SSH & Terminal Access

Securing MySQL Access with SSH Tunnels: A Comprehensive Guide

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (9 sections)

An SSH tunnel lets a database tool on your own computer, such as MySQL Workbench, DBeaver or HeidiSQL, talk to your hosting database through an encrypted SSH login, without MySQL ever being open to the internet. On Domain India shared hosting it is the way to reach your database from your desk, because port 3306 is closed to outside connections. This guide explains how a tunnel works, what you need first, and how to set one up on macOS, Linux and Windows.

Key takeaways

Ask support to enable jailed SSH on your hosting account: it is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo) and is off by default. SSH login uses a key, not a password, so add your public key to the account. Then run ssh -N -L 3307:localhost:3306 username@server, leave it open, and point your database tool at 127.0.0.1, port 3307, with your normal database name, user and password. Adding your IP address under Remote Database Access does not open port 3306; the tunnel is what gets you in.

1. Why you need a tunnel on shared hosting

Your website reaches its database as localhost, on the same server. A tool on your own computer is outside the server, and port 3306 is closed to outside connections on our shared servers (measured September 2026). A direct connection is refused or times out.

cPanel's Remote Database Access page and DirectAdmin's access hosts only tell the database which addresses may log in. They don't open the port in the server firewall, so they don't help on their own.

An SSH tunnel solves this. Port 22 (SSH) is open on our cPanel, DirectAdmin and Webuzo servers. Your computer logs in over SSH, and the SSH connection carries your database traffic to MySQL on the server. MySQL sees a local connection, and nothing but SSH is exposed.

2. What you need first

  1. Jailed SSH enabled on your account.
    Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo). It is off by default; ask support to enable it for your account by live chat or a ticket at /client/support/new. It is a jailed (restricted) shell, which is all a tunnel needs.
  2. Your SSH login details and a key.
    In the client area, open your hosting service, click Manage and open the Access tab. The Login details card shows your username and server IP. SSH login on our servers uses a key pair, not a password: create one on your computer and add the public key to your hosting account, as explained in enabling and accessing jailed SSH and how to generate SSH keys.
  3. The database details.
    The database name, database user and that user's password, exactly as your control panel shows them, including the account prefix (for example acme_shop). See how to connect to the MySQL database.
  4. An SSH client.
    macOS, Linux and Windows 10 or 11 include the ssh command. PuTTY is a free alternative on Windows.
Windows (Plesk) hosting has no SSH

Our Windows hosting runs Plesk with Microsoft SQL Server databases, and SSH (port 22) is not available on it. This guide applies to cPanel, DirectAdmin and Webuzo hosting.

3. Create the tunnel on macOS or Linux

Open a terminal and run:

bash
ssh -N -L 3307:localhost:3306 [email protected]

Replace acme with your hosting username and 203.0.113.10 with your server IP from the Access tab. If your private key isn't in the default place, add -i and its path, for example -i ~/.ssh/id_ed25519. What each part does:

  • -L 3307:localhost:3306 forwards port 3307 on your computer to port 3306 on the server, as seen from the server itself.
  • -N opens the tunnel without starting a shell, which is all you need.
  • 3307 is used locally so it doesn't clash with a MySQL server you may run on your own computer. Any free port works.

Enter your key's passphrase if it has one. The command then appears to hang: that is the tunnel running. Leave the window open while you work, and press Ctrl+C to close it.

To test it from a second terminal with the mysql client, run mysql -h 127.0.0.1 -P 3307 -u acme_shopuser -p acme_shop. Use 127.0.0.1, not localhost, on your computer: MySQL clients treat localhost as a local socket and skip the tunnel.

4. Create the tunnel on Windows

With the built-in ssh command. Open PowerShell or Windows Terminal and run the same command as in section 3. Nothing needs installing on Windows 10 or 11 where the OpenSSH client is present.

With PuTTY:

  1. Session.
    Open PuTTY and enter your server IP in Host Name, with port 22.
  2. Key.
    Open Connection › SSH › Auth (called Credentials under Auth in newer PuTTY versions) and select your private key file. PuTTY uses the .ppk format; PuTTYgen converts or creates one.
  3. Tunnels.
    In the left panel, open Connection › SSH › Tunnels. Set Source port to 3307 and Destination to localhost:3306, leave Local selected, and click Add.
  4. Save it.
    Go back to Session, type a name under Saved Sessions and click Save, so you don't have to repeat this.
  5. Open.
    Click Open, enter your hosting username, and your key's passphrase if it has one. Keep the PuTTY window open while you work.

