Viewing articles tagged 'security ssl'

Activating a NordVPN subscription purchased through Nabtech

A NordVPN subscription protects the connection between a supported device and the VPN service....

Activating free SSL and resolving HTTPS warnings

Our Web Hosting product includes free SSL, allowing supported domains to use HTTPS once the...

Activating SiteLock and checking your website protection

SiteLock packages can provide different combinations of scanning, cleanup and firewall...

Adding a narrow sender exception in SpamExperts

Add a sender exception in SpamExperts only for a defined legitimate need. Verify the real...

Adding a SiteLock trust seal without making misleading claims

Use the SiteLock-generated trust seal for the website it belongs to, and verify that its linked...

Adding Cloudflare Turnstile with mandatory server-side verification

Turnstile can protect a form from unwanted automated submissions, but the server must validate...

Adding or removing names from a multi-domain certificate

Changing a multi-domain certificate requires a planned reissue and deployment. Adding a...

Adjusting Cloudflare Challenge Passage

Challenge Passage controls how long a visitor who successfully completes an eligible Cloudflare...

Applying an available rate-limit rule to an abused login endpoint

A rate-limit rule can reduce repeated requests to an abused login endpoint. Design it from...

Applying Ubuntu Server security updates with a restart plan

Apply Ubuntu Server security updates with an explicit service-restart and reboot plan....

Binding an HTTPS certificate to an IIS website

Bind a valid server certificate to the intended IIS website so clients can authenticate the...

Blocking a specific IP address with current Apache access rules

An IP-based rule can prevent requests from a known address from reaching part of a website. It...

Blocking an unwanted sender in SpamExperts

Use a SpamExperts sender block entry for repeated unwanted mail from a known address or domain....

Blocking an unwanted website visitor with cPanel IP Blocker

IP Blocker restricts website access from an address or range. It is a web access control, not a...

Changing a user's role without losing content ownership

Changing a WordPress user's role adjusts their capabilities while keeping the account and its...

Changing a WHM server hostname with DNS and certificate checks

The server hostname identifies WHM and other system services and can appear in mail headers....

Changing the public display name of a WordPress user

Your public display name controls the author label shown by many WordPress themes and comments....

Changing your WordPress account password

Change your WordPress password from your profile when you can sign in. If you cannot sign in,...

Checking HTTPS after enabling a website security proxy

A security proxy creates two connections to check: the browser connects to the proxy, and the...

Checking the destination mail server behind SpamExperts

The SpamExperts destination is the server that receives mail after filtering. It must point to...

Checking which messages an email archive actually captures

Verify what SpamExperts archiving captures before relying on it for business record retention....

Checking which names a wildcard certificate protects

A wildcard such as *.example.com covers a single leftmost label, such as shop.example.com....

Choosing an SSL certificate for the names your website uses

A TLS certificate, often sold as an SSL certificate, helps browsers establish an encrypted...

Choosing Cloudflare bot controls that fit the site and plan

Cloudflare’s bot products differ in available controls and exception support. Choose settings...

Choosing which cPanel hostnames AutoSSL should manage

AutoSSL inclusion determines which eligible hostnames participate in automatic certificate...

Closing comments on selected posts

Close comments on a post when it should no longer accept new discussion while preserving its...

Complete HostBill security settings after installation

Complete HostBill's security configuration before accepting real customer information. The work...

Complete the WHMCS security checks after installation

Complete the security configuration of a self-hosted WHMCS installation before accepting...

Completing a certificate authority's DNS validation request

DNS certificate validation proves control by publishing the certificate authority's exact...

Completing certificate domain validation by email

Email domain validation works when an authorised person receives and approves the certificate...

Completing HTTP file-based certificate validation

File-based certificate validation requires the issuer's challenge to be publicly available at...

Completing SiteLock website ownership verification

Complete the ownership check shown for the exact website in your SiteLock account. A paid order...

Configuring a useful SpamExperts quarantine report

Email Scout Reports summarise messages matching a defined SpamExperts search. Configure the...

Configuring comment moderation and disallowed words

Discussion rules can hold suspicious comments for review or classify them according to the...

Configuring Django hosts and CSRF origins behind HTTPS

Django checks hostnames and browser request origins to protect application requests. A...

Configuring NordVPN auto-connect for a supported device

Configure NordVPN to connect automatically on the network types you choose, then test that...

