Your Ultra Web Hosting account controls your website, your email, your DNS, and your billing, which makes the login to it a single point of failure worth protecting. Two-factor authentication (2FA) adds a second lock on top of your password, so that even if someone steals or guesses that password they still cannot get in. This guide explains how 2FA works, which app to use, and exactly how to turn it on for cPanel, your client area, WordPress, and your email provider.
- What Two-Factor Authentication Is and Why a Password Is Not Enough
- Choosing an Authenticator App
- Enable 2FA on cPanel
- Enable 2FA on Your Client Area and Billing Login
- Save Your Backup Codes and Plan for a Lost Phone
- Enable 2FA on WordPress
- Enable 2FA on Your Email Provider
- Best Practices for Account Security
- Troubleshooting Common Issues
One App, Two Logins to Protect First
Install a TOTP authenticator app on your phone, then turn on 2FA in the two places that matter most: your cPanel and your Ultra Web Hosting client area. Each one shows a QR code you scan once, after which every login asks for a rotating six-digit code.
- Use an authenticator app, not SMS text messages
- cPanel: Security > Two-Factor Authentication
- Client area: Profile > Security Settings at my.ultrawebhosting.com
- Save the backup codes offline before you finish
Store Your Backup Codes Before You Enable
When you turn on 2FA you are handed a set of one-time backup codes and, for cPanel, a secret key. These are your only way back in if you lose or wipe your phone. Copy them somewhere safe that is not on the phone itself before you click the final confirm button. People lock themselves out every week because they skipped this one step.
- Write the codes down or store them in a password manager
- Never keep them only on the device running the authenticator
- Lost everything? We can verify your identity and reset 2FA (Section 05)
01. What Two-Factor Authentication Is and Why a Password Is Not Enough
A password is a single secret. If an attacker learns it, they are you. And passwords leak constantly: through data breaches at unrelated sites where you reused the same password, through phishing pages that copy a real login screen, and through credential stuffing, where bots try millions of stolen username and password pairs against every login they can find. None of those attacks require the attacker to be clever about your specific account. They just need your password to exist somewhere in a dump.
Two-factor authentication closes that gap by requiring two different kinds of proof to log in:
- Something you know - your password.
- Something you have - a rotating six-digit code generated on your phone.
The code is a TOTP, a Time-based One-Time Password. Your authenticator app and the server share a secret when you scan the setup QR code, and from then on both sides independently compute the same six-digit number, which changes every 30 seconds. Because it is derived from the shared secret and the current time, a code that leaks is worthless within half a minute, and an attacker who only has your password never sees a valid code at all.
A compromised hosting login is worse than most because it cascades. From cPanel an attacker can read your email, plant malware in your website files, export your databases, and change your DNS to hijack mail. From the client area they can see billing details and open support requests as you. 2FA on these two logins blocks the overwhelming majority of automated takeover attempts.
02. Choosing an Authenticator App
You need a TOTP authenticator app on your phone or computer. Any of these work and are free. Pick one and use it for everything:
- Google Authenticator - simple, widely used, now supports encrypted cloud backup tied to your Google account.
- Microsoft Authenticator - good if you also use Microsoft 365, with cloud backup and push approvals for Microsoft accounts.
- Authy - multi-device with encrypted backups, so a lost phone is far less painful. A solid default for most people.
- 1Password - if you already use it as a password manager, it stores TOTP codes next to the matching login, so both halves live in one encrypted vault.
TOTP apps generate codes on the device itself with no network connection, so they keep working on a plane, in a dead zone, or on a fresh phone you have restored from backup. They are also safer than text-message codes. SMS can be intercepted through SIM-swap fraud, where an attacker convinces your mobile carrier to move your number to their phone. A code that never travels over the cellular network cannot be stolen that way. Where a service offers both, choose the authenticator app.
03. Enable 2FA on cPanel
cPanel is where your website files, databases, email accounts, and DNS live, so this is the login to protect first. Setup takes about two minutes.
- Log in to cPanel for your account.
- In the Security section, click Two-Factor Authentication.
- Click Set Up Two-Factor Authentication. cPanel displays a QR code and, next to it, an Account and a text Key.
- Open your authenticator app and add a new account. Choose Scan a QR code and point the camera at the code on screen. If the camera will not focus, use the manual option and type the text key instead.
