An SSH tunnel lets a database tool on your own computer, such as MySQL Workbench, DBeaver or HeidiSQL, talk to your hosting database through an encrypted SSH login, without MySQL ever being open to the internet. On Domain India shared hosting it is the way to reach your database from your desk, because port 3306 is closed to outside connections. This guide explains how a tunnel works, what you need first, and how to set one up on macOS, Linux and Windows.
Ask support to enable jailed SSH on your hosting account: it is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo) and is off by default. SSH login uses a key, not a password, so add your public key to the account. Then run ssh -N -L 3307:localhost:3306 username@server, leave it open, and point your database tool at 127.0.0.1, port 3307, with your normal database name, user and password. Adding your IP address under Remote Database Access does not open port 3306; the tunnel is what gets you in.
1. Why you need a tunnel on shared hosting
Your website reaches its database as localhost, on the same server. A tool on your own computer is outside the server, and port 3306 is closed to outside connections on our shared servers (measured September 2026). A direct connection is refused or times out.
cPanel's Remote Database Access page and DirectAdmin's access hosts only tell the database which addresses may log in. They don't open the port in the server firewall, so they don't help on their own.
An SSH tunnel solves this. Port 22 (SSH) is open on our cPanel, DirectAdmin and Webuzo servers. Your computer logs in over SSH, and the SSH connection carries your database traffic to MySQL on the server. MySQL sees a local connection, and nothing but SSH is exposed.
2. What you need first
- Jailed SSH enabled on your account.Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo). It is off by default; ask support to enable it for your account by live chat or a ticket at /client/support/new. It is a jailed (restricted) shell, which is all a tunnel needs.
- Your SSH login details and a key.In the client area, open your hosting service, click Manage and open the Access tab. The Login details card shows your username and server IP. SSH login on our servers uses a key pair, not a password: create one on your computer and add the public key to your hosting account, as explained in enabling and accessing jailed SSH and how to generate SSH keys.
- The database details.The database name, database user and that user's password, exactly as your control panel shows them, including the account prefix (for example
acme_shop). See how to connect to the MySQL database. - An SSH client.macOS, Linux and Windows 10 or 11 include the
sshcommand. PuTTY is a free alternative on Windows.
Our Windows hosting runs Plesk with Microsoft SQL Server databases, and SSH (port 22) is not available on it. This guide applies to cPanel, DirectAdmin and Webuzo hosting.
3. Create the tunnel on macOS or Linux
Open a terminal and run:
ssh -N -L 3307:localhost:3306 [email protected]Replace acme with your hosting username and 203.0.113.10 with your server IP from the Access tab. If your private key isn't in the default place, add -i and its path, for example -i ~/.ssh/id_ed25519. What each part does:
-L 3307:localhost:3306forwards port 3307 on your computer to port 3306 on the server, as seen from the server itself.-Nopens the tunnel without starting a shell, which is all you need.3307is used locally so it doesn't clash with a MySQL server you may run on your own computer. Any free port works.
Enter your key's passphrase if it has one. The command then appears to hang: that is the tunnel running. Leave the window open while you work, and press Ctrl+C to close it.
To test it from a second terminal with the mysql client, run mysql -h 127.0.0.1 -P 3307 -u acme_shopuser -p acme_shop. Use 127.0.0.1, not localhost, on your computer: MySQL clients treat localhost as a local socket and skip the tunnel.
4. Create the tunnel on Windows
With the built-in ssh command. Open PowerShell or Windows Terminal and run the same command as in section 3. Nothing needs installing on Windows 10 or 11 where the OpenSSH client is present.
With PuTTY:
- Session.Open PuTTY and enter your server IP in Host Name, with port 22.
- Key.Open Connection › SSH › Auth (called Credentials under Auth in newer PuTTY versions) and select your private key file. PuTTY uses the
.ppkformat; PuTTYgen converts or creates one. - Tunnels.In the left panel, open Connection › SSH › Tunnels. Set Source port to
3307and Destination tolocalhost:3306, leave Local selected, and click Add. - Save it.Go back to Session, type a name under Saved Sessions and click Save, so you don't have to repeat this.
- Open.Click Open, enter your hosting username, and your key's passphrase if it has one. Keep the PuTTY window open while you work.