Configuring outgoing filtering and investigating blocked messages

Outgoing filtering helps detect unwanted or malicious mail before your server sends it to...

Connect deSEC while preserving its DNSSEC and delegation requirements

deSEC signs the zones it serves and manages their signing keys. Domain Nexus exposes that...

Coordinate a DNSSEC key rollover with the registrar's DS update

A DNSSEC key rollover replaces signing keys while allowing cached trust information to remain...

Creating a certificate signing request in Plesk

For a certificate ordered outside an automated Plesk workflow, generate a CSR in the domain's...

Creating a limited Cloudflare API token for DNS automation

A scoped Cloudflare API token lets an integration manage only its required resources. For DNS...

Creating a narrowly scoped Cloudflare WAF custom rule

A Cloudflare WAF custom rule should match a clearly defined unwanted request pattern. Start...

Creating a narrowly scoped Windows Firewall rule

Create a Windows Firewall rule for the specific service, port and remote sources that need...

Creating a WordPress user with the right role

Create a separate WordPress user for each person and assign the least role needed for their...

Creating and revoking WordPress application passwords

An application password lets an approved integration authenticate to WordPress without storing...

Deactivating a SiteWorx user while preserving the account

Deactivating a secondary SiteWorx user stops the intended panel access while preserving a...

Delegate certificate DNS validation without exposing the main zone credential

DNS-01 certificate validation proves control through a TXT record at an _acme-challenge name. A...

Delegating SiteWorx access to a secondary user

A secondary SiteWorx user can perform selected account-management tasks without receiving the...

Deleting an unused CSR from cPanel

Deleting a stored CSR removes that request from cPanel’s request list. It does not revoke an...

Diagnose DNSSEC validation failures that appear as SERVFAIL

DNSSEC validation can turn an otherwise visible DNS answer into SERVFAIL when the chain of...

Diagnosing a legitimate request blocked by ModSecurity in cPanel

ModSecurity is a web application firewall that can block suspicious requests before the...

Diagnosing a pending Cloudflare edge certificate

An edge certificate protects the browser-to-Cloudflare connection. If its status remains...

Diagnosing Cloudflare error 525 during the origin TLS handshake

Cloudflare error 525 means its TLS handshake with the origin failed. The browser may already...

Diagnosing Cloudflare error 526 with Full strict TLS

Cloudflare error 526 indicates that the origin certificate cannot be validated for the...

Diagnosing Linux TLS errors caused by trust or clock problems

TLS failures on a Linux client can come from a wrong clock, hostname mismatch, incomplete...

Diagnosing Rails host authorization and HTTPS redirect loops

A Rails app behind a proxy needs consistent host and HTTPS information. Host authorization...

Disabling directory listing and protecting private files

Directory listing can reveal filenames when a directory has no default index page. Disabling...

Distinguishing spam comments from genuine customer feedback

Review a comment's relevance, intent and links before classifying it as spam. Genuine...

Enable optional website insights, malware and performance tools

Several website manager features depend on server software or an external service. Configure...

Enabling DNSSEC for a Plesk-managed zone

DNSSEC lets validating resolvers verify signed DNS answers. A Plesk-signed zone needs a...

Enabling HSTS only after all required hostnames support HTTPS

HSTS tells browsers to require HTTPS for a period of time. Enable it only after HTTPS is...

Enabling SiteWorx two-factor authentication

SiteWorx two-factor authentication adds a time-based code to the user’s panel login. Configure...

Enabling two-factor authentication for a cPanel login

cPanel two-factor authentication adds a time-based code to the panel login after the password....

Enabling two-factor authentication for WHM administration

Two-factor authentication adds a time-based code to supported WHM interactive logins. Configure...

Enabling two-factor authentication in Webmin

Enable two-factor authentication for Webmin administration so the browser login needs both the...

Ending other WordPress login sessions

End other WordPress browser sessions when you have finished using a shared device or suspect an...

Exporting personal data through WordPress privacy tools

WordPress's personal-data export tool can gather information associated with a verified person...

Exporting selected archive messages for an authorised request

Export the specific archived messages required for a migration or authorised review. The...

Finding a held message in SpamExperts quarantine

Use the SpamExperts quarantine to find messages held by the filtering service before delivery....

