Restricting cPanel login access to trusted IP addresses adds a powerful barrier against unauthorized access attempts. Here’s how to configure it safely.
The Concept Behind IP Restriction
Even with a strong password, your cPanel login page is exposed to the entire internet by default. IP-based access restriction limits who can even reach the login screen, allowing connections only from specific, trusted IP addresses — such as your office network or home connection.
Why This Is Effective
Attackers scanning for vulnerable hosting panels rely on being able to reach the login page from anywhere. If your cPanel only accepts connections from a pre-approved list of IP addresses, automated attacks from unknown locations are blocked before they even see a login prompt.
How to Restrict Access in cPanel/WHM
- Log in to WHM as the root or reseller administrator.
- Navigate to Security Center > cPHulk Brute Force Protection or Host Access Control, depending on your WHM version.
- Under Host Access Control, add the IP addresses or ranges that should be allowed to access cPanel, FTP, and WHM services.
- Set the default policy to deny all other connections.
- Save changes and test access from an approved and a non-approved connection to confirm the rule works.
Important Considerations
- If your team works from dynamic or changing IP addresses, consider a VPN with a fixed exit IP instead of restricting to individual home addresses.
- Always keep a documented list of approved IPs and review it quarterly.
- Avoid locking yourself out — test changes in a separate browser session before closing your current one.
The Payoff
IP restriction won’t replace strong authentication, but layered alongside it, it dramatically shrinks your attack surface by making the login page effectively invisible to the rest of the internet.