Applies to: All plans.
Before you start: You need access to your client area (my.maxinodes.com) and an authenticator app on your phone (such as Google Authenticator, Microsoft Authenticator or Authy). cPanel is reached by single sign-on from your service page, so you rarely type its password — but you can still set 2FA on it directly.
Two-factor authentication (2FA) adds a second step to logging in: after your password, you enter a one-time code from your phone. Even if someone learns your password, they cannot get in without that code. We strongly recommend enabling 2FA on both your client area and cPanel, and using a strong, unique password for each.
Enable 2FA on your client area
- Log in to your client area at my.maxinodes.com.
- Open the account menu (top right) and go to your profile/security settings — look for the option labelled Security Settings or Two-Factor Authentication.
- Choose the Authenticator App (time-based one-time password) method and click to enable it.
- Scan the QR code with your authenticator app, then type the 6-digit code it shows to confirm.
- Save the backup code somewhere safe (a password manager). You will need it if you lose your phone.
Result: Next time you log in to the client area, you enter your password and then the current code from your authenticator app.
Enable 2FA on cPanel
- From your client area -> Services -> My Services, open your hosting service and use the Login to cPanel single sign-on button.
- In cPanel, go to cPanel -> Security -> Two-Factor Authentication.
- Click Set Up Two-Factor Authentication and scan the QR code with your authenticator app.
- Enter the 6-digit code to confirm and finish.
Result: If you ever sign in to cPanel directly (rather than by single sign-on), you'll be asked for your authenticator code after your password.
Use strong, unique passwords
- Make each password long (aim for 12+ characters) and use a different one for your client area, cPanel, email, WordPress and your registrar.
- Never reuse a password across services — if one site is breached, the rest stay safe.
- Use a password manager to generate and store them, so you only remember one master password.
- To change your cPanel password, see How to reset your cPanel password.
- Your email password is managed in your provider's console (Microsoft 365 or Google Workspace), not in cPanel — read your mail at outlook.office.com or mail.google.com.
Troubleshooting this task
- Codes are rejected: Your phone's clock may be out of sync. Enable automatic date and time on the device, then try the new code.
- Lost your phone: Use the backup code you saved to log in, then re-set 2FA with your new device. No backup code for the client area? Start a chat with us and we'll help you verify your identity and reset it.
- Don't see the cPanel 2FA icon: It lives under cPanel -> Security. If it's missing, contact support.
- Locked out of the client area: Email support from the address on your account — include your domain so we can help.
Comments
0 comments
Please sign in to leave a comment.