Two-factor authentication (2FA) means that logging in to cPanel needs two things: your password and a six-digit code from an app on your phone. Even if someone steals or guesses your password, they cannot get in without your phone. It is one of the simplest and most effective ways to protect your website and email.
This guide covers 2FA for the cPanel login page. Your FimuroHost client area has its own 2FA setting under Security Settings in the account menu, and we recommend turning on both.
Before you start
- Install an authenticator app on your phone, such as Google Authenticator, Microsoft Authenticator, Duo Mobile or 2FAS. Any app that supports time-based codes (TOTP) works.
- Make sure your phone’s date and time are set automatically. Codes are based on the current time and fail if the clock is wrong.
Step by step
- Log in to your FimuroHost client area at https://app.fimurohost.com.
- Go to Services and select your cPanel Hosting plan.
- Click Login to cPanel. cPanel opens in a new tab, already signed in.
- In the Security section, click Two-Factor Authentication.
- Click Set Up Two-Factor Authentication. A QR code appears.
- In your authenticator app, tap the add (+) button and scan the QR code. If you cannot scan it, choose manual entry in the app and type the Account and Key shown below the QR code.
- The app now shows a six-digit code that changes every 30 seconds. Type the current code in the Security Code box.
- Click Configure Two-Factor Authentication. You will see a confirmation that 2FA is active.
From now on, after entering your password on the cPanel login page you will be asked for the current code from the app.
Keep a way back in
- When you scan the QR code, save the Key (the long text code) in a password manager or print it and store it safely. Adding it to a second device later recreates the same codes.
- Single sign-on from the FimuroHost client area (Services » your plan » Login to cPanel) does not ask for the cPanel code, so protect your client area with its own 2FA as well.
Moving to a new phone
- Log in to cPanel (single sign-on is easiest).
- Go to Security » Two-Factor Authentication and click Reconfigure.
- Scan the new QR code with the app on your new phone, enter the code and confirm.
Reconfiguring replaces the old setup, so codes from the old phone stop working immediately and other open cPanel sessions are logged out.
Turning 2FA off
Go to Security » Two-Factor Authentication and click Remove Two-Factor Authentication. We recommend only doing this briefly, for example while switching apps.
Common problems
“The security code is invalid”
- Check the time on your phone. Turn on automatic date and time, then try a fresh code.
- Type the code before it changes. If it is about to expire, wait for the next one.
- Make sure you are reading the entry for the right account if you have several in the app.
I lost my phone
Log in through the client area with single sign-on and reconfigure 2FA with your new phone. If you cannot do that, open a ticket from your client area. After we confirm you are the account holder, we can remove 2FA from your cPanel account so you can set it up again.
Need help?
If anything in this guide does not match what you see, or you get stuck, open a support ticket (choose the Support department) or message us on WhatsApp at 01818160926. Tell us your domain name and what you have tried so far, and never send your password in a ticket or chat.
Categories
Written by
FimuroHost Team
Technical Writer