5. Connect your database tool
With the tunnel open, every tool uses the same settings:
| Setting | Value |
|---|---|
| Host | 127.0.0.1 |
| Port | 3307 (the local port you chose) |
| Username | Your database user, with prefix, e.g. acme_shopuser |
| Password | The database user's password |
| Database | Your database name, with prefix, e.g. acme_shop |
Many tools can also open the tunnel themselves. In MySQL Workbench, choose the connection method Standard TCP/IP over SSH; in DBeaver, fill in the SSH tab of the connection; in HeidiSQL, choose the MySQL (SSH tunnel) network type. In each case, the SSH part uses your server IP, port 22, your hosting username and your private key file (choose public key authentication, not a password), and the MySQL part uses host 127.0.0.1, port 3306 and your database login.
6. Keep it secure
- Protect your key with a passphrase. SSH on our servers accepts keys only, so your private key is your login. Give it a passphrase, keep it only on your own devices, and never send it to anyone, including support: only the public key goes on the server. See setting up SSH key authentication.
- Close the tunnel when you finish. An open tunnel is an open door from your computer to the database.
- Keep the local port private.
ssh -Llistens only on your own computer by default. Don't add options that share it with your network. - Don't add
%under Remote Database Access. A wildcard host lets the database accept logins from anywhere, and it isn't needed for a tunnel. Remove old entries you no longer use.
7. Troubleshooting
| Problem | Likely cause | What to do |
|---|---|---|
| Connection to port 22 refused or timed out | Wrong server address, or your own network blocks outgoing SSH | Check the server IP on the Access tab, or try another network |
| Permission denied (publickey) | SSH isn't enabled on your account yet, the public key isn't added to it, or the wrong private key or username is used | Ask support to enable jailed SSH, add your public key, and use the username on the Access tab |
| "bind: Address already in use" | Something on your computer already uses the local port | Pick another local port, such as 3308 |
| Tool says Access denied for the database user | Wrong database user or password, or the prefix is missing | Log in to phpMyAdmin with the same details to check them |
| Tool can't connect although the tunnel is open | The tool points at localhost or at port 3306 | Use host 127.0.0.1 and your local port, such as 3307 |
If the tunnel opens but the database refuses you, work through Database troubleshooting. The ports that are open on our servers are listed in our port numbers guide.
8. Where Domain India fits
Every Domain India cPanel, DirectAdmin and Webuzo plan includes MySQL-compatible databases, phpMyAdmin and jailed SSH on request, so you can use a tunnel on any of them. For everyday work, phpMyAdmin in your control panel needs no setup at all. Prices on the cards are live and exclude 18% GST.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
If you need MySQL open to other servers, your own database configuration or a full (root) shell, a VPS gives you full control of the server.
Frequently asked questions
Can I connect to my Domain India database from MySQL Workbench?
Yes, through an SSH tunnel. Port 3306 is closed to outside connections on our shared servers, so a direct connection fails. Ask support to enable jailed SSH on your account, then use Workbench's Standard TCP/IP over SSH method, or open a tunnel yourself and connect to 127.0.0.1 on the local port.
Is SSH included with Domain India shared hosting?
Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo). It is off by default; ask support by live chat or ticket to enable it for your account. Login uses an SSH key, not a password. Windows (Plesk) hosting has no SSH.
What is the ssh command for a MySQL tunnel?
Run ssh -N -L 3307:localhost:3306 username@server-ip, using your hosting username and the server IP from the Access tab in the client area. Leave it running, then connect your database tool to host 127.0.0.1, port 3307.
Why doesn't adding my IP under Remote Database Access work?
The Remote Database Access list only controls which addresses the database accepts logins from. It does not open port 3306 in the server firewall, so connections from outside still fail. An SSH tunnel goes through port 22 instead.
Can I use a tunnel on Windows hosting?
No. Domain India's Windows (Plesk) hosting has no SSH, so there is nothing to tunnel through. Its databases are Microsoft SQL Server.
Ready to connect? Ask support to enable jailed SSH on your account, check your database details with how to connect to the MySQL database, or compare VPS plans if you need full control.
Tell us your hosting username or domain, and we will enable jailed SSH on your account and help you add your SSH key.
Ask our support team