Keeping your account secure
Updated Sep 15, 2026Your YallowHost account controls your websites, servers, domains, email and billing. Protecting it protects everything that depends on it. These steps take minutes and make a real difference.
Use a strong, unique password
Use a long password, ideally 14 characters or more, that you do not use anywhere else. A password manager can generate and remember one for you. To change it, open Security from the account menu, enter your current password and the new one twice, then choose Update password.
If you forget your password, use the password reset link on the sign-in page. For your protection, repeated failed sign-in and reset attempts are temporarily blocked.
Turn on two-factor authentication
Two-factor authentication (2FA) means a stolen password alone is not enough to sign in. After entering your password, you also enter a 6-digit code from an authenticator app on your phone. It is the most effective single step you can take. See Enabling two-factor authentication.
Protect the email address on your account
Password resets, invoices and service notices go to your account email, so anyone who controls that inbox can potentially take over your account. Give the mailbox its own strong password and two-factor authentication, and make sure it belongs to your organisation rather than to one individual who might leave.
Recognise phishing
- We will never ask for your account password, your 2FA codes or your full card number by email, phone or ticket.
- Be wary of urgent messages about suspension or payment that link to a sign-in page. Instead, open the website yourself by typing the address and check your account there.
- Check the sender's address and hover over links before clicking.
Everyday habits
- Do not tick Keep me signed in on shared or public computers, and always use Sign out when you are done.
- Keep your computer's operating system and browser up to date.
- Share access details for migrations and management only through the secure forms, never in tickets or email.
- Store server root passwords and SSH keys in a password manager, and use SSH keys rather than passwords on servers.
If you think your account is compromised
- Change your password immediately and turn on 2FA if it is off.
- Secure the email inbox linked to your account.
- Review your services, saved cards and recent invoices for anything unexpected.
- Open a High priority ticket describing what you noticed, and our team will help you investigate.
Still need a hand?
Our team is happy to help — open a ticket and we'll reply by email.