- Your app now shows a six-digit code for this account that refreshes every 30 seconds. Type the current code into the Security Code box in cPanel.
- Click Configure Two-Factor Authentication. cPanel confirms it is enabled.
From now on, every cPanel login asks for your password and then the current six-digit code from your app. Log out and back in once to confirm it works before you move on.
Before you click the final confirm button, copy the text Key shown next to the QR code and store it offline. If you ever lose the phone, re-entering that key in a new authenticator app regenerates the same codes. If you have already lost both the phone and the key, do not panic: contact us and we can verify your identity and clear 2FA from the account so you can set it up again. For a refresher on the login itself, see Getting Started with cPanel and How to Change Your cPanel Password.
04. Enable 2FA on Your Client Area and Billing Login
Your client area at my.ultrawebhosting.com is the login for billing, domains, and support. It is separate from cPanel and needs its own 2FA. The good news is you can add it to the same authenticator app.
- Sign in at
my.ultrawebhosting.comwith your client area email and password. - Click your name in the top right and choose Security Settings (also reachable from the account or profile menu).
- Find Two-Factor Authentication and click Click here to Enable.
- Choose the Time Based Tokens (authenticator app) method and continue.
- Scan the QR code with your authenticator app, exactly as you did for cPanel. The app adds a second entry.
- Type the current six-digit code into the confirmation box and submit.
- The client area displays your backup codes. Save these now (see Section 05), then finish.
Your authenticator app is meant to hold many accounts at once. After this you will have at least two entries, one for cPanel and one for the client area, each with its own rotating code. Label them clearly in the app so you grab the right code at the right prompt. Adding your email, WordPress, and other logins to the same app keeps everything in one place.
05. Save Your Backup Codes and Plan for a Lost Phone
Backup codes are single-use passwords that get you in when your authenticator is unavailable, for example when your phone is lost, broken, or reset. Treat them like spare keys to your house.
- Store them offline. Write them on paper and put it somewhere safe, or save them in your password manager. Do not store them only on the phone that runs the authenticator, because if that phone dies you lose both at once.
- Use each one only once. A backup code is consumed the moment you log in with it. Cross it off your list.
- Regenerate if they run low or leak. Both cPanel and the client area let you generate a fresh set, which invalidates the old ones.
If you lose your phone, here is the order to recover access:
- Restore the app. If your authenticator had cloud backup (Authy, 1Password, or the newer Google and Microsoft apps), install it on a new phone and your codes come back automatically.
- Use a backup code. No cloud backup? Log in with one of the backup codes you saved, then disable and re-enable 2FA to pair a new device.
- Use the cPanel key. For cPanel specifically, re-enter the text key you saved in Section 03 into a new authenticator app to regenerate the same codes.
- Contact support. If you have lost the phone, the backup codes, and the key, open a ticket. We will verify your identity and reset 2FA on the account so you can start fresh.
2FA is designed so that no one, including us, can see or bypass your codes without proving who you are. That is what makes it secure, and it is also why identity verification takes a little time when you are locked out. The five minutes it takes to save your backup codes now is far shorter than the recovery process later. For password recovery unrelated to 2FA, see How Do I Change My Password.
06. Enable 2FA on WordPress
If you run WordPress, its admin login (/wp-admin) is a favorite target for the same credential-stuffing bots that hit hosting logins. WordPress has no built-in 2FA, so you add it with a plugin.
- In your WordPress dashboard, go to Plugins > Add New.
- Search for a reputable 2FA plugin such as Two-Factor, Wordfence Login Security, or the two-factor feature built into a security suite you already run.
- Install and activate it, then open its settings from your user profile or the plugin menu.
- Choose the authenticator app (TOTP) method, scan the QR code with the same app you used above, and confirm with a six-digit code.
- Save the plugin's backup codes alongside your others.
2FA only protects the accounts that have it turned on. Require it for every administrator on the site, not just yourself, since a single admin without 2FA is the weak link an attacker will find. For the full set of steps that make a WordPress site hard to break into, see WordPress Security Hardening.
07. Enable 2FA on Your Email Provider
Email is the master key to almost everything else, because most password resets are sent there. Whoever controls your inbox can reset your other accounts one by one. Protect it accordingly.
If your mail runs through a provider rather than cPanel, turn on 2FA in that provider's account settings:
- Google Workspace - go to your Google Account, then Security > 2-Step Verification, and add an authenticator app. Workspace admins can require 2-Step Verification for every user in the Admin console.
- Microsoft 365 - sign in at
myaccount.microsoft.com, open Security info, and add the Microsoft Authenticator app or another TOTP app. Administrators can enforce multi-factor authentication for the whole tenant with a Conditional Access or security-defaults policy.
If your email lives in cPanel on your Ultra Web Hosting account rather than an external provider, the protection comes from securing the cPanel login itself (Section 03) and using strong per-mailbox passwords.
Enabling 2FA on your Google or Microsoft account may prompt older mail clients to reauthenticate. Modern apps handle this cleanly. Any older client that only supports basic password authentication may need an app-specific password, which those providers generate for you in the same security settings.
08. Best Practices for Account Security
2FA is the strongest single upgrade you can make, but it works best as part of a few habits that reinforce each other:
Password Only
One password, reused across several sites, with no second factor. A single breach anywhere exposes every account that shares it.
- Reused passwords chain together across services
- A leaked password is an immediate login
- Nothing stops an automated takeover
Unique Passwords, a Manager, and 2FA
A long unique password per site, stored in a password manager, with 2FA on every account that offers it. A breach at one site stays contained to that site.
- Every login has its own password
- The manager remembers them so you do not have to
- 2FA blocks logins even when a password leaks
- Use a unique password for every account. A password manager (1Password, Bitwarden, and similar) generates and stores long random passwords so reuse is never a temptation.
- Turn on 2FA everywhere it is offered, starting with the highest-value accounts: hosting, email, banking, and your domain registrar.
- Never share a code with anyone. No legitimate staff member, including ours, will ever ask you to read out a 2FA code. Anyone who does is trying to log in as you right now.
- Keep backup codes offline and separate from the device that generates your codes.
- Review your logins periodically. Remove old admin accounts and rotate any password you suspect was exposed. For the wider account and firewall protections we run on our side, see Firewall and Security Protection.
A common scam is a caller or email claiming to be support who needs your 2FA code to fix an urgent problem. The code exists precisely so that no one else can log in as you. Do not read it out, do not type it into a page you reached from a link in an unexpected message, and contact us directly through your client area if you are unsure whether a request is real.
09. Troubleshooting Common Issues
My code is rejected as invalid. The most common cause is your phone's clock drifting out of sync, since TOTP depends on accurate time. Set your phone's date and time to update automatically, then try the next code that appears.
The code expired before I could type it. Codes rotate every 30 seconds. Wait for a fresh one and enter it promptly rather than typing one that is about to change.
I scanned the QR code but got no account in my app. Some cameras struggle with on-screen codes. Use the manual entry option in your authenticator and type the text key shown next to the QR code instead.
I lost my phone. Follow the recovery order in Section 05: restore from the app's cloud backup, or use a backup code, or the saved cPanel key, and only then contact support for an identity-verified reset.
2FA is not offered on a service I use. Some older tools do not support it. Where it is missing, lean harder on a unique strong password and a password manager, and enable 2FA on the email account tied to that service so its password resets are protected.
Locked Out or Not Sure Where to Start?
If you have lost your phone and your backup codes, or you would like a hand turning 2FA on across your account, open a ticket. We will verify your identity, reset 2FA where needed, and walk you through securing each login.
Open a Support TicketQuick Recap: 2FA in Six Steps
If you only do six things from this guide, do these:
- Install a TOTP authenticator app such as Authy, Google Authenticator, Microsoft Authenticator, or 1Password. Use an app, not SMS.
- Enable 2FA on cPanel under Security > Two-Factor Authentication, and save the text key offline.
- Enable 2FA on your client area under Profile > Security Settings at my.ultrawebhosting.com.
- Save every set of backup codes offline, separate from the phone that runs the app.
- Protect WordPress and email too, with a 2FA plugin for WordPress and the built-in setting for Google Workspace or Microsoft 365.
- Use a password manager and unique passwords, and never share a code with anyone.
Last updated July 2026 · Browse all Hosting Control Panel articles
