How to Restrict cPanel and Webmail Access by IP Address

Lock down your cPanel and webmail logins to trusted IP addresses so attackers cannot even reach the login page from unknown networks.

· Updated · 983 views

If only you and your team access cPanel, restricting logins to known IP addresses is one of the strongest protections you can add. An attacker who never sees the login page cannot brute-force it.

Before You Begin

You need a static IP address, or at least a predictable range. Find your current IP by searching "what is my IP" in your browser. Note that many Kenyan home and mobile connections use dynamic IPs that change, so use this method only if your IP is stable, such as an office line.

Restricting Access with .htaccess

You can protect the cPanel and webmail login paths by adding rules through Security → IP Blocker in reverse, or by using directory protection. The simplest supported method is the cPanel IP Blocker to deny everything except your range, but for login-only restriction, contact support to apply a server-level rule safely.

Safer Alternatives for Dynamic IPs

If your IP changes often, IP restriction will lock you out. Use these instead:

  • Two-factor authentication on cPanel (Security → Two-Factor Authentication)
  • A very strong, unique password of 16+ characters
  • cPHulk brute-force protection, enabled by default on our servers

If You Get Locked Out

Should your IP change and block you, open a ticket from any device or message WhatsApp on +254 796 358081 and we will whitelist your new address after verifying your identity.

Tip: Combine IP restriction with two-factor authentication for the strongest possible login security.

Was this article helpful?

Your feedback helps us improve our documentation.

Still Need Help?

Our support team is available 24/7 to assist you.