5. Connect your database tool

With the tunnel open, every tool uses the same settings:

SettingValue
Host127.0.0.1
Port3307 (the local port you chose)
UsernameYour database user, with prefix, e.g. acme_shopuser
PasswordThe database user's password
DatabaseYour database name, with prefix, e.g. acme_shop

Many tools can also open the tunnel themselves. In MySQL Workbench, choose the connection method Standard TCP/IP over SSH; in DBeaver, fill in the SSH tab of the connection; in HeidiSQL, choose the MySQL (SSH tunnel) network type. In each case, the SSH part uses your server IP, port 22, your hosting username and your private key file (choose public key authentication, not a password), and the MySQL part uses host 127.0.0.1, port 3306 and your database login.

6. Keep it secure

  • Protect your key with a passphrase. SSH on our servers accepts keys only, so your private key is your login. Give it a passphrase, keep it only on your own devices, and never send it to anyone, including support: only the public key goes on the server. See setting up SSH key authentication.
  • Close the tunnel when you finish. An open tunnel is an open door from your computer to the database.
  • Keep the local port private. ssh -L listens only on your own computer by default. Don't add options that share it with your network.
  • Don't add % under Remote Database Access. A wildcard host lets the database accept logins from anywhere, and it isn't needed for a tunnel. Remove old entries you no longer use.

7. Troubleshooting

ProblemLikely causeWhat to do
Connection to port 22 refused or timed outWrong server address, or your own network blocks outgoing SSHCheck the server IP on the Access tab, or try another network
Permission denied (publickey)SSH isn't enabled on your account yet, the public key isn't added to it, or the wrong private key or username is usedAsk support to enable jailed SSH, add your public key, and use the username on the Access tab
"bind: Address already in use"Something on your computer already uses the local portPick another local port, such as 3308
Tool says Access denied for the database userWrong database user or password, or the prefix is missingLog in to phpMyAdmin with the same details to check them
Tool can't connect although the tunnel is openThe tool points at localhost or at port 3306Use host 127.0.0.1 and your local port, such as 3307

If the tunnel opens but the database refuses you, work through Database troubleshooting. The ports that are open on our servers are listed in our port numbers guide.

8. Where Domain India fits

Every Domain India cPanel, DirectAdmin and Webuzo plan includes MySQL-compatible databases, phpMyAdmin and jailed SSH on request, so you can use a tunnel on any of them. For everyday work, phpMyAdmin in your control panel needs no setup at all. Prices on the cards are live and exclude 18% GST.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

If you need MySQL open to other servers, your own database configuration or a full (root) shell, a VPS gives you full control of the server.

Frequently asked questions

Can I connect to my Domain India database from MySQL Workbench?

Yes, through an SSH tunnel. Port 3306 is closed to outside connections on our shared servers, so a direct connection fails. Ask support to enable jailed SSH on your account, then use Workbench's Standard TCP/IP over SSH method, or open a tunnel yourself and connect to 127.0.0.1 on the local port.

Is SSH included with Domain India shared hosting?

Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo). It is off by default; ask support by live chat or ticket to enable it for your account. Login uses an SSH key, not a password. Windows (Plesk) hosting has no SSH.

What is the ssh command for a MySQL tunnel?

Run ssh -N -L 3307:localhost:3306 username@server-ip, using your hosting username and the server IP from the Access tab in the client area. Leave it running, then connect your database tool to host 127.0.0.1, port 3307.

Why doesn't adding my IP under Remote Database Access work?

The Remote Database Access list only controls which addresses the database accepts logins from. It does not open port 3306 in the server firewall, so connections from outside still fail. An SSH tunnel goes through port 22 instead.

Can I use a tunnel on Windows hosting?

No. Domain India's Windows (Plesk) hosting has no SSH, so there is nothing to tunnel through. Its databases are Microsoft SQL Server.

Ready to connect? Ask support to enable jailed SSH on your account, check your database details with how to connect to the MySQL database, or compare VPS plans if you need full control.

Want SSH enabled for a tunnel?

Tell us your hosting username or domain, and we will enable jailed SSH on your account and help you add your SSH key.

Ask our support team

Ready when you are

Get cPanel hosting from ₹125/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app