  • Webmail in the browser, with IMAP, POP and SMTP for any client
  • Your current site moved across by our engineers at no charge
  • A staging copy for rehearsing a change before it goes live
  • A PHP version chosen per site from the control panel
  • NVMe SSD storage on every tier, not just the expensive ones

Frequently Asked

Questions we field again and again

If somebody gets into my client area, can they take my domains?

That is precisely the risk, and it is why this account outranks the rest. From inside it, an attacker can lift the transfer lock, request an auth code and start a move. Two-factor on the account and the lock left engaged between transfers are what turn a stolen password into a nuisance rather than a loss. Watch the contact mailbox too, because transfer notifications go there.

Should the domain's contact address be a mailbox hosted on the same account?

It is convenient and it is a bad idea. If the account is compromised or suspended, that mailbox goes with it, and the reset link you need arrives somewhere you can no longer reach. Keep the registrant and administrative contacts on an address that is independent of the thing they recover — and one somebody actually reads, because a transfer notice is easy to miss in an unattended role inbox.

A developer needs access. How much do I give?

Scope it to the task and never share the master credentials. An FTP account confined to the project directory, or a separate panel user where that is supported, covers most work. The client area, which controls the registrations, should stay out of it entirely. Record what you granted and revoke it on the day the work ends rather than the week you remember.

If I cancel, what happens to the names and the files?

They remain yours. A full copy can be downloaded from the panel at any point, before or during cancellation. Names stay registered in your name for the term you have paid for, and can move to any registrar once the standard 60-day window has passed. Ask for the auth code in the client area and it appears at once, with no retention script in the way.

Keep reading

  • PHP Hosting

    Choose the PHP version per site, on quick NVMe hardware.

  • CMS Hosting

    Quick, hardened hosting for WordPress, Joomla, Drupal and every major CMS.

Changing provider? Work through this checklist beforehand.

A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.

You get the checklist, followed now and then by a note on keeping a site responsive. Unsubscribe whenever you want; the privacy policy covers the rest.

Hold the name and the hosting behind one login.

Every plan carries as standard what other hosts bill as extras, and a desk that answers.

View PHP Hosting plans