Security & SSL

Security Best Practices for DirectAdmin Hosting

By the Domain India teamPublished 5 min read
Knowledge base article
Contents (4 sections)

On Domain India DirectAdmin hosting, the server's security is managed for you: the firewall, Imunify360 malware scanning, CloudLinux account isolation and the PHP builds. Your part is your account and your website: logins, the apps you install, file permissions, HTTPS and your own copy of your backups. This page is the quick checklist for that part.

For the full guide

Every step below is explained in How to secure and optimize your DirectAdmin hosting environment, which also covers PHP versions, logs, email security and running DirectAdmin on your own VPS.

Key takeaways

Use unique passwords from a password manager and turn on two-factor authentication for your client area. Keep WordPress, plugins and themes updated and delete what you don't use. Force HTTPS with the free Let's Encrypt certificate, set folders to 755 and files to 644, block sensitive files, and download a copy of your weekly JetBackup backup now and then.

1. The checklist

AreaWhat to do
PasswordsA long, unique password for the client area, DirectAdmin, every mailbox, FTP account and WordPress admin, kept in a password manager
Two-factorTurn it on for your client area under Account › Security; that account can reset your DirectAdmin password
Panel loginOpen DirectAdmin with the button in the client area, so you don't need to type the panel password
UpdatesUpdate WordPress core, plugins and themes promptly; delete unused ones and old test copies
HTTPSIssue free Let's Encrypt SSL in DirectAdmin, then redirect all traffic to https
PermissionsFolders 755, files 644, never 777
Sensitive filesKeep .env files and credentials above public_html; block the ones that must stay
Directory listingAdd Options -Indexes to .htaccess
BackupsDownload a copy of your JetBackup backup before big changes and once a month
LogsCheck access and error logs when something looks wrong

2. Force HTTPS and block sensitive files

Once the padlock shows, add these lines at the top of public_html/.htaccess. They use the current Apache 2.4 syntax; the old Order Allow,Deny lines in many older guides are outdated.

apache
RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

Options -Indexes

<Files "wp-config.php">
    Require all denied
</Files>
Two .htaccess lines that break DirectAdmin sites

On our DirectAdmin servers, Options accepts only Indexes, IncludesNOEXEC, MultiViews, SymLinksIfOwnerMatch, FollowSymLinks and None; any other value gives a 500 error. And because PHP doesn't run as an Apache module, any php_value or php_flag line also gives a 500. If a site breaks after an edit, remove the new line and see troubleshooting a 500 internal server error.

For permissions in detail, see how to manage file permissions in DirectAdmin.

3. Backups and logs

Every DirectAdmin account is backed up weekly with JetBackup 5, on Sunday, and the last 5 copies are kept. You can restore or download them yourself from JetBackup in DirectAdmin; see backup and restore with JetBackup. Keep your own downloaded copy as well, somewhere you control.

For access and error logs, see how to access and analyse logs in DirectAdmin. Repeated requests to wp-login.php or xmlrpc.php, or to admin pages you don't have, are the usual signs of automated attacks.

4. If your site has been hacked

Imunify360 runs on our DirectAdmin server, but no scanner catches everything. If you see a defaced page, spam links or a browser warning, work through the security checklist for a hacked or defaced website, then change every password.

Imunify360 Malware Scanner inside DirectAdmin with Malicious, Scan and History tabs and no malicious files found
Imunify360's malware scanner, as it appears inside DirectAdmin.
DA Starter
₹100/mo + GST
  • 10 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 5 Email Accounts
See plan details

Prices on the cards exclude 18% GST.

Do I need to install a firewall or malware scanner on DirectAdmin hosting?

No. On Domain India DirectAdmin shared hosting, the CSF firewall and Imunify360 run server-wide for every account, and you can't install server software. Your part is logins, updates, permissions, HTTPS and backups.

How do I turn on two-factor authentication?

In the Domain India client area, open Account › Security and click Enable 2FA, then scan the QR code with an authenticator app and enter the six-digit code.

What file permissions should I use on DirectAdmin?

Folders 755 and files 644. Never use 777: websites on our servers don't need it, and it lets anything on the account rewrite the file.

How often is my DirectAdmin account backed up?

Weekly. JetBackup 5 backs up every DirectAdmin account on Sunday and keeps the last 5 copies, which you can restore or download from JetBackup in DirectAdmin.

Why does my site show a 500 error after I edited .htaccess?

On our DirectAdmin servers, php_value and php_flag lines are not allowed, and Options accepts only a short list of values. Remove the new line and the site comes back.

Ready to tighten up your site? Turn on two-factor authentication, work through the full DirectAdmin security guide, or compare DirectAdmin hosting plans. If something looks wrong, open a support ticket or use the 24/7 live chat.

DirectAdmin hosting with security managed for you

Imunify360, CloudLinux isolation, free Let's Encrypt SSL and weekly JetBackup backups on every plan.

See DirectAdmin plans

Ready when you are

Get DirectAdmin hosting from ₹100/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
DirectAdmin Hosting Security Checklist | Domain India