ModSecurity is a web application firewall (WAF) that checks every request to your website before your code sees it, and blocks the ones that look like attacks. On Domain India cPanel hosting it runs for the whole server and is managed by us. This guide explains what it protects against, why there is no ModSecurity switch in your cPanel, and what to do when it blocks something legitimate.
ModSecurity is always on for every account on our cPanel servers, using Imunify360's full ruleset. Customers can't turn it off per domain: the ModSecurity feature is disabled in cPanel's default feature list, so the ModSecurity icon doesn't appear in your cPanel. If it blocks a legitimate action, usually with a 403 Forbidden on one save, upload or form, open a ticket with the full URL, the exact time and your public IP address. We find the rule in the server logs and decide whether a precise exception is safe.
1. What ModSecurity protects against
ModSecurity compares each request with a set of rules that describe known attack patterns. On our cPanel servers the rules come from Imunify360, set to its full ruleset, with extra rules for popular content management systems. It stops a large share of automated attacks, including:
It works alongside your own security, not instead of it. Keeping WordPress, plugins and themes updated removes the weaknesses the rules are guarding. See common WordPress security issues.
2. Why there is no ModSecurity switch in your cPanel
cPanel has a ModSecurity page where an account can turn the firewall off for its domains. On Domain India shared hosting that feature is disabled in the default feature list that our cPanel plans use (measured on our server, 23 September 2026). So you won't find a ModSecurity icon under Security, and you can't switch it off for a domain.
This is deliberate. On a shared server, one site with its firewall off is an easy way in, and a compromised site can then be used against others. The protection is also the same on every plan: it is configured for the whole server, not per plan.
Directives such as SecRuleEngine Off or SecRuleRemoveById are not allowed in .htaccess on our servers. Adding them makes your site return a 500 Internal Server Error. Ask support instead.
3. How to recognise a ModSecurity block
A WAF block has a typical pattern: the site works, but one action fails.
- Saving a long post or a page-builder layout returns 403 Forbidden.
- A contact form or checkout fails only when the message contains code, SQL-like words or unusual characters.
- An upload or import fails with a 403 while normal pages load fine.
- An admin plugin or an API call to your own site is refused.
If the whole site is down, or pages time out rather than showing a 403, it isn't a WAF rule. For other 403 causes, such as file permissions, .htaccess rules and IP blocks by the server firewall, see understanding and resolving HTTP error 403 Forbidden.
4. Report a false positive
A false positive is a legitimate request that a rule mistook for an attack. We can find the exact rule in the server logs, but only if you tell us which request to look for.
- Repeat the action once.Note the exact time, with the date, as close to the minute as you can.
- Copy the full URLfrom the address bar, and write down what you did, for example "clicked Update on the About page".
- Find your public IP address.Search "what is my IP" from the same device and connection.
- Open a ticketat /client/support/new when logged in, or at /support/ticket, with those details.
- Wait for our reply before changing things.We check the log entry and the rule that fired, and decide whether a precise exception is safe for your site.
Don't disable security plugins, loosen file permissions or rename files to get round a block. It rarely helps and weakens the site.
5. ModSecurity and WordPress
WordPress sites meet ModSecurity most often when:
- saving posts that contain HTML, scripts or embed codes;
- saving complex page-builder layouts;
- running import tools or plugins that send large or unusual requests;
- a security plugin scans the site through web requests.
For a one-off block, report it as in section 4. If the block comes from a plugin that sends code in form fields, check for an update to the plugin first; newer versions often send data in a way the rules accept.
6. What ModSecurity doesn't do
- It rarely explains a slow site. If pages are slow, the cause is usually elsewhere: heavy plugins, slow database queries or your account's resource limits. See how to check your hosting resource usage and my website is slow.
- It doesn't clean a hacked site. It blocks attack requests; it doesn't remove malware that is already there. See the security checklist for a hacked website.
- It doesn't replace updates. Rules catch known patterns; updating closes the hole.
For how ModSecurity works in depth, its logs and its configuration on a server you manage yourself, read the comprehensive guide to ModSecurity.
7. Where Domain India fits
Every Domain India cPanel plan runs on servers with the same server-wide protection: ModSecurity with Imunify360's full ruleset, whatever plan you choose. If you need to configure ModSecurity yourself, with your own rules and exceptions, a VPS gives you root access. The live cards show today's prices, excluding 18% GST.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
Can I turn off ModSecurity for my domain in cPanel?
No. On Domain India cPanel hosting, ModSecurity is managed for the whole server and the ModSecurity feature is disabled in cPanel for customer accounts, so there is no per-domain switch. If it blocks something legitimate, open a ticket with the URL, the time and your IP address.
Why can't I find ModSecurity in my cPanel?
The ModSecurity feature is disabled in the default feature list our cPanel plans use, so the icon isn't shown. ModSecurity is still active and protecting your site.
How do I know if ModSecurity blocked my request?
The usual sign is a 403 Forbidden error on one specific action, such as saving a post, submitting a form or uploading a file, while the rest of the site works. If the whole site is down or times out, the cause is something else.
What should I send support about a ModSecurity block?
The full URL, the exact date and time you repeated the action, what you did, and your public IP address. With those, support can find the rule that fired in the server logs.
Can I add SecRuleEngine Off to .htaccess?
No. ModSecurity directives aren't allowed in .htaccess on our servers, and adding them gives your site a 500 error. Ask support to review the rule instead.
Is ModSecurity protection different on higher cPanel plans?
No. ModSecurity and Imunify360 are configured for the whole server, so every account on it gets the same protection, whatever plan it is on.
Ready to get a blocked action working again? Collect the URL, the time and your IP address and open a support ticket. Support is on 24/7 live chat, and tickets get a first response within 15 minutes. Compare cPanel hosting plans if you are choosing a plan.
Send us the URL, the exact time and your public IP address, and we will find the rule and help you get it working.
Open a ticket