Reseller runbook · Access control · 30 minutes
How to secure your hosting account — Your Login Is the Master Key to Every Client You Have
If somebody took your reseller login tonight, the list of businesses that would find out tomorrow is longer than you think.
Straight answer first
Start by mapping the blast radius, because a reseller's exposure is not one site but every account under the package — 100, 250 or 500 of them depending on which plan you bought. Secure the WHM login and the billing login first, since those two control provisioning, suspension and the domains, then work outward to client cPanels.
The rest is unglamorous inventory: separate manager-generated passwords for each layer, two-factor wherever it is offered, every stale FTP account and API key deleted, and a recovery mailbox that does not sit inside the hosting you resell. None of it is difficult; all of it is the sort of thing that only gets done deliberately.
Written by the Hosting Seller staff · Checked 24 August 2026
Beginner
Skill assumed
30 minutes
Bench time
5
Runbook stages
24/7
Cover for you and your clients
A single-site owner securing their account is protecting one business. You are protecting everybody who trusted you with theirs, and most of them have no idea your login exists.
That difference changes the order of the work. It is not about the strongest possible password on one account — it is about knowing which credentials exist at all, which of them can create or suspend accounts, and which ones were issued to somebody who left two years ago.
Map the blast radius before you change any password
Write down the layers in order of what they can destroy. The billing login controls services, renewals and domains. WHM creates, suspends and terminates client accounts and holds root-adjacent power over every one of them. Individual cPanels affect one client each. The registrar, if your domains live elsewhere, sits above all of it.
Now put the effort where the damage is. Almost everyone reverses this and spends an afternoon on a WordPress password while the WHM login uses a variant of the same phrase as the billing account. The list is the deliverable here; five minutes with a pen changes what you do next.
The credentials your predecessors and contractors left behind
Every reseller account of any age carries logins nobody remembers making. FTP accounts cut for a designer on a one-off job. An API key for a billing integration that was abandoned. An extra cPanel user for the developer who rebuilt a client's site in 2023. Each is a door standing open with nobody watching it.
Audit them by account, not from memory. Inside each client cPanel: FTP accounts, database users, API tokens, extra users. In WHM: your own resellers-under-you, if you have any, and anything with account-creation rights. Delete anything you cannot justify out loud. Nobody has ever regretted removing a credential that turned out to still be needed — that is a five-minute reissue.
The recovery mailbox that outranks everything else
Account recovery runs through your contact address, which means that mailbox quietly sets the ceiling on every other control you have put in place. Two-factor on WHM does nothing if the reset email lands somewhere an attacker already reads.
There is a trap specific to resellers: putting that mailbox on the hosting you resell. If the account is suspended, or the platform is the thing having the incident, you have locked your recovery route inside the burning building. Keep the contact address somewhere independent, secure it harder than anything else you own, and check it is current today rather than on the day you need it.
What you can require of clients, and how to enforce it
You cannot make a client care. You can, however, decide what their account exposes. Give each client the cPanel features their site actually needs, keep terminal and account-level tools out of packages that do not need them, and set the initial password yourself from a manager rather than letting them choose one at signup.
Then write the expectations into the agreement: their credentials are theirs to protect, shared logins are not supported, and a compromise caused by their own password is billable work. That paragraph costs nothing to include and is the difference between a bad week that is chargeable and a bad week that is not.

Separation is the product, not a premium tier
A Hosting Seller reseller package gives you WHM and every client a cPanel of their own, with limits you set per account. That separation is what stops one client's mistake reaching the others, and it is switched on from the first account you create.
Imunify360 stands guard on every client site, and a backup is taken daily across every account — so the recovery path exists before you need to think about it.
- A cPanel of their own for every client
- Limits you set per client account
- Imunify360 on guard on every client site
- Daily backups across the whole estate
Why Hosting Seller
On every plan, as standard
Ordered by damage, not by habit
The work is sequenced by what each credential can destroy, which is rarely the order people actually work in.
Inventory over intuition
The page assumes you have forgotten half the logins that exist, because every reseller has.
Client obligations spelled out
What to put in the agreement is written out, including the clause that makes a client-caused breach billable.
Sized for an estate
Everything is described per account and then per estate, so the routine still works at forty clients.
Recovery kept outside the fire
The one mistake that defeats every other control — recovery inside the resold platform — is called out explicitly.
Support that answers at any hour
People are on the counter for you and for your clients, including during the hours an incident prefers.
First Steps
From choosing to live
- 1
List the layers and what each one can destroy
Billing, WHM, each client cPanel, the registrar, the recovery mailbox. Five minutes with a pen. Everything after this is done in the order that list produces rather than the order you happen to log in.
- 2
Give billing and WHM separate manager-generated passwords
Not variants of each other, not variants of anything you have used elsewhere. These two are the accounts that can provision, suspend and terminate, so they get the strongest and the least memorable.
- 3
Sweep every account for credentials you cannot justify
FTP accounts, database users, API tokens, extra panel users, and any reseller-under-you with creation rights. Delete on sight. Reissuing a credential takes five minutes; discovering one you forgot takes a week.
- 4
Move the recovery mailbox off the platform you resell
If the account is suspended or the platform is the incident, a recovery address inside it is useless. Put it somewhere independent, secure it harder than anything else, and confirm it is current now.
- 5
Set the client's password and their panel scope yourself
Issue the initial credentials from your manager and give the package only the features that account needs. Then put the expectations in writing so a client-caused compromise is chargeable work rather than an argument.
In the Box
Packed with every plan
- WHM for you, and a cPanel of their own for every client account
- cPanel, the panel your clients and your contractors already know
- Imunify360 on guard on every client site
- Daily backups taken across every client account you create
- Packages you build, name and price yourself
- Client-account allowances of 100, 250 or 500, depending on the package
- DDoS filtering handled out at the network edge
- Real people answering, for you and for your clients, at any hour
- A 99.9% uptime target, watched by monitoring day and night
- Seven days' money back on reseller hosting, thirty on hosting plans
Across the Counter
Things people ask us all the time
If a client's cPanel is compromised, is my WHM at risk?
Not directly — each client account is separated, which is the whole point of reselling rather than stacking sites into one account. The realistic risk is lateral: shared or reused passwords between a client's panel and something of yours, and any credential you issued to that client which also opens another account.
What is the safe way to give a contractor access to one client account?
Create a credential scoped to that account and nothing else — an FTP user or a separate panel user on that cPanel — never your WHM login and never the client's master password. Diary the removal for the day the work ends, because the credential you forget is the one that matters.
Should my recovery mailbox live on the hosting I resell?
No. If the account is suspended, or the platform itself is having the incident, your recovery route is trapped inside the problem. Keep the contact address with an independent provider and protect it harder than anything else you own.
Can I force two-factor authentication on my clients?
You cannot make them switch it on, but you can shape what their account exposes, issue the initial password yourself, and put credential responsibility in the agreement. Where a client account holds a shop or customer data, make the requirement a condition of that package rather than a suggestion.
Read next
PHP Hosting
Per-site PHP versions and the extensions a client's legacy build still needs.
CMS Hosting
One account, several CMS builds, each with the PHP version it wants.
Moving your site to another host? Start with this checklist.
A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.
Sell separation, not shared risk.
WHM for you, a cPanel of their own for every client, Imunify360 on every site, and limits you set account by account.
See PHP Hosting plans