cPanel Login URL and Port: How Do You Access cPanel?

What is the cPanel login URL, and which port does it use?
The cPanel login URL is the web address you use to open your hosting account's control panel. The most common forms are example.com/cpanel, cpanel.example.com and example.com:2083. cPanel uses port 2083 for secure connections and port 2082 for unencrypted ones. Your hosting provider also supplies the username and password.
In this guide we cover every route to the cPanel login screen, what each port does and where to start when a login fails. We are a web and digital marketing team, not a hosting company. Therefore every port number and setting name here comes straight from the official cPanel documentation. If you want the bigger picture of what cPanel can do, our sibling article on what cPanel is covers that. Here, instead, we stay focused on the front door.
A quick note on examples, then. We use example.com instead of a real domain and 203.0.113.10 instead of a real IP address. Both come from ranges reserved for documentation, and RFC 5737 defines the IP ranges. You will type your own domain and the IP address your provider gave you.
This article has two kinds of readers in mind. The first is the site owner on shared hosting who opens the panel now and then. The second is the developer who runs cPanel on their own VPS and has to fix login problems on the server side too. In each section we say which step you can take yourself and which one belongs to your hosting provider.
Which addresses can you use to reach cPanel?
There is no single correct address for cPanel login. Depending on the server setup, several doors can be open at once. They all lead to the same sign-in screen, because only the route and the port differ. For example, if you registered your domain yesterday or the DNS change has not propagated yet, the domain based addresses may not work. In that case you switch to the server hostname or the IP address.
- https://example.com/cpanel: a shortcut on your domain; the server redirects you to the secure port.
- https://cpanel.example.com: a service subdomain that runs over the standard port 443.
- https://example.com:2083: the classic address that connects straight to the cPanel SSL port.
- https://host.example.net:2083: your provider's server hostname, which usually has a valid certificate.
- https://203.0.113.10:2083: login by IP address, a fallback when the domain does not resolve.
In practice, try example.com/cpanel first. It is easy to remember, and if the server allows it, it moves you to the right port on its own. If the redirect fails, then work your way down the list. Also, if your provider sent a specific address in the welcome email, use that one first. Some providers open cPanel with a single click from inside their own client area.
What are the cPanel, WHM and Webmail ports?
cPanel's official firewall configuration guide lists the ports each service listens on. The table below summarizes the rows that matter for login screens. All of them use TCP, and each service has one encrypted and one unencrypted port.
| Service | With SSL (recommended) | Without SSL | Who uses it? |
|---|---|---|---|
| cPanel | 2083 | 2082 | Site owner, hosting account user |
| WHM | 2087 | 2086 | Server administrator, reseller account |
| Webmail | 2096 | 2095 | Email account user |
The rule here is simple: always pick the port in the SSL column. On the unencrypted ports, your username and password can travel across the network as plain text. In addition, the same guide says at least one port from its list must stay open for the license callback to work. So a server administrator never closes all of them; they only restrict the ones nobody needs.
How does the example.com/cpanel shortcut work?
When you type example.com/cpanel into the browser, the request first reaches your site's normal web port. The server recognizes the path and sends you on to the cPanel sign-in screen. The cPanel documentation describes redirection settings in WHM's Tweak Settings for the /cpanel, /webmail and /whm paths. For example, the setting "Choose the closest matched domain for which that the system has a valid certificate when redirecting from non-SSL to SSL URLs" is on by default.
With that setting on, the system sends you to the closest matching domain that has a valid certificate, on the secure port. As a result, the address bar sometimes shows your provider's hostname instead of your own domain. That is not an error. The server simply takes you to an address with a valid certificate so the browser does not warn you.
Still, sometimes the shortcut fails. For instance, if your site has its own rewrite rules or your domain points to another server, the /cpanel path may land on your site's 404 page. You can check which IP your domain points to with our DNS lookup tool. If it does not match the IP your provider gave you, the problem sits in DNS, not in cPanel.
Why is the cpanel.example.com subdomain useful?
According to cPanel's Tweak Settings domains reference, the "Service subdomains" option gives users access to cPanel and WHM through the standard ports 80 and 443. Specifically, the option is on by default. When it is active, the system creates cpanel.example.com, whm.example.com, webmail.example.com and webdisk.example.com.
