Skip to content
UK web hosting, domain names, email, website security and online services.

Secure hosting and application passwords Print

  • security, hosting
  • 0

Every administrator, mailbox and file-transfer account should use a unique strong password.

Applies to: Website security, malware and Imunify360

A clean malware scan does not prove an application is secure. Effective recovery combines containment, credential rotation, patching, file and database review, and monitoring for reinfection.

Before you start

  • Sign in to the Customer Portal and open the affected hosting service.
  • Take a current backup before changing website files, databases, DNS or application configuration.

Step-by-step

  1. Use a reputable password manager. Do not include the secret in a ticket, email or screenshot.
  2. Enable multi-factor authentication wherever offered.
  3. Remove unused accounts. Read the confirmation text because the action may remove data or interrupt service.
  4. Rotate credentials after staff changes or suspected compromise. Do not include the secret in a ticket, email or screenshot.

Confirm the result

  • The affected site is patched, credentials are rotated and no unauthorised file, user, scheduled task or redirect remains.
  • A fresh scan and follow-up monitoring show no immediate reinfection while the website continues to function normally.

Common problems

SymptomLikely causeWhat to do
The login page keeps rejecting the details.The wrong email address, an old password, browser autofill or an account-specific lockout is being used.Type the account email manually, use the password-reset process once and avoid repeated attempts that may extend a lockout.
A one-time code is not accepted.The device clock is inaccurate, the code belongs to a different account or an older code was entered.Set the device time automatically, wait for a fresh code and confirm the authenticator entry name before trying again.

When to contact Tudor Internet

Open a ticket through the Customer Portal when the checks above do not resolve the issue, when an action is unavailable for your service, or when continuing could risk data loss or service interruption. Include the following so the request can be investigated efficiently:

  • The affected domain and SiteWorx account
  • The exact error text and time
  • The last change made
  • Relevant log lines with passwords and personal data removed
Do not send passwords, private keys, full payment-card details, one-time authentication codes or unredacted identity documents in an ordinary support reply.

Related articles

Last reviewed: 2026-07-18.


Was this answer helpful?

« Back