Hosting control panel password requirements
What counts as a strong password in the hosting control panel: minimum length 8, Strong strength, and which accounts it covers.
When you create or change a password inside your web hosting account control panel, the server checks it against our Strong policy and a minimum length of 8. Weak or common passwords are rejected before they are saved.
This page covers only passwords for your web hosting account control panel. It does not cover the client area login or passwords inside apps you install (WordPress, plugins, and similar).
Requirements
| Rule | What we require |
|---|---|
| Minimum length | 8 characters |
| Strength | Strong |
| Character mix (Strong) | Upper and lower case letters and at least one digit |
| Common passwords | Blocked (dictionary of well-known weak passwords) |
The password must be at least 8 characters and meet the Strong character mix above. Common passwords remain blocked. Special characters are not required by these rules.
Tips that usually pass:
- Mix uppercase and lowercase letters and include a digit
- Prefer a longer passphrase that still includes mixed case and a digit
- Avoid names, domains, years, and keyboard patterns (
Password1,Welcome123, and similar)
Where it applies
The policy applies to passwords you set in your web hosting account control panel, including:
- The main hosting control panel user
- FTP accounts
- Email mailboxes
- Shell users (when shell access is enabled on the plan)
- MySQL / MariaDB users
It does not apply to:
- The HostBill client area password (reset that separately)
- Third-party application passwords (WordPress admin, CMS plugins, SaaS tools)
- Passwords stored only in your local apps or password managers
If the panel rejects the password
- Check length is at least 8.
- Include an uppercase letter, a lowercase letter, and a digit.
- Avoid common words and simple substitutions; try a fresh passphrase.
- Confirm the two password fields match exactly.
- Try saving again. If the password meets these requirements but is still rejected, open a ticket and include the screen name and exact error message—never include your password.
Change a panel password
Open the hosting control panel from the client area service page, then edit the user, FTP account, mailbox, shell user, or MySQL user whose password you want to change. Use a unique password per account; do not reuse the client-area password.
After you change a password, update any saved credentials in your email or FTP clients, and in application database settings where the old password is stored.