The real value of these subdomains shows up on restricted networks. Many corporate networks, school networks and hotel Wi-Fi setups only allow ports 80 and 443. Because of that, example.com:2083 may never load there. On the other hand, cpanel.example.com carries the same session over port 443, so it gets through most filters.
The subdomain needs a DNS record to work. cPanel usually adds these records to the domain's DNS zone itself. However, if you manage DNS with an external service such as Cloudflare, you may need to add the cpanel record there yourself. Also, if that record sits behind a proxy, the connection may not behave as you expect. In that situation, ask your provider what they recommend.
When do you need to log in to cPanel by IP address?
A cPanel login by IP address is a bridge you use when the domain does not point to the new server yet. In practice, the most common case is a site migration. You open a new hosting account, but the domain's DNS records still point to the old server. At that stage, example.com/cpanel takes you to the old account. To reach the new one, you use the IP address or the hostname from your provider.
The address looks like this: https://203.0.113.10:2083. If you do not know the server IP, check your welcome email. To see which IP your domain currently points to, our IP lookup tool does the job. If the two IPs differ, you know the DNS change has not finished.
On shared hosting, many accounts share the same IP address. That does not stop IP based login, because cPanel opens the session based on your username, not on the domain you came from. Still, logging in by IP has one side effect: the browser almost always shows a certificate warning. The next section explains how to judge that warning.
What should you do about a certificate warning at cPanel login?
A certificate warning means the address you typed does not match the name on the SSL certificate the server presents. When you use cPanel login by IP, this is close to unavoidable. Providers usually issue certificates for a domain or hostname, not for a bare IP. However, the connection is still encrypted. The browser only says it cannot confirm who is on the other end.
That said, you should not click past the warning everywhere. Before you accept it, ask yourself these questions:
- Is the IP you typed really the one your provider gave you?
- Are you on a network you trust, such as your home or office?
- Does the same warning appear when you use the server hostname?
- Did the warning suddenly show up on an address that never had one before?
If you answer yes to the last two, stop. A warning on the hostname may mean the certificate has expired, and you can confirm that with our SSL checker. Our SSL certificate guide explains what certificates do and why browsers warn. The lasting fix is to use an address with a valid certificate instead of the IP.
Where do you find your cPanel login details?
Your cPanel login details arrive in the welcome email your provider sends when it sets up the hosting account. That email usually contains the login URL, the username, the initial password and the server IP or hostname. If you cannot find it, search your inbox for the provider's name and words like "account information" or "welcome". Also check the spam folder.
A common mix-up is to treat the provider's client area login and the cPanel login as the same thing. The client area handles invoices, domains and support tickets, and you usually sign in there with your email address. cPanel, in contrast, is the hosting account on the server, and it has its own username. That username is often a short word derived from your domain, not an email address.
If the welcome email is gone, open your hosting plan in the provider's client area, under something like "My Services". Many client areas show the cPanel username there and offer a "Log in to cPanel" button. If you work with an agency or developer, ask them for the details. Remember that you are the owner, though: keep a copy of the account details yourself.
How should your first cPanel login on a new account go?
Your first cPanel login is the moment you lay the security foundation for the account. So do not just check that the screen loads and leave. The list below sums up what we suggest you do in the first fifteen minutes on a new hosting account:
- Log in with the address from the welcome email, using the SSL port.
- Change the initial password right away and choose a long, unique one.
- Turn on two factor authentication if your provider allows it.
- Check that the contact email address belongs to you and is current.
- Confirm with a DNS tool that the domain points to this server.
- Look at the backup options and download a first backup.
For the password, a random one from your browser or password manager works well. If you have neither at hand, our password generator creates a long, random password. On the backup side, our website backup strategy guide covers how often to back up and where to store copies. That way, on day one you lock the door and prepare a way back at the same time.
What do you do if you forgot your cPanel password?
If you forgot your cPanel password, the most reliable route is to sign in to your provider's client area and reset it there. Most providers offer a password change option on the hosting plan's management page. The new password reaches the server within seconds, and you can log in right away.
On some servers, the cPanel login screen also shows a password reset link. The server administrator decides whether to enable it, so it may not appear for you. If the link is there, the reset code goes to the contact email stored in the account. This is exactly why we suggest checking that contact address on your first login. If a former employee's address is on file, the code goes to them.
