Login protection
A 2FA challenge confirms that the person entering the password also controls the selected second factor. A new browser session, cleared cookies or security-sensitive login can require another code.
New authenticationProves the second factor.
Browser state mattersPrivate mode forgets sessions.
Codes expireUse the current challenge.
Why it appears
Without access to the email account or authenticator, the password alone should not complete the login. This is especially important when the account can change domains, DNS and billing details.
Why frequency varies
Signing out, using private browsing, clearing cookies, changing device or browser, or security controls can trigger a fresh challenge. Shared devices should not retain trusted sessions.
Use the right code
Email codes expire after ten minutes. Use the newest active challenge and do not press the login button repeatedly; the interface locks after submission while WHMCS processes the request.
Article feedback