Finding and copying an existing CSR in cPanel

You can retrieve a previously generated certificate signing request from cPanel when a...

Finding and correcting mixed content on an HTTPS website

Mixed content occurs when an HTTPS page requests resources over insecure HTTP. Fix the resource...

Finding mixed content when HTTPS works through Cloudflare

Mixed content occurs when an HTTPS page requests assets through HTTP. The main certificate can...

Fixing a certificate hostname mismatch

A hostname mismatch means the certificate presented by the server does not cover the name the...

Fixing a Cloudflare HTTPS redirect loop

A redirect loop occurs when Cloudflare and the origin disagree about the expected scheme or...

Fixing an incomplete certificate chain

An incomplete certificate chain means a client cannot build the required trust path from the...

Fixing valid-recipient rejection in incoming filtering

SpamExperts can check whether a recipient exists before accepting mail for delivery. If a new...

Generating a certificate signing request in cPanel

A certificate signing request, or CSR, contains the public-key and identity information needed...

Getting a free HTTPS certificate for a cPanel website

An eligible cPanel website can use the server’s AutoSSL service to obtain and renew a...

Install Domain Nexus in WHMCS and initialise its secure storage

Install the current Domain Nexus release in a backed-up WHMCS environment, initialise its...

Installing a Cloudflare Origin CA certificate and understanding its trust

Cloudflare Origin CA certificates secure traffic between Cloudflare and a proxied origin. They...

Installing an issued certificate through cPanel

Install the issued certificate in the cPanel account serving the website, using its matching...

Installing and assigning an issued certificate in Plesk

Use the supported Plesk upload path for your certificate files, then confirm that the website...

Interpreting an outgoing-filter rejection message

Use the complete SMTP response to diagnose outgoing mail rejected through SpamExperts....

Investigating a certificate warning in an email application

A mail certificate warning concerns the server your application is connecting to. Compare that...

Investigating a Cloudflare WAF false positive with Ray IDs

When a legitimate action is blocked, use its Ray ID and request time to identify the Cloudflare...

Investigating a DirectAdmin brute-force block

DirectAdmin Brute Force Monitor records repeated authentication failures and can work with...

Investigating a legitimate request blocked by a website firewall

Investigate a blocked legitimate request by matching the visitor's failure to a specific...

Investigating a slow connection while NordVPN is active

Compare like-for-like measurements to identify why a NordVPN connection feels slow. The local...

Investigating malware and recovering a WordPress website

Treat a malware alert or unexpected website behaviour as a reason to investigate promptly. Our...

Investigating queued incoming mail during an outage

The incoming delivery queue holds mail the filter has accepted but cannot currently deliver to...

Investigating TLS delivery failures through email filtering

Review both inbound TLS connections when requiring encrypted delivery through SpamExperts: the...

Inviting contributors without sharing administrator credentials

Give a contributor their own account and a clear submission workflow instead of sharing an...

Issuing a website certificate in Webuzo

Issue a website certificate through Webuzo Automatic SSL after the domain points to the...

Issuing an automatic TLS certificate in DirectAdmin

DirectAdmin can request and renew ACME certificates for hosted domains when that capability is...

Issuing and renewing a certificate with Plesk SSL It

Plesk SSL It can request and manage a certificate for the hostnames used by a website. Include...

Keeping business services under the right account ownership

Keep business services under documented business control, with named people authorised to...

Limiting shared directory credentials with Leech Protection

Leech Protection can respond to unusual login activity in directories protected by HTTP...

Managing separate edge and origin certificates for a CDN

Track edge and origin certificates separately when a CDN or security proxy handles HTTPS. The...

Managing SolusVM login alerts and account security

Login notifications help you notice unexpected access, but they do not prevent it. Current...

Moderating comments before publication

Comment moderation lets an authorised editor review submissions before they appear publicly....

Moving a Cloudflare site to Full strict TLS safely

Full (strict) encrypts the Cloudflare-to-origin connection and validates the origin...

Operate DNSSEC from zone signing through parent DS verification

DNSSEC requires a signed authoritative zone and a matching chain of trust at its parent. Domain...

Password-protecting a website folder with cPanel Directory Privacy

Directory Privacy places a browser login in front of a website folder, making it useful for a...

Planning a staff departure across email and shared files

Plan a staff departure across email, shared files and connected applications before deleting...