If you cannot get into the client area either, write to your provider's support team. They may ask for billing details, ID or a registered phone number to verify you. The process can feel tedious; still, it protects you. It makes it harder for a stranger to take over your account by claiming they lost the password. Never send your password by email or chat, and never ask support to send it to you in plain text.
Why does a cPanel login fail?
Most cPanel login problems come down to a handful of causes. The error message is usually short, so you work out which one you face from the symptoms. The list below sorts the most frequent causes together with what you see:
- Wrong username or password: the screen loads, but you see a message like "login failed".
- Caps Lock or keyboard layout: the password is right, yet different characters reach the server.
- Brute force protection: after many failed attempts, even the right password may not work.
- Firewall block: the page never loads and the browser times out.
- Closed port: the network you are on does not allow outgoing traffic to port 2083.
- DNS problem: the domain points to the wrong server or does not resolve at all.
- Suspended account: the provider has paused the account over billing or abuse.
Start the diagnosis with the simplest step. Type the password in a text editor, check it by eye, then copy and paste it. If the problem stays, try a different network, for example your phone's mobile data. If it works on mobile data, the issue lies with your network or a block on your IP. When it fails everywhere, however, look at the server or DNS side.
What happens if cPHulk or a firewall blocks you?
cPanel's cPHulk Brute Force Protection service watches logins to cPanel, WHM, email, FTP and SSH. If an account or an IP address collects too many failed attempts, cPHulk locks the account or blocks the IP for a period. In other words, after a few wrong tries the door may stay shut for a while even when you type the right password.
With a cPHulk lock, the page usually loads but refuses the login. With a server firewall block, by contrast, the page does not load at all, so the browser simply times out. In the second case, one common tool is CSF, and our CSF firewall guide explains how it works. CSF can also track failed logins and block your IP temporarily or permanently.
On shared hosting you cannot lift this block yourself. Instead, you send your IP address to your provider and ask them to remove it. If you manage your own VPS, the cPanel documentation points to WHM, then "Security Center", then "cPHulk Brute Force Protection". There, the "History Reports" tab shows the block and the "Remove Block" option clears it. The same page also recommends adding your own static IP to the whitelist.
Which route should you try if the cPanel port is closed?
For example, some networks block everything except standard web ports. Corporate networks, public institutions and guest Wi-Fi in hotels and cafes are typical examples. On these networks, example.com:2083 times out while ordinary websites load fine. If you see that pattern, the problem most likely sits in your network, not on the server.
The first fix is to try the cpanel.example.com service subdomain. Because it uses port 443, it usually gets through the network filter. The second option is the example.com/cpanel shortcut. However, if the shortcut redirects you to port 2083, you hit the same wall. The third option is to switch networks, for instance by tethering to your phone's mobile data.
If you run your own server, the situation can be the reverse. A firewall on the server itself may have closed port 2083, and then no outside network can reach it. Before you change firewall rules, make sure you still have SSH access to the server. Otherwise you can lock yourself out completely. If you lack experience with server security, leave these settings to your provider's managed support team.
How does two factor authentication protect your cPanel login?
Two factor authentication (2FA) adds a six digit code from an app on your phone after the password at cPanel login. According to cPanel's two factor authentication documentation, your hosting provider must first enable the feature in WHM. If it is available, you set it up from the "Two-Factor Authentication" screen in cPanel's Security section.
During setup, a QR code appears on screen, and you scan it with Google Authenticator, Duo Mobile or a similar app. From then on, someone who steals your password still cannot get in without your phone. We see this extra layer as a clear gain, especially for sites that handle email, payments or customer data.
Keep two things in mind, then. First, the codes depend on time, so a phone clock that drifts too far can make them fail. Set the clock to update automatically. Second, if you lose the phone, the documentation says you need to contact your hosting provider to disable 2FA. To make recovery easier, you can also store the setup QR code in a secure password manager at the time you scan it.
Which cPanel login route fits which situation?
