Security (Imunify360, ModSecurity)

Configuring ModSecurity in cPanel

By the Domain India teamPublished 7 min read
Knowledge base article
Contents (7 sections)

ModSecurity is a web application firewall (WAF) that checks every request to your website before your code sees it, and blocks the ones that look like attacks. On Domain India cPanel hosting it runs for the whole server and is managed by us. This guide explains what it protects against, why there is no ModSecurity switch in your cPanel, and what to do when it blocks something legitimate.

Key takeaways

ModSecurity is always on for every account on our cPanel servers, using Imunify360's full ruleset. Customers can't turn it off per domain: the ModSecurity feature is disabled in cPanel's default feature list, so the ModSecurity icon doesn't appear in your cPanel. If it blocks a legitimate action, usually with a 403 Forbidden on one save, upload or form, open a ticket with the full URL, the exact time and your public IP address. We find the rule in the server logs and decide whether a precise exception is safe.

1. What ModSecurity protects against

ModSecurity compares each request with a set of rules that describe known attack patterns. On our cPanel servers the rules come from Imunify360, set to its full ruleset, with extra rules for popular content management systems. It stops a large share of automated attacks, including:

SQL injection
Form fields or URLs that try to smuggle database commands into your queries.
Cross-site scripting
Attempts to inject JavaScript that would run in your visitors' browsers.
File inclusion
Requests that try to make your code load a file from another server or from outside your site.
Path traversal
Requests using ../ patterns to reach files outside your website folder.

It works alongside your own security, not instead of it. Keeping WordPress, plugins and themes updated removes the weaknesses the rules are guarding. See common WordPress security issues.

2. Why there is no ModSecurity switch in your cPanel

cPanel has a ModSecurity page where an account can turn the firewall off for its domains. On Domain India shared hosting that feature is disabled in the default feature list that our cPanel plans use (measured on our server, 23 September 2026). So you won't find a ModSecurity icon under Security, and you can't switch it off for a domain.

This is deliberate. On a shared server, one site with its firewall off is an easy way in, and a compromised site can then be used against others. The protection is also the same on every plan: it is configured for the whole server, not per plan.

ModSecurity lines in .htaccess give a 500 error

Directives such as SecRuleEngine Off or SecRuleRemoveById are not allowed in .htaccess on our servers. Adding them makes your site return a 500 Internal Server Error. Ask support instead.

3. How to recognise a ModSecurity block

A WAF block has a typical pattern: the site works, but one action fails.

  • Saving a long post or a page-builder layout returns 403 Forbidden.
  • A contact form or checkout fails only when the message contains code, SQL-like words or unusual characters.
  • An upload or import fails with a 403 while normal pages load fine.
  • An admin plugin or an API call to your own site is refused.

If the whole site is down, or pages time out rather than showing a 403, it isn't a WAF rule. For other 403 causes, such as file permissions, .htaccess rules and IP blocks by the server firewall, see understanding and resolving HTTP error 403 Forbidden.

4. Report a false positive

A false positive is a legitimate request that a rule mistook for an attack. We can find the exact rule in the server logs, but only if you tell us which request to look for.

  1. Repeat the action once.
    Note the exact time, with the date, as close to the minute as you can.
  2. Copy the full URL
    from the address bar, and write down what you did, for example "clicked Update on the About page".
  3. Find your public IP address.
    Search "what is my IP" from the same device and connection.
  4. Open a ticket
    at /client/support/new when logged in, or at /support/ticket, with those details.
  5. Wait for our reply before changing things.
    We check the log entry and the rule that fired, and decide whether a precise exception is safe for your site.

Don't disable security plugins, loosen file permissions or rename files to get round a block. It rarely helps and weakens the site.

5. ModSecurity and WordPress

WordPress sites meet ModSecurity most often when:

  • saving posts that contain HTML, scripts or embed codes;
  • saving complex page-builder layouts;
  • running import tools or plugins that send large or unusual requests;
  • a security plugin scans the site through web requests.

For a one-off block, report it as in section 4. If the block comes from a plugin that sends code in form fields, check for an update to the plugin first; newer versions often send data in a way the rules accept.

6. What ModSecurity doesn't do

For how ModSecurity works in depth, its logs and its configuration on a server you manage yourself, read the comprehensive guide to ModSecurity.

7. Where Domain India fits

Every Domain India cPanel plan runs on servers with the same server-wide protection: ModSecurity with Imunify360's full ruleset, whatever plan you choose. If you need to configure ModSecurity yourself, with your own rules and exceptions, a VPS gives you root access. The live cards show today's prices, excluding 18% GST.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details
VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details
Can I turn off ModSecurity for my domain in cPanel?

No. On Domain India cPanel hosting, ModSecurity is managed for the whole server and the ModSecurity feature is disabled in cPanel for customer accounts, so there is no per-domain switch. If it blocks something legitimate, open a ticket with the URL, the time and your IP address.

Why can't I find ModSecurity in my cPanel?

The ModSecurity feature is disabled in the default feature list our cPanel plans use, so the icon isn't shown. ModSecurity is still active and protecting your site.

How do I know if ModSecurity blocked my request?

The usual sign is a 403 Forbidden error on one specific action, such as saving a post, submitting a form or uploading a file, while the rest of the site works. If the whole site is down or times out, the cause is something else.

What should I send support about a ModSecurity block?

The full URL, the exact date and time you repeated the action, what you did, and your public IP address. With those, support can find the rule that fired in the server logs.

Can I add SecRuleEngine Off to .htaccess?

No. ModSecurity directives aren't allowed in .htaccess on our servers, and adding them gives your site a 500 error. Ask support to review the rule instead.

Is ModSecurity protection different on higher cPanel plans?

No. ModSecurity and Imunify360 are configured for the whole server, so every account on it gets the same protection, whatever plan it is on.

Ready to get a blocked action working again? Collect the URL, the time and your IP address and open a support ticket. Support is on 24/7 live chat, and tickets get a first response within 15 minutes. Compare cPanel hosting plans if you are choosing a plan.

Blocked by the firewall?

Send us the URL, the exact time and your public IP address, and we will find the rule and help you get it working.

Open a ticket

Ready when you are

Get cPanel hosting from ₹125/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
ModSecurity on cPanel Hosting: Blocks and False Positives