Login protection

Why a new 2FA code may be required at login

A 2FA challenge confirms that the person entering the password also controls the selected second factor. A new browser session, cleared cookies or security-sensitive login can require another code.

New authenticationProves the second factor.

Browser state mattersPrivate mode forgets sessions.

Codes expireUse the current challenge.

Why it appears

The code limits what a stolen password can do

Without access to the email account or authenticator, the password alone should not complete the login. This is especially important when the account can change domains, DNS and billing details.

Why frequency varies

Sessions can end or be forgotten by the browser

Signing out, using private browsing, clearing cookies, changing device or browser, or security controls can trigger a fresh challenge. Shared devices should not retain trusted sessions.

Use the right code

Submit once and wait for the login to complete

Email codes expire after ten minutes. Use the newest active challenge and do not press the login button repeatedly; the interface locks after submission while WHMCS processes the request.

Was this answer helpful?

« Back