Use scoped login keys and catch-all email carefully

Safer automation credentials and sensible mail-delivery defaults.

DirectAdmin login keys

  1. Enable Two-Step Authentication for your interactive login. Keep recovery codes secure.
  2. Open Login Keys under your account/profile settings. Create a separate key for each automation or integration.
  3. Select only the commands the integration requires. Set an expiry and restrict the allowed