SSL Certificates

Website Security Best Practices

By the Domain India teamPublished 5 min read
Knowledge base article
Contents (6 sections)

Most hacked websites are broken into through an outdated plugin, a reused password or a missing backup, not through the server. A handful of habits closes those gaps. This page lists them, explains what Domain India's shared servers already do for you, and points to the detailed guides.

The detailed guides

For your Domain India login, see account security best practices. For WordPress, see the complete WordPress hardening guide. If your site is already hacked, go straight to the hacked website checklist.

Key takeaways

Update your CMS, plugins and themes promptly and remove what you don't use. Use long, unique passwords in a password manager, and turn on two-factor authentication for your Domain India account, your control panel and your site's admin. Keep your own off-server backups. The server adds malware scanning and a web application firewall, but it can't fix an outdated plugin or a stolen password.

1. The habits that matter most

Update everything
Apply WordPress, Joomla, plugin and theme updates promptly. Delete plugins, themes and old test installs you no longer use.
Unique passwords
Use a password manager and a different long password for your client area, control panel, site admin, FTP, database and email.
Two-factor authentication
Turn it on for your Domain India account, in cPanel, and for every admin user of your site.
Your own backups
Keep regular copies of your files and database off the server, and test that you can restore one.

Also keep your site on a supported PHP version (check your control panel for the versions available), give each person their own login instead of sharing one, and never set file permissions to 777.

2. Two-factor authentication in three places

3. What the shared servers already do

On our cPanel and DirectAdmin servers, measured in September 2026:

  • CloudLinux with CageFS keeps each hosting account separate from the others on the server.
  • Imunify360 runs a full ModSecurity web application firewall ruleset and scans for malware. On cPanel it removes known malicious code from infected files automatically and keeps the original for 14 days. You can't start a scan yourself, and you are not emailed when something is found.
  • Free SSL: on cPanel, AutoSSL issues free Let's Encrypt certificates for domains that point to the server; on DirectAdmin you issue a free Let's Encrypt certificate in the panel.

These layers stop many common attacks, but not a login with a stolen password or an attack through a plugin you haven't updated. Domain India doesn't promise to clean a hacked site for you.

4. Security tools in cPanel

ToolWhat it does
IP BlockerBlocks specific IP addresses or ranges from your site
Hotlink ProtectionStops other sites embedding your images and using your bandwidth
Directory PrivacyPassword-protects a folder, such as an admin area
Two-Factor AuthenticationAdds a code to your cPanel login
SSL/TLS Certificates (Status tab)Shows which of your domains have a valid free certificate

DirectAdmin and Webuzo have similar tools under different names. If you can't find one, ask support.

5. Backups: yours and ours

cPanel and DirectAdmin accounts get weekly JetBackup backups, taken on Sunday with 5 copies kept, which you can restore from the panel. See backup and restore with JetBackup. Webuzo accounts are backed up every night to a separate Domain India backup server, and support restores them on request.

A weekly backup can be several days old, and it may already contain malware if a hack went unnoticed. Keep your own copies off the server as well, especially before updates.

Signs you may already be hacked

Unknown admin users, visitors redirected to spam sites, emails you never sent, or a browser "Dangerous site" warning. Don't start deleting files at random: follow the hacked website checklist.

Frequently asked questions

What is the most important thing I can do to keep my website secure?

Keep your CMS, plugins and themes updated, and remove the ones you don't use. Outdated software is the most common way sites are broken into.

Does Domain India protect my website from malware?

The cPanel and DirectAdmin servers run Imunify360 with a web application firewall and malware scanning. It blocks many attacks but can't fix an outdated plugin or a stolen password, so your own updates, passwords and backups still matter.

Can I turn on two-factor authentication in cPanel?

Yes. Open Two-Factor Authentication in cPanel's Security section and scan the QR code with an authenticator app. Turn it on for your Domain India client area as well.

Do I need my own backups if my hosting has backups?

Yes. Hosting backups on cPanel and DirectAdmin are weekly, so they can be days old. Keep your own copies off the server, especially before updates.

Ready to lock your site down? Turn on two-factor authentication, work through the WordPress hardening guide, or open a ticket if something looks wrong.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

Prices on the cards exclude 18% GST.

Hosting with security built in

CloudLinux account isolation, Imunify360 scanning, free SSL and weekly JetBackup backups on cPanel hosting.

See cPanel hosting plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app