Two-factor authentication (2FA) means that signing in to your Domain India account needs two things: your password and a six-digit code from an app on your phone. Someone who steals or guesses your password still cannot get in without the phone. This guide shows how to turn it on, how signing in changes, and what to do when you change or lose your phone.
Go to Account › Security in the client area (or /client/security/2fa), click Enable 2FA and confirm with your current password. Scan the QR code with an authenticator app such as Google Authenticator, Authy or Microsoft Authenticator, save the recovery codes the page shows, then enter the six-digit code from the app. You are signed out, and from then on every sign-in asks for a code.
1. What two-factor protects
Your client-area account controls your domains, hosting, invoices and support tickets. Whoever signs in to it can change nameservers, reset your control panel password or read your billing details. 2FA puts a second lock on that door.
The second factor is a time-based code. An authenticator app on your phone shows a new six-digit code every 30 seconds, worked out from a secret that only your phone and your Domain India account share. No SMS is sent and no internet connection is needed on the phone to produce the code.
2FA is optional on Domain India client accounts, and we recommend it for anyone who manages a business domain.
2. Before you start
You need three things:
- A phone with an authenticator app. The setup page links to Google Authenticator, Authy and Microsoft Authenticator for iOS and Android. Any standard authenticator app that scans a QR code works the same way.
- Your current client-area password. The page asks for it before it shows the QR code. If you only ever sign in with Google and have never set a password, first set one with Forgot password on the sign-in page, then come back.
- Somewhere safe for recovery codes, such as a password manager or a printed sheet you keep with your business papers.
3. Turn on two-factor authentication
- Open the Security page.Sign in to the client area and choose Account › Security, or go to /client/security/2fa. The page shows "Two-Factor Authentication is Disabled".
- Click Enable 2FA.A Confirm it's you box asks for your current password. Enter it and click Continue.
- Install an app (Step 1).If you do not have an authenticator app yet, install one of the apps listed, then click Continue to Next Step.
- Scan the QR code (Step 2).In the app, tap + (add account) and scan the code on screen. If the camera will not scan it, choose manual entry in the app and type the Secret Key shown under the QR code. The app now shows a new entry for your account with a six-digit code.
- Save your recovery codes (Step 3).Use Download Codes or Copy All Codes, store them safely, tick the box confirming you have saved them, and click Continue to verification.
- Verify (Step 4).Type the six-digit code your app is showing and click Verify Code.
- Sign in again.2FA is now on, and you are signed out with the message "Two-factor is on. Sign in again." Sign in with your password and a code from the app.
The QR code and recovery codes are shown only during setup. If you close the page before Step 4, 2FA stays off; start again with Enable 2FA and scan the new QR code, removing the unfinished entry from your app.
4. Recovery codes
During setup the page shows a set of ten one-time recovery codes. Each code can be used only once. The download is a plain text file, so store it in a password manager or print it and delete the file.
Treat these codes like a password:
- keep them somewhere other than your phone, so losing the phone does not also lose the codes;
- never send them by email, chat or in a support ticket;
- never share them with a developer or agency working on your site.
Used some, or think they may have been seen? On the Security page, click Generate New Codes and enter a code from your authenticator app. You get a fresh set and all the old codes stop working.
If the setup page says it could not show your recovery codes, you can still finish turning 2FA on. As soon as you sign in again, open the Security page and generate new codes.
5. Signing in with two-factor
- Enter your email and passwordon the sign-in page as usual.
- Enter the Authentication Code.A second screen asks for the six-digit code from your authenticator app. Open the app, find the entry for your Domain India account and type the code shown.
- Choose whether to remember this device.Tick Remember this device for 30 days on a computer only you use, and you will not be asked for a code on that browser for 30 days. Leave it unticked on shared or office computers.
- Click Verify Code.
If the code is rejected, wait for the app to show the next code and try again. Repeated wrong codes count as failed sign-ins, and too many lock the account for 15 minutes.
6. Changing to a new phone
The codes live on the phone, so plan a phone change before you wipe or hand in the old one.
