Protect customer accounts with automated Email OTP Two-Factor Authentication, trusted browser cookies, and IP whitelisting.
Many clients find authenticator apps cumbersome. Email OTP 2FA provides zero-friction login verification directly through the client's registered email inbox.
Estimate how many credential stuffing and unauthorized login attempts Email 2FA blocks across your WHMCS user base.
Protect your WHMCS portal logins without burdening clients with third-party authenticator setup.
Generates a secure 6-digit one-time passcode delivered to the client's email inbox on every unrecognized login attempt.
Clients can check "Remember this browser for 30 days" to bypass repeat OTP prompts on their primary personal devices.
Specify office or VPN IP subnets to automatically bypass 2FA checks for trusted corporate network environments.
Exempt specific VIP clients or staff accounts from mandatory 2FA requirements based on admin exclusion rules.
Allows pre-authorized IP ranges to completely bypass email verification prompts for seamless automated API & portal access.
Enforces Email 2FA for secondary contacts and sub-accounts to prevent delegated account misuse.
Compare standard WHMCS 2FA options against our Email Login Verification module.
| Security & UX Feature | Native WHMCS 2FA | Client Login Verification |
|---|---|---|
| Zero App Setup Required No need for clients to install TOTP authenticator apps. | Requires App Setup | Instant Email OTP |
| Remember Trusted Devices (30 Days) Bypass OTP on recognized user devices. | Every Login | Trusted Browser Cookie |
| Corporate IP Whitelist Bypass Skip 2FA for static office IP ranges. | No | Configurable Subnets |
| Sub-Account 2FA Support Enforce 2FA on secondary contact logins. | Primary Only | Yes (Full Coverage) |
Full compatibility specifications for WHMCS environments, PHP runtimes, and licensing terms.
Quick answers to common questions about email 2FA, device cookies, and installation.
No! Passcodes are delivered directly to the client's registered email address, making it zero-friction for non-technical users.
Yes, free installation support is included with your purchase. Our technical team is available to assist you via ticket.
Review our license terms, compatibility notes, and support policies.
There is No Refund Policy on module licenses — onetime or yearly. Modules are non-tangible, non-returnable goods. Refunds are not issued once the order is finalized and the product is activated.
If you face any issue with installation, open a support ticket, email us, or talk to us via live chat. We're here to help before and after purchase.
Modules are developed against the latest stable WHMCS version. LTS versions of WHMCS are not supported. Supports WHMCS 8.x & 9.x Ready with PHP 8.2 & PHP 8.3 Encoded encoded files.
Module purchase is restricted for websites using Nulled WHMCS. Nulled WHMCS users will be considered as Fraud. Sign up with a Valid Email ID from your Top Level Domain.
An Order Confirmation mail will be sent to your Email ID. Once the mail is verified the order will be processed. Otherwise the order will be deleted without notice.
If you face a "response can not be decoded" error, upgrade your cURL to 7.30 or above. If WHMCS shows a non-compatible encoded file warning, just ignore the message.