Planning email archiving, retention and authorised searches

Email archiving preserves messages according to the archive service's configured scope and...

Planning HSTS after every required hostname works with HTTPS

Enable HSTS only after the required website names work reliably over HTTPS and certificate...

Planning origin access restrictions behind Cloudflare

Origin access restrictions can prevent ordinary visitors from bypassing Cloudflare and reaching...

Prepare Route 53 KMS permissions before enabling DNSSEC

Route 53 DNSSEC depends on a key-signing key backed by a suitable AWS KMS customer managed key....

Preparing a website for an eligible SiteLock firewall service

An eligible SiteLock firewall service sits in the website traffic path. Prepare the origin,...

Preparing email and collaboration access for a new employee

Prepare a new employee's email and collaboration access from an approved role request. Giving...

Preventing comment form abuse without blocking all visitors

Reduce comment abuse with targeted moderation and supported anti-spam controls, then test that...

Preventing unintended directory listings in cPanel

A directory listing can expose filenames when a website folder has no index page. cPanel’s...

Preventing unwanted image hotlinking with cPanel

Hotlink Protection can restrict other sites from embedding selected files hosted on your...

Processing a WordPress personal-data erasure request

WordPress's erasure tool can remove or anonymise eligible personal data from core and...

Protecting .htaccess and configuration files from public downloads

A public request for .htaccess should not return the file contents. This file can reveal...

Protecting a Plesk account with two-factor authentication

Multi-factor authentication adds a second verification step to a Plesk account. Current...

Protecting a SiteWorx preview directory with a browser password

A browser password can protect a preview directory before the website is public. SiteWorx’s...

Protecting your Web Hosting website and responding to a compromise

Our Web Hosting environment combines hosting-level protections with account tools that help you...

Providing the access needed for eligible SiteLock cleanup

File scanning and eligible cleanup require a working connection to the website files. Configure...

Reading a SiteLock scan report and assigning the next action

A SiteLock report is useful when each finding becomes a specific action with an owner and a...

Reading Cloudflare security events for an incident

Security Events explains actions taken by Cloudflare security products. Use it to investigate a...

Recovering the Nord Account used by your VPN subscription

Recover the Nord Account associated with your activated VPN subscription before creating a...

Recovering Zoho account access after losing an MFA device

If you lose the phone or authentication method used for Zoho, first try the recovery methods...

Redirecting HTTP to HTTPS safely with an Apache .htaccess rule

Use an HTTPS redirect after the website has a valid certificate and works correctly over HTTPS....

Releasing a legitimate SpamExperts quarantined message

Release a quarantined SpamExperts message only after confirming that it is expected and safe...

Removing a WordPress user and reassigning their content

When a person no longer needs WordPress access, remove or restrict the account while preserving...

Removing an obsolete SiteLock integration carefully

Remove an obsolete SiteLock integration in the right order. A website that still routes through...

Renewing and replacing SSL certificates under current validity limits

Renewal requires a valid certificate to be issued and installed before the current one expires....

Replacing a certificate when the private key is lost or exposed

A certificate cannot be installed with an unrelated private key. If the matching key is...

Replacing a shared mailbox password with controlled team access

Replace a shared mailbox password with named, controlled access where the product supports it....

Replacing an expiring Windows Server certificate without breaking bindings

Installing a renewed certificate in Windows does not always switch the services that use it. A...

Replacing or removing cPanel two-factor authentication

When changing phones, reconfigure cPanel 2FA so the new authenticator can generate valid codes....

Reporting a legitimate message incorrectly filtered as spam

A false positive is legitimate mail classified as unwanted. Correct the particular message and...

Reporting unwanted mail that passed SpamExperts filtering

A false negative is unwanted mail that passed filtering. Report representative originals and...

Requesting a review of a suspected SiteLock false positive

A suspected false positive needs evidence and review. Keep the warning visible while you...

Requesting and renewing a certificate in Virtualmin

Request a trusted HTTPS certificate for a Virtualmin domain after its public names reach the...

Requesting certificate revocation after a key compromise

Report a compromised certificate private key promptly and arrange revocation through the issuer...

Responding to a SiteLock alert or a hacked website

Treat a malware alert as a problem to investigate, contain and verify. Removing a suspicious...