- While you still have the old phone, open the Security pageand click Disable 2FA. Enter the current code from the old phone's app to confirm.
- Install an authenticator appon the new phone.
- Turn 2FA on againwith Enable 2FA, scan the new QR code with the new phone, and save the new recovery codes.
- Remove the old Domain India entryfrom the old phone's app.
Some authenticator apps can back up or sync their accounts to a cloud account, which can bring your codes across to a new phone automatically. Check whether yours does, and test that the Domain India code appears on the new phone before you reset the old one.
7. Lost your phone?
If another device still has your authenticator app with the Domain India entry, use it to sign in, then turn 2FA off and set it up again on your new phone.
If you have no working authenticator app, open a ticket at /support/ticket from the email address on your account. Say that you have lost access to your authenticator app, and give your name and a domain on the account. Support will tell you what is needed to confirm the account is yours. Never put your password or recovery codes in the ticket.
8. When something does not work
| What you see | Likely cause | What to do |
|---|---|---|
| "That code is not right" at sign-in | The code expired, or the phone's clock is wrong | Wait for the next code; set the phone to automatic date and time |
| "Current password is incorrect" during setup | A typo in the password on the Confirm it's you box | Retype it; after 5 wrong tries, wait 15 minutes |
| "Your account has no password yet" | You sign in with Google only | Set a password with Forgot password, then enable 2FA |
| "Too many attempts" | Several wrong codes or passwords in a row | Wait 15 minutes, then try again |
| "We could not check your two-factor status" | The Security page could not reach the service | Nothing has changed; reload later and keep using your app |
9. cPanel has its own two-factor setting
The client-area 2FA protects your Domain India account. Your control panel is a separate login. Where it is available on your server, cPanel has its own Two-Factor Authentication page in the Security section. It works the same way, with the same kind of app, and protects direct logins to cPanel. Add it as a separate entry in your app; the two codes are not interchangeable.
10. Where Domain India fits
Every service you have with us, whether domains, hosting on cPanel, DirectAdmin, Webuzo or Windows (Plesk), Business Email or a VPS, is managed from the same client area, so turning on 2FA there protects all of it at once.
If you get stuck, support is available by 24/7 live chat, and tickets get a first response within 15 minutes; how long a fix takes depends on the issue. There is no phone support.
Frequently asked questions
How do I turn on two-factor authentication for my Domain India account?
Sign in to the client area and open Account, Security, or domainindia.com/client/security/2fa. Click Enable 2FA, confirm with your current password, scan the QR code with an authenticator app, save your recovery codes and enter the six-digit code from the app.
Which authenticator apps can I use?
The setup page links to Google Authenticator, Authy and Microsoft Authenticator for iOS and Android. Any standard authenticator app that scans a QR code and shows six-digit codes works.
Why was I signed out after turning on 2FA?
Turning on two-factor signs you out so that your next sign-in uses it. Sign in again with your password and a code from your authenticator app.
Do I have to enter a code every time I sign in?
Yes, unless you tick Remember this device for 30 days on the code screen. That browser then skips the code for 30 days. Only use it on a device nobody else uses.
How many recovery codes do I get, and can I get new ones?
You get ten one-time codes during setup. To replace them, click Generate New Codes on the Security page and enter a code from your app; all the old codes stop working.
How do I turn two-factor off?
Open the Security page, click Disable 2FA and enter the current code from your authenticator app. Turn it back on as soon as you have finished, for example after moving to a new phone.
I lost my phone and cannot sign in. What should I do?
If another device has your authenticator app, use it. Otherwise open a ticket at domainindia.com/support/ticket from your account email, say you have lost access to your authenticator app, and support will tell you what is needed. Never include your password or recovery codes.
Does client-area 2FA also protect cPanel?
No. cPanel is a separate login. Where available on your server, cPanel has its own Two-Factor Authentication page in its Security section.
Ready to add the second lock? Open Account › Security and click Enable 2FA. While you are there, check your password is strong at /client/security/password. If anything goes wrong, open a ticket.
It takes about two minutes with an authenticator app on your phone. Save your recovery codes before you finish.
Open Security