Every cPanel account comes with a built-in firewall called ModSecurity, and most hosts turn it on by default. But occasionally it gets switched off, either by you or your provider, and your website stays exposed until someone flips it back on. If you’re not sure whether ModSecurity is active or you just disabled it and want it back, here’s how to turn it on in a couple of minutes.
How Do I Turn On WAF (ModSecurity) in cPanel?
Step 1: Sign In to cPanel
Use the URL, username, and password your host issued at signup. The host sends these details in the account confirmation email upon account creation.
Step 2: Head to the Security Section
Once you’re inside cPanel, scroll down to the Security section on the dashboard. Most themes group it near the bottom, though a few hosts move it up top. You’ll spot several icons here, including one labeled ModSecurity.
Step 3: Click on “ModSecurity.”
Click that icon and cPanel will load a page listing every domain and subdomain tied to your account. Each one gets its own row, so you’re not stuck turning the firewall on or off for everything at once.
Related Read: How to Configure WAF Rules for Maximum Security?
Step 4: Pick the Domain You Want to Secure
Scroll through the list and find the domain you’re working on. If you manage multiple websites under one account, please take a moment to ensure you’re selecting the correct one. It’s easy to pick the wrong one when the list runs long.
Step 5: Flip the toggle to “On.”
Next to your domain, you’ll see an On/Off switch. Click it once to enable ModSecurity. There’s no save button and no confirmation popup; the change takes effect immediately.
Step 6: Verify the Update
The toggle switches to “On” beside the domain name. That confirms ModSecurity is running on the domain. Additionally, take a moment to quickly browse the website to ensure that nothing you are running has been mistakenly blocked.
Related Read: How to Enable WAF in Plesk?
A Few Important Considerations
Enabling ModSecurity is one of the simplest ways to enhance website security in cPanel, but it is not a comprehensive solution. If your website uses a page builder, a custom form, or an API, watch your traffic for the next day or so. Occasionally a legitimate request gets flagged as suspicious and blocked. If that happens, your host’s support team can help you whitelist the specific rule instead of turning the whole firewall off again.
