How to Enable or Disable Mod Security in cPanel?
ModSecurity is a web application firewall that protects your domains from attacks. You can enable or disable it for all domains at once, or configure protection separately for each site using cPanel's ModSecurity tool.
Open cPanel, go to Home then Security then ModSecurity. Click Enable to turn ModSecurity on for all domains, click Disable then Disable All to turn it off, or click Configure All Domains to show per‑domain On or Off toggles.
Before you start
- You must be logged in to the correct cPanel account that owns the domain.
- cPanel strongly recommend leaving ModSecurity enabled. Only disable it while you troubleshoot, because disabling removes all rule enforcement for that domain.
- If the ModSecurity page is missing in cPanel, we need to enable the feature and module on the server for you. open a support ticket.
Step 1: Open ModSecurity in cPanel
- Log in to cPanel for your hosting plan.
- Go to Home > Security > ModSecurity.
Step 2: Enable or disable ModSecurity for all domains
- To enable protection for every domain on this cPanel account: click Enable. Undo: if you change your mind, click Disable then confirm with Disable All.
- To disable protection for every domain on this cPanel account: click Disable, then confirm with Disable All. Undo: click Enable to turn it back on for all domains.
Step 3: Turn ModSecurity on or off for a single domain
- In ModSecurity, click Configure All Domains to reveal per‑domain controls.
- Find the domain and set it to Off to disable, or On to enable. Undo: return here and toggle it back the other way.
If it does not work
- You cannot find ModSecurity in cPanel. The feature may not be exposed to your cPanel account or the module is not installed. We need to enable the ModSecurity Domain Manager in WHM’s Feature Manager, ensure Apache’s
mod_security2is installed via EasyApache 4, and have at least one rule vendor enabled. open a support ticket. - No per‑domain On or Off toggles appear. Click Configure All Domains. If they still do not show, the ModSecurity Domain Manager feature or a rule vendor may not be enabled on the server. open a support ticket.
- Disabling ModSecurity did not fix the error. The block is likely from a specific ModSecurity rule. The safer fix is to disable or adjust that rule rather than turn off ModSecurity entirely. open a support ticket and tell us the exact error text and when it occurred.
What next
If you need deeper tuning, such as enabling the OWASP Core Rule Set vendor or disabling a single rule, that is done server side in WHM’s ModSecurity tools. Tell us what you observed and we will advise. If you run your own server with us, see our VPS guides. Planning a move to a VPS for full server control in the UK, see Linux VPS.
Common questions
Where is the ModSecurity icon in cPanel?
It is under Home, then Security, then ModSecurity. If you do not see it, the feature may be disabled for your cPanel account. open a support ticket and we will check the server configuration.
Why do I not see per‑domain On or Off toggles?
They only appear after you click Configure All Domains. If you still cannot see them, the ModSecurity Domain Manager feature or a rule vendor may not be enabled on the server. open a support ticket.
Is it safe to turn ModSecurity off?
cPanel strongly recommend keeping ModSecurity enabled and only turning it off while you troubleshoot. Disabling removes all web application firewall rule enforcement for that domain, which increases risk. If one rule is the problem, ask us to review and adjust that rule instead of disabling ModSecurity for the whole domain.
Was this article helpful?
0 people found this helpful