Protecting Your Account with Two-Factor Authentication Print

  • 0

What it is and why it matters

Two-factor authentication adds a second step to logging in: your password, plus a six-digit code that changes every thirty seconds and lives on your phone. Someone who steals or guesses your password still cannot get in, because they do not have your phone.

This matters more for a hosting account than for most logins. Your client portal controls your domains, your services, and your billing, and access to it is the route to everything else you own online. Passwords leak constantly through breaches at unrelated websites, and reused passwords make one leak everyone's problem. Two-factor authentication makes that irrelevant.

From January 2027 it will be compulsory

Two-factor authentication is optional right now, and from January 2027 it will be required on every client portal account, with no exceptions. We are telling you well in advance so that nobody is caught out.

Set it up now rather than waiting. Doing it today takes five minutes at a moment of your choosing, with time to save your backup code properly and get comfortable with it. Doing it in January, alongside everyone else, at the moment you happen to need to log in for something urgent, is the same five minutes spent far less pleasantly.

Setting it up

You will need a free authenticator app on your phone first. Google Authenticator, Microsoft Authenticator, Authy, and Duo Mobile all work, any of them will do, and if you already use one for another service, use the same one.

  1. Log in to your client portal and click your name in the top right, then Security Settings.
  2. Click Click here to Enable.
  3. Choose Time Based Tokens and click Get Started.
  4. Open your authenticator app and scan the QR code shown on screen. If scanning will not work, the screen also shows a code you can type into the app by hand.
  5. Enter the six-digit code your app now displays, to confirm it is working.
  6. Save the backup code you are shown. This step matters more than the rest, and the next section explains why.

The backup code: do not skip this

At the end of setup you are shown a backup code, sixteen letters and numbers. It is shown once. It is your way back in if your phone is lost, stolen, replaced, or simply flat at the wrong moment.

Store it somewhere that is not your phone. A password manager entry alongside your portal login is the best home for it. Written down and kept somewhere safe is fine too. What does not work is leaving it in a screenshot on the phone that is also holding your authenticator app, since losing the phone then loses both halves at once.

If you cannot log in

  • Phone unavailable, backup code saved: on the two-factor prompt, use the option to log in with your backup code instead. You can then set 2FA up again on your new device.
  • Both unavailable: open a support ticket or contact us on WhatsApp at +27 72 270 9321. We can disable two-factor authentication on your account, but only after verifying your identity properly, as set out in our article on updating your account and contact details. Expect us to be strict about this, a provider who disables 2FA on request without proper verification has made the feature worthless.
  • The code is rejected even though it looks right: this is almost always your phone's clock. Time-based codes depend on your device's time matching ours, so set your phone's date and time to automatic and try again.

If you sign in with Google

You can also sign in to your client portal using your Google account. If you do, your security is governed by Google's own two-factor system rather than ours, so make sure two-step verification is switched on in your Google account. Either route is fine, the important thing is that one of them is protecting you.

Good to know

Two-factor authentication on your client portal protects your account with us. It does not protect your email, your cPanel, or your website's admin login, all of which are separate, as our article on understanding your logins explains. Your email deserves the same treatment and probably sooner, since your email address is the reset mechanism for almost everything else you own. Whatever authenticator app you install for us today will happily hold your other accounts too.


Was this answer helpful?

« Back

Powered by WHMCompleteSolution