Responding to unusual outgoing traffic or a suspended sender

If SpamExperts detects abusive outgoing mail, contain the affected sender before restoring...

Restricting a private directory to trusted IP addresses

An allowlist limits a directory to trusted source IP addresses. It can add a useful layer...

Restricting access to an organisation's email archive

Restrict archive search and export to people with an approved business reason. A domain-wide...

Restricting Ubuntu firewall access without locking out SSH

Use UFW to permit required services and restrict administrative access on a self-managed Ubuntu...

Retrying AutoSSL after fixing a certificate-validation problem

An AutoSSL retry is useful after correcting the reason a hostname could not be validated....

Review customer DNSSEC and reverse DNS requests

Customer requests let your company review selected DNS actions before they are performed. This...

Reviewing a suspected phishing message before release

Treat an email requesting a password, payment change, unusual download or urgent secrecy as a...

Reviewing firewall access for Webmin and hosted services

Permit the Webmin administration listener and hosted services through the firewall only where...

Reviewing WooCommerce customer account security

Review customer account security so buyers can access their own orders and downloads without...

Reviewing WordPress administrator accounts

Review administrator access regularly so every powerful account has a known owner and a current...

Reviewing WordPress security findings and protection tools

Our NabWP Security area helps you understand the security condition of the selected WordPress...

Roll out two-factor authentication for WHMCS users and staff

Enable two-factor authentication in WHMCS with a tested enrolment and recovery process. This...

Rotating an outgoing filtering credential safely

SpamExperts outgoing filtering requires an authorised relay route and authentication method....

Searching an enabled SpamExperts email archive

Search SpamExperts archiving when you need a retained message that the purchased archive...

Securing a WordPress website with practical maintenance and access controls

A secure WordPress website needs maintained software, controlled access, reliable recovery and...

Send our support team useful screenshots and logs without exposing secrets

A focused screenshot or log excerpt helps us understand your problem faster. It should show the...

Setting FastAPI CORS for a separate website origin

A browser treats scheme, hostname and port as part of an origin. A frontend on one origin may...

Setting up an actionable certificate-expiry check

An actionable certificate check combines the public expiry information with a named renewal...

Setting up incoming email filtering without interrupting mail

Incoming email filtering checks messages before they reach your mailbox server. Our...

Signing a DirectAdmin DNS zone with DNSSEC

DNSSEC signs a DirectAdmin-managed zone so validating resolvers can verify its answers. The...

Tracing a SpamExperts message by sender, recipient and time

Trace one message through SpamExperts before changing filters. The aim is to identify whether...

Troubleshooting browser CORS errors for an API

CORS is a browser-enforced rule for reading responses across origins. It is separate from DNS,...

Troubleshooting NordVPN connections and website access

When a website stops working while NordVPN is connected, determine whether the problem is the...

Turning WHM Security Advisor findings into an action plan

Security Advisor checks server configuration and reports findings with suggested actions. Treat...

Understand HTTPS and SVCB records before adding them to a hosting zone

HTTPS and SVCB records can advertise service endpoints and connection parameters to compatible...

Understanding a certificate issuance failure caused by CAA

A CAA failure can mean that your DNS policy does not authorise the requested certificate...

Understanding and testing NordVPN Kill Switch behaviour

Kill Switch controls what happens when traffic cannot use the VPN connection. Its behaviour...

Use CAA records to authorise the certificate authorities your services need

CAA records let a domain operator express which certificate authorities may issue certificates...

Using Cloudflare Under Attack mode during a web attack

Under Attack mode adds a browser challenge before eligible requests reach the site. It can help...

Using Cloudflare’s current security controls instead of old security levels

Older Cloudflare guides refer to selectable Low, Medium or High security levels. Current...

Using NordVPN split tunnelling where your platform supports it

Use split tunnelling when an approved application needs a different network path from the rest...

Using SiteWorx advanced .htaccess controls carefully

The SiteWorx Htaccess interface controls directory-level web settings such as redirects, access...

Using the available cPanel Virus Scanner and reviewing its limits

The optional Virus Scanner checks selected account data using the server’s available scanning...

Using two-factor authentication with a recovery plan

Two-factor authentication adds a second verification step to WordPress login. Set up a recovery...

Verifying a website after SiteLock cleanup or manual repair

Close a cleanup incident only after both the security findings and the affected business...