1. Separate verified controls from broad security claims
GreatHosts documents what the customer can actually see and use. The live CP exposes ModSecurity, IP Blocking, Password Protection, Hotlink Protection, DNSSEC and Cloudflare controls. That is different from making vague claims about every layer of infrastructure security.
- Use the controls that match the application threat model.
- Do not treat one control as a replacement for secure application code.
- GreatHosts deliberately does not infer unsupported DDoS, malware-scanning or physical-security claims from these menu items.
2. ModSecurity web application firewall
GreatHosts CP labels ModSecurity as a Web Application Firewall. It can help block classes of malicious HTTP requests before they reach the application.
- Keep it enabled unless a verified application conflict requires a targeted exception.
- When a legitimate request is blocked, capture the rule/event information before changing configuration.
- Do not disable broad protection merely to make one request pass.
3. IP blocking and password protection
IP Blocking can deny selected addresses or ranges, while Password Protection can restrict access to a page or an entire site. These are useful controls for staging, private tools and abusive-source containment.
- Use password protection for non-public staging areas.
- Use IP blocking for clearly identified abusive or administrative restrictions.
- Avoid permanent broad IP blocks that accidentally exclude legitimate customers or crawlers.
4. Hotlink protection
Hotlink Protection is intended to reduce third-party embedding of your hosted images or other assets where that traffic is not wanted.
- Enable it only when external embedding is actually undesirable.
- Allow legitimate CDN or partner origins when required.
- Verify social previews and integrations after changing rules.
5. DNSSEC and Cloudflare controls
The current Web Tools menu exposes DNSSEC and Cloudflare management. DNSSEC protects DNS authenticity when the full delegation chain is configured correctly; Cloudflare integration can be used when that service is part of the customer architecture.
- Enable DNSSEC only when registrar and authoritative DNS settings can be coordinated correctly.
- Do not change nameservers or signing records without a rollback plan.
- Cloudflare is an external service; its own account, terms and configuration remain separate from GreatHosts hosting.
6. SSL/TLS and certificate workflow
Certificate management belongs with the domain and HTTPS workflow. GreatHosts supports SSL/TLS and the CP exposes certificate and CSR controls.
- Use HTTPS for public logins, forms and normal production websites.
- CSR generation is available when a certificate workflow requires it.
- Confirm renewal and certificate term details in the current domain/SSL order path.
7. Secure configuration still matters
Control-panel security features do not correct weak passwords, exposed secrets, vulnerable application code or outdated software. Keep the application itself maintained and minimize unnecessary access.
- Use unique credentials and protect administrative accounts.
- Keep application frameworks, CMS software and plugins current.
- Back up before risky changes and verify restoration capability.
Common questions
Does GreatHosts claim DDoS protection from these controls?
No. The factual baseline intentionally avoids unsupported DDoS, malware-scanning, physical-security and shared-account-isolation claims unless separately documented.
Should I disable ModSecurity if it blocks my application?
Prefer a targeted diagnosis or rule exception. Broadly disabling protection to solve one conflict is usually the wrong first response.
Is Cloudflare included with hosting?
The live CP exposes Cloudflare management, but Cloudflare remains an external service with its own account and configuration. Check the current service terms before assuming any paid Cloudflare feature is included.