Each login route has strengths and weaknesses, so the choice depends on where you are. The comparison table below shows at a glance which address to pick in which case. It relies on the port and service subdomain definitions in the official cPanel documentation. If your provider's setup differs, the address they give you takes priority.
| Login route | Port | Certificate warning | Works on restricted networks? | Best for |
|---|---|---|---|---|
| example.com/cpanel | Depends on redirect | Usually none | Depends on redirect target | Daily use |
| cpanel.example.com | 443 | Usually none | Mostly yes | Office network, hotel, cafe |
| example.com:2083 | 2083 | None if the certificate covers the domain | Mostly no | Direct, quick access |
| Hostname:2083 | 2083 | Usually none | Mostly no | Migration, before DNS propagates |
| IP address:2083 | 2083 | Almost always | Mostly no | Last resort, short term |
In short, use the shortcut or the service subdomain for daily work. The direct port address is quick, but restricted networks often stop it. Login by IP only makes sense during a transition, and it means you accept the certificate warning knowingly.
Is it safe to log in to cPanel on public Wi-Fi?
On public Wi-Fi, a cPanel login still runs over an encrypted connection as long as you use the SSL port and see no certificate warning. However, these networks carry extra risk. Fake access points, devices that try to redirect traffic and shared computers top the list. For that reason, we suggest you avoid opening your hosting panel from a cafe or airport network unless you have to.
If you must, these habits cut the risk noticeably:
- Always type the address with https and the SSL port; never use unencrypted ports such as 2082.
- If a certificate warning appears on a public network, do not continue; disconnect instead.
- On a shared computer, do not let the browser save the password.
- When you finish, sign out with "Log Out" rather than just closing the tab.
- If possible, connect through your phone's mobile data.
In short, these habits apply to every admin panel, not only cPanel. Our OWASP Top 10 guide explains why session and authentication flaws matter so much in web applications.
How does Webmail login differ from cPanel login?
Webmail is a separate door for people who only need their mailbox. Its address is usually webmail.example.com or example.com:2096. There, you enter the full email address, such as info@example.com, as the username. At cPanel login, by contrast, you use the account's short username. This difference causes confusion in teams more often than anything else on this list.
The split has a practical benefit. Instead of handing out the cPanel password, you give each employee only the password for their own mailbox. As a result, someone reading email cannot touch site files, the database or DNS settings. When a person leaves, you only change their mailbox password. If you want to forward mailboxes to other addresses, see our email forwarding guide.
Put simply, the cPanel password should stay with the one or two people who manage the account. Everyone else reaches their mailbox through Webmail or a desktop email client. This simple rule keeps the damage small if a password leaks.
What is the difference between WHM login and cPanel login?
WHM is the top level panel that manages the whole server, while cPanel is the panel for a single hosting account on that server. You reach WHM on port 2087 and cPanel on port 2083. On shared hosting you have no WHM access, and you do not need it. Reseller plans, however, give you limited WHM access, and you create your clients' cPanel accounts from there.
Our cPanel reseller hosting guide explains how the reseller model works. If you run cPanel on your own VPS, you log in to WHM as root, and that account can reach everything on the server. So use root only for server administration and switch to the relevant cPanel account for daily site work.
If you are still choosing a panel, our Plesk vs cPanel comparison lays out the differences. In addition, one of the most common tasks after you log in is switching the PHP version, which our MultiPHP guide walks through step by step.
When should you leave it to your hosting provider?
You can solve some cPanel login problems yourself, but others sit outside your permissions. To be honest, on shared hosting you cannot touch server settings, and you do not need to. In the cases below, we suggest you contact your provider's support team without losing time:
- cPHulk or a firewall has blocked your IP address.
- Your account is suspended, or the sign-in screen shows a message like "suspended".
- You lost your 2FA device.
- You get a certificate warning even on the server hostname.
- The panel does not open from any network or any address.
Add your IP address, the address you tried, the date and time and the exact error text to the ticket. Those details speed up the diagnosis a lot. If you run your own VPS but have little experience with firewalls, SSH and certificates, a managed plan makes sense. Our hosting selection guide helps you pick the right model.
A short checklist for cPanel login
To wrap up, cPanel login rests on a few simple rules. Try example.com/cpanel or cpanel.example.com first. If you need a port, use 2083; for WHM pick 2087, and for Webmail pick 2096. If the domain does not work, switch to the hostname or the IP address. With an IP, accept the certificate warning only on a network you trust.
If a login fails, check the password first, then the network, and the server last. Do not repeat failed attempts back to back. Otherwise the protection systems will lock you out for a while. On your first login, change the password, turn on 2FA and update the contact email. Those three steps spare you a lot of trouble later.
As your site grows, so does the work around panels, security and performance. If you want to share that load, our web design service covers setup and launch with you, while running the server always stays with your hosting provider.



