If only you and your team access cPanel, restricting logins to known IP addresses is one of the strongest protections you can add. An attacker who never sees the login page cannot brute-force it.
Before You Begin
You need a static IP address, or at least a predictable range. Find your current IP by searching "what is my IP" in your browser. Note that many Kenyan home and mobile connections use dynamic IPs that change, so use this method only if your IP is stable, such as an office line.
Restricting Access with .htaccess
You can protect the cPanel and webmail login paths by adding rules through Security → IP Blocker in reverse, or by using directory protection. The simplest supported method is the cPanel IP Blocker to deny everything except your range, but for login-only restriction, contact support to apply a server-level rule safely.
Safer Alternatives for Dynamic IPs
If your IP changes often, IP restriction will lock you out. Use these instead:
- Two-factor authentication on cPanel (Security → Two-Factor Authentication)
- A very strong, unique password of 16+ characters
- cPHulk brute-force protection, enabled by default on our servers
If You Get Locked Out
Should your IP change and block you, open a ticket from any device or message WhatsApp on +254 796 358081 and we will whitelist your new address after verifying your identity.
Tip: Combine IP restriction with two-factor authentication for the strongest possible login security.