Short answer: Two-factor authentication (2FA) asks for a second proof, such as a code from an app or a security key, in addition to the password, so a stolen or guessed password alone is not enough to log in. Website owners should turn it on first for the accounts that control everything else: the domain registrar, DNS provider, hosting account, the e-mail account used for password resets and every CMS administrator. Use an authenticator app or security keys, store recovery codes safely and give each person their own login.
Why passwords alone are not enough
Most website takeovers do not start with clever hacking. They start with a password that was reused on another service, leaked in a data breach, guessed, or typed into a convincing phishing page. Once an attacker has it, they log in as you and change what they like.
A second factor breaks that chain. Even with the correct password, the attacker also needs something only you have, usually your phone or a hardware key. That is why security agencies such as CISA recommend multi-factor authentication as one of the most effective basic protections for any organisation.
2FA does not replace good passwords, updates or backups. It closes one specific and very common door: logging in with stolen credentials.
The five accounts to protect first
A website depends on more accounts than most owners realise. These five decide who controls it, so they come first:
- Domain registrar. Whoever controls the registrar account can point the domain anywhere, move it to another registrar or let it expire. Losing it means losing the website and e-mail at the same time. Combine 2FA with a registrar lock, as described in our guide on protecting your domain from hijacking.
- DNS provider. If DNS is hosted separately, for example with a CDN, that account can redirect your visitors and your mail. Protect it the same way as the registrar.
- Hosting account and control panel. This gives access to files, databases, backups and often e-mail boxes. An attacker here can install malware or copy customer data.
- The e-mail account used for password resets. Almost every other service lets you reset a password by e-mail. If the recovery mailbox falls, everything linked to it can fall too.
- CMS administrator accounts. In WordPress, Joomla, Shopify or any other CMS, every account with administrator rights can install code. Each of them needs 2FA, not only the owner’s.
After these, add 2FA to the accounts that can change what visitors see or receive: the CDN, the payment provider, the newsletter tool, Google Search Console, analytics and any code repository used for deployment.
Which 2FA method to choose
Not all second factors are equally strong. The main options, from strongest to weakest:
| Method | So funktioniert’s | Strength | Notes |
|---|---|---|---|
| Security keys and passkeys | A hardware key or device confirms the login cryptographically | Highest | Resistant to phishing, because the key checks the real website address |
| Authenticator app (TOTP) | An app shows a six-digit code that changes every 30 seconds | Strong | Works offline; can still be phished if you type the code into a fake page |
| Push approval | The phone asks you to approve the login | Strong if used carefully | Never approve a request you did not start |
| SMS code | A code is sent by text message | Weaker | Vulnerable to SIM swapping; still far better than no 2FA |
| E-mail code | A code is sent to your mailbox | Weakest | Only as safe as the mailbox itself |
For most small businesses, an authenticator app for everyone and security keys for the owner’s registrar, hosting and main e-mail accounts is a practical, affordable combination. Use SMS only where nothing better is offered.
How to set up 2FA without locking yourself out
The fear of being locked out stops many owners from enabling 2FA. A little preparation removes that risk:
- Save the recovery codes. Most services show one-time backup codes when you enable 2FA. Store them in a password manager or print them and keep them in a safe place, not only on the phone that generates the codes.
- Add a second factor where possible. Register two security keys, or an app and a key, so a lost device is not a crisis.
- Keep the phone number and recovery e-mail current. Outdated recovery details are a common cause of permanent lockouts.
- Test before you rely on it. Log out and log in again on another device to confirm everything works while you still have access.
- Write down which accounts use which method. A short, private list saves time when a phone is replaced.
When you change phones, move your authenticator app first, using its transfer function or by re-enrolling each account, before you reset the old device.
2FA for WordPress and other CMS logins
Some platforms include 2FA; others need an extension. Hosted platforms such as Shopify and Wix offer it in the account settings. WordPress does not include it in the core, so it is added with a well-maintained security or 2FA plugin.
When you add 2FA to a CMS:
- Require it for every user with administrator or editor rights, not just offer it.
- Give each person their own account. Shared logins make 2FA impractical and remove any record of who did what.
- Remove accounts of former staff, agencies and freelancers who no longer need access.
- Keep the 2FA plugin updated, like any other plugin.
- Combine it with login rate limiting, as explained in our guide to protecting logins from brute-force attacks.
Also check other login paths. In WordPress, for example, application passwords and XML-RPC can allow access without the normal login screen, so disable what you do not use.
Agencies, freelancers and shared access
Websites are often built and maintained by outside people, and access tends to be shared carelessly. A safer approach:
- Invite the agency as a separate user in the registrar, hosting and CMS instead of giving them your own password.
- Use role-based access where the platform supports it, so they only get what they need.
- Ask the agency to use 2FA on their accounts too.
- Keep ownership of the registrar and hosting accounts in the business’s name and with a business e-mail address.
- Review who has access at least twice a year and after every project ends.
If a shared login is unavoidable, store it in a team password manager that supports shared 2FA codes rather than sending codes by chat.
Common mistakes to avoid
- Protecting the CMS but not the registrar. The domain is the key to everything, including your e-mail.
- Using the same phone number everywhere with SMS. One SIM swap then opens every account.
- Keeping recovery codes on the same phone. If the phone is lost, the codes are lost with it.
- Approving unexpected push requests. Attackers send repeated requests hoping you tap “approve” to make them stop.
- Letting a former employee’s account stay active. 2FA protects an account from outsiders, not from someone who still legitimately has the second factor.
If you suspect that an account has already been misused, change the password, reset the second factor, review recent activity and follow a structured plan such as our website recovery steps.
What 2FA does not protect against
It is worth being clear about the limits, so 2FA does not create false confidence. It does not stop attacks that never use a login, such as a vulnerable plugin that lets code run on the server, an outdated CMS version or an exposed backup file. It does not protect a session that is already open on an infected computer, and it does not help if an attacker can reset the account through a poorly protected recovery mailbox.
That is why 2FA works best as one layer among several: updated software, unique passwords in a password manager, regular tested backups and a short list of people with administrator rights.
How Site AI Audit helps
2FA happens behind the login screen, so no outside scan can confirm it for you. What Site AI Audit does check from the outside are the security basics visitors and attackers can see: the SSL certificate and its expiry, the HTTP to HTTPS redirect, security headers, exposed software versions and the e-mail authentication records that stop others sending mail in your name. Together with 2FA on your key accounts, fixing those findings covers a large part of everyday website security. You can run a free check of your website.
Related reading
- Website Security for Small Businesses: Where to Start
- WordPress Security Checklist: 20 Steps That Actually Matter
- Website Security Audit Checklist: What to Check and in What Order
The bottom line
Two-factor authentication makes a stolen password useless on its own, which stops one of the most common ways websites are taken over. Turn it on first for the registrar, DNS, hosting, recovery e-mail and every CMS administrator, prefer security keys or an authenticator app, and keep recovery codes somewhere safe. Give everyone their own account and review access regularly.
FAQ
What is two-factor authentication?
It is a login method that requires two different proofs of identity, usually a password and a code or key from a device you own. A stolen password alone is then not enough to log in.
Is SMS two-factor authentication safe enough?
SMS codes are much better than no second factor, but they can be intercepted through SIM swapping. Use an authenticator app or security key where the service offers one.
Which website account needs 2FA the most?
The domain registrar, because whoever controls the domain controls the website and e-mail. Hosting, DNS, the recovery mailbox and CMS administrator accounts follow closely.
What happens if I lose my phone with the authenticator app?
You log in with the recovery codes saved when you enabled 2FA, or with a second registered key or device, then set up the new phone. Without either, you must go through the service’s account recovery process, which can take days.
Does WordPress have built-in two-factor authentication?
No, WordPress core does not include it. It is added with a reputable, maintained plugin, and it should be required for every administrator and editor account.



