Your Domain India account controls your domains, hosting, email and invoices. Anyone who gets into it can change your nameservers, reset your control panel password or unlock a domain for transfer. This guide lists the settings and habits that keep it safe, and what to do if you think someone else has been in.
Use a long, unique password kept in a password manager, and turn on two-factor authentication under Account › Security. Give staff and web designers their own logins as team members instead of sharing yours, and keep the email address on your account secure, because password resets go there. Keep the transfer lock on your domains. Domain India support will never ask for your password, a 2FA code or card details.
1. Use a strong, unique password
- Make it long and random. At least 12 characters is a good target; the client area requires at least 8, with upper- and lower-case letters, a number and a symbol.
- Never reuse it. If another website you use is breached, a reused password opens your Domain India account too.
- Use a password manager to generate and store it. See the best password managers for personal and business use.
- Change it at once if it may have been exposed: at
/client/security/password, enter your current password, then the new one twice.
There is no need to change a strong, unique password on a fixed schedule. Change it when there is a reason: a suspected leak, a departed employee who knew it, or a device you lost.
2. Turn on two-factor authentication
Two-factor authentication (2FA) means a sign-in needs your password and a six-digit code from an authenticator app on your phone. A stolen password alone is then not enough.
- Open Account › Security(
/client/security/2fa) and click Enable 2FA. - Confirm your password,then scan the QR code with an authenticator app such as Google Authenticator, Authy or Microsoft Authenticator.
- Save the recovery codessomewhere other than your phone, such as a password manager.
- Enter the six-digit codefrom the app to finish. You are signed out and sign in again with a code.
On the code screen, Remember this device for 30 days skips the code on that browser. Use it only on a computer nobody else uses. Before you change phones, move 2FA to the new phone while you still have the old one. If you lose the phone and have no other device with the app, open a ticket from your account email. The full guide is how to enable two-factor authentication.
3. Protect the email address on your account
Password reset links, invoices and security notices all go to your account email. Whoever controls that mailbox can take over your Domain India account.
- Secure the mailbox itself with a strong password and its own two-factor authentication.
- Don't use an address on a domain you are about to move or let expire. If the domain stops working, so does your email, and with it your password resets.
- Keep it current under Account › Profile.
4. Never share your login
5. Sign in safely
- Check the address. Sign in only at
domainindia.com/client/login, with the padlock showing. Type it or use a bookmark rather than a link in an email. - Treat unexpected emails with suspicion. Messages about a "suspended account" or an "expiring domain" that push you to sign in through a link are a common phishing trick. Open the client area yourself to check.
- Sign out on shared computers and don't let the browser save your password there.
- Too many wrong attempts lock sign-in. After 10 failed sign-ins within 15 minutes, sign-in for that email address is locked for up to 15 minutes, and a password reset does not lift it. Repeated locks you did not cause can mean someone is guessing your password: turn on 2FA if you have not.
6. Secure your domains
- Keep the transfer lock on. It stops the domain being moved to another registrar and does not block nameserver or DNS changes. You manage it on the domain's Transfer tab. See understanding domain lock.
- Guard the EPP code. Anyone with the code of an unlocked domain can try to transfer it. Get it only when you are moving the domain, and give it only to the receiving registrar.
- Keep registrant contacts accurate on the domain's Contacts tab. See changing your domain's WHOIS information.
7. Secure your hosting
Your control panel (cPanel, DirectAdmin, Webuzo or Plesk) has its own login, separate from the client area.
- Use a different strong password for the control panel. You can reset it from the hosting service's page in the client area; see how to reset your cPanel password.
- Turn on cPanel's own two-factor authentication. It works for customers and protects direct logins to cPanel. Add it as a separate entry in your authenticator app.
- Remove what you don't use: old FTP accounts, email accounts of people who have left, and unused WordPress admin users.
- Keep websites updated. Most hacked sites run an outdated CMS, plugin or theme. See what to do if your website has been hacked.
- SSH, if you use it, is key-only. Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo); it is off by default, so ask support to enable it for your account.
8. If you think someone has been in your account
- Change your client-area passwordat once, and the password of the email account it uses.
- Turn on two-factor authentication,or if it was already on, generate new recovery codes.
- Review Account › Team members and Account › Connected apps.Remove anyone or anything you don't recognise.
- Check each domain:nameservers, the transfer lock on the Transfer tab, and the contacts.
- Check your hosting:change the control panel password, and look for unknown files, email accounts or forwarders.
- Open a ticketat /client/support/new or /support/ticket and describe what you noticed and when. Don't include any passwords.
If a domain you did not unlock shows as Unlocked, lock it again on its Transfer tab straight away and tell support in a ticket. A transfer needs both an unlocked domain and its EPP code.
Support is available by 24/7 live chat, and tickets get a first response within 15 minutes; resolution can take longer depending on the issue. There is no phone support.
Frequently asked questions
How do I turn on two-factor authentication for my Domain India account?
Open Account, Security in the client area, click Enable 2FA, confirm your password, scan the QR code with an authenticator app, save the recovery codes and enter the six-digit code. From then on every sign-in asks for a code.
Will Domain India support ever ask for my password?
No. Domain India support never asks for your password, a 2FA code, recovery codes, card number, CVV or payment OTP. If someone claiming to be support asks, do not share them and report it in a ticket.
How can my web designer work on my account without my password?
Invite them under Account, Team members with only the permissions they need. They get their own login, and you can suspend or remove their access at any time.
Why is my client area sign-in locked?
After 10 failed sign-ins within 15 minutes, sign-in for that email address is locked for up to 15 minutes. A password reset does not lift the lock; wait, then sign in with the right password.
Is my control panel protected by client-area two-factor authentication?
No. The control panel has its own login. cPanel has its own two-factor authentication, which customers can turn on in cPanel's Security section.
What should I do if I think my account was accessed by someone else?
Change your client-area and email passwords, turn on two-factor authentication, remove unknown team members and connected apps, check your domains and hosting, and open a support ticket describing what you noticed.
Ready to tighten things up? Sign in to the client area, turn on two-factor authentication, and check the transfer lock on your domains.
Two-factor authentication takes about two minutes to set up with an authenticator app on your phone.
Open Security