cPanel - Security - Two-Factor Authentication
Two-Factor Authentication (2FA) for cPanel
Two-Factor Authentication (2FA) adds an extra layer of security by requiring two forms of identification. After entering your password, you’ll need a six-digit code from an app on your smartphone. Without this code, you can’t log in.

Note: Your hosting provider must enable 2FA in WHM for this feature to work.
How 2FA Works:
- Tracks authentication across all open browser windows. Logging out in one will log you out of the others.
This can also be enabled for **Webmail**.
Requirements:
- A smartphone with a TOTP (Time-Based One-Time Password) app. Recommended apps:
Google Authenticator™
Duo Mobile
Set Up 2FA
1. Click **Set Up Two-Factor Authentication** in cPanel.
2. Link your 2FA app:
- **Scan the QR code** (automatic), or
- **Enter the Account & Key manually** (manual setup).
3. Enter the six-digit code generated by your app before it expires.
4. Click **Configure Two-Factor Authentication**.
Tip: If you receive a “security code is invalid” error, your server's date/time may be off: contact your hosting provider.
Disable 2FA
Click **Remove Two-Factor Authentication**.
Reconfigure 2FA
Click **Reconfigure** to set up 2FA again.
This will overwrite the current setup, making old codes invalid.
Lost Access to Your 2FA App
Contact your system administrator to disable 2FA so you can regain access and reconfigure it.
Related cPanel Tutorials and How To Guides
Over 75 different website hosting features available
Tweet Share Pin Email
Error: No site found with the domain 'mail.rshweb.com' (Learn more)