Skip to main content
Billing & Account

Keeping your account secure

Your hosting account controls your website and your email. Email is the password-reset route for everything else you own. It's worth ten minutes.

Turn on two-factor authentication

Everywhere it's offered:

  • The client area — Profile → Two-factor authentication
  • Your Microsoft 365 mailboxaka.ms/mfasetup
  • Your domain registrar, if your domains are elsewhere

Use an authenticator app rather than SMS where you have the choice. SIM swapping is a real attack and it's not difficult.

Save your recovery codes somewhere that isn't the account they unlock.

Passwords

Length beats complexity. Three or four unrelated words is stronger than P@ssw0rd! and you'll actually remember it.

Never reuse a password across sites. Credential-stuffing attacks take username and password pairs from one breach and try them everywhere — a password reused on a forum that got breached in 2019 is how a lot of hosting accounts get taken.

Use a password manager. Bitwarden, 1Password and your browser's built-in one are all fine, and any of them beats reuse.

Keep your software patched

On shared hosting, the overwhelming majority of compromises come through outdated WordPress plugins, not through the server.

  • Turn on automatic updates in Plesk's WordPress Toolkit.
  • Delete plugins and themes you don't use. Inactive code is still code

an attacker can reach.

  • Be wary of nulled premium plugins. They very often ship with a

backdoor — that's the business model.

Spotting a phishing email

We will never email you asking for your password, and we will never send you a link demanding immediate action to avoid suspension.

Signs to look for:

  • A sender domain that's close but not right — apaxonh0st.com,

apaxonhost-billing.com

  • Urgency: "your account will be terminated in 24 hours"
  • A link whose text and destination don't match (hover to check)
  • An attachment you weren't expecting

When in doubt, don't click. Open apaxonhost.com yourself and sign in directly. If it's real, it'll be in your client area.

Forward anything suspicious to abuse@apaxonhost.com.

If you think you've been compromised

Tell us immediately. We would much rather help you clean up early than find out when a blocklist does. We don't penalise anyone for reporting a compromise — a quick report is the best outcome for everyone.

Then, in this order:

  1. Change your email password first. It's the reset route for

everything else.

  1. Change your client area and Plesk passwords.
  2. Check for mail-forwarding rules you didn't create — attackers add

them to keep reading your mail after you lock them out.

  1. Review users on your WordPress site and remove any you don't

recognise.

We can restore from backup, scan for injected files, and check the mail logs for what went out.

Was this guide helpful?

Didn’t solve it?

Open a ticket with your domain name and what you’ve already tried — it gets you a faster answer.