Connecting to a MySQL database remotely means reaching your hosting database from somewhere other than your website: a database tool on your laptop, a script on your own computer, or a reporting app. On Domain India shared hosting, port 3306 is closed to outside connections, so a direct connection does not work. The way in is an SSH tunnel.
Adding your IP address under Remote Database Access in cPanel, or as an access host in DirectAdmin, does not open port 3306; the server firewall still blocks it. Instead, ask support to enable jailed SSH on your account, add your SSH public key, run ssh -N -L 3307:localhost:3306 username@server-ip, and connect your tool to 127.0.0.1 on port 3307 with your usual database name, user and password. Because the tunnel does not depend on your IP address, a dynamic IP is no longer a problem.
This page is the short version. For every step on macOS, Linux and Windows (including PuTTY), tool settings for MySQL Workbench, DBeaver and HeidiSQL, and troubleshooting, read Securing MySQL access with SSH tunnels.
1. Why a direct connection fails on shared hosting
Your website talks to its database as localhost, on the same server, so it never needs port 3306 from outside. A tool on your own computer is outside the server. Port 3306 (MySQL) is closed to outside connections on our cPanel, DirectAdmin and Webuzo servers (measured September 2026), so a direct connection is refused or times out.
Older guides told you to open cPanel's Remote Database Access page, or DirectAdmin's access hosts, and add your IP address or the % wildcard. Those settings only tell MySQL which addresses may log in. They do not open the port in the server firewall, so on their own they change nothing.
The % wildcard lets the database accept logins from any address on the internet. It is not needed for a tunnel and only widens the risk. If you added % or old IP addresses in the past, remove them.
2. How the tunnel gets you in
Port 22 (SSH) is open on our Linux shared servers. An SSH tunnel logs in to your hosting account over SSH and carries your database traffic inside that encrypted connection. MySQL sees the connection coming from the server itself, and nothing but SSH is exposed to the internet.
This also solves the old dynamic-IP problem. You don't allow-list your IP address anywhere, so it doesn't matter if your broadband or mobile connection changes address every day.
3. Set it up
- Ask for jailed SSH.Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo). It is off by default; ask support to enable it for your account by live chat or a ticket at /client/support/new.
- Add your SSH key.SSH login on our servers uses a key, not a password. Create a key pair and add the public key to your account, as shown in enabling and accessing jailed SSH.
- Find your login details.In the client area, open My Hosting, click Manage on the service and open the Access tab. It shows your username and server IP.
- Open the tunnel.In Terminal (macOS, Linux) or PowerShell (Windows 10 and 11), run
ssh -N -L 3307:localhost:3306 username@server-ip. Leave the window open while you work. - Connect your tool.Use host
127.0.0.1, port3307, and your database user, password and database name.
Use 127.0.0.1, not localhost, in the tool on your computer: many MySQL clients treat localhost as a local socket and skip the tunnel. Local port 3307 avoids a clash with any MySQL server you run on your own computer; any free port works.
4. The connection settings
| Setting | Through the tunnel | From your website on the same server |
|---|---|---|
| Host | 127.0.0.1 | localhost |
| Port | 3307 (the local port you chose) | 3306 (the default) |
| Database name | Full name with your account prefix, e.g. acme_shop | Same |
| Username | Full name with your account prefix, e.g. acme_shopuser | Same |
| Password | The database user's password | Same |
You can see the database names and users in your control panel: Manage My Databases in cPanel, or Account Manager › Databases in DirectAdmin. If you are not sure of the details, work through how to connect to the MySQL database.
Tools such as MySQL Workbench (Standard TCP/IP over SSH), DBeaver (the SSH tab) and HeidiSQL (MySQL (SSH tunnel)) can open the tunnel for you. Give them your server IP, port 22, your hosting username and your private key file, and use 127.0.0.1 port 3306 for the MySQL part.
5. When a tunnel is not the right answer
- An app on another server that needs the database all the time. A tunnel is built for a person at a desk. For a live application, keep the app and the database on the same hosting account, or move both to a VPS, where you control MySQL and the firewall yourself.
- Windows (Plesk) hosting. It has no SSH, so there is nothing to tunnel through, and its databases are Microsoft SQL Server. Ask support about remote access for a Windows plan.
- Everyday edits. For browsing tables, running a query or importing a file, phpMyAdmin in your control panel needs no setup at all.
6. Where Domain India fits
Every cPanel, DirectAdmin and Webuzo plan includes MySQL databases, phpMyAdmin and jailed SSH on request, so a tunnel works on any of them. Prices on the card are live and exclude 18% GST.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
If you need MySQL listening on the internet, your own database configuration or root access, a VPS is self-managed and gives you full control of the server.
Frequently asked questions
Can I connect to my Domain India MySQL database remotely?
Yes, through an SSH tunnel. Port 3306 is closed to outside connections on Domain India shared servers, so a direct connection fails. Ask support to enable jailed SSH, add your SSH key, open a tunnel, and connect your tool to 127.0.0.1 on the local port.
I added my IP under Remote Database Access. Why can't I connect?
The Remote Database Access list only controls which addresses MySQL accepts logins from. It does not open port 3306 in the server firewall, so outside connections are still blocked. An SSH tunnel goes through port 22 instead.
What if my IP address changes every day?
With an SSH tunnel it does not matter. You do not allow-list your IP address anywhere, so a dynamic IP from your broadband or mobile provider works without any change.
What hostname and port do I use?
Through a tunnel, use host 127.0.0.1 and the local port you chose, such as 3307. Your website on the same server uses localhost and port 3306. The database name and user include your account prefix.
Is SSH included with Domain India shared hosting?
Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo). It is off by default; ask support to enable it for your account. Login uses an SSH key, not a password. Windows (Plesk) hosting has no SSH.
Ready to connect? Read the full SSH tunnel guide, ask support to enable jailed SSH on your account, or compare VPS plans if you need a database open to other servers.
Tell us your hosting username or domain, and we will enable jailed SSH on your account and help you add your SSH key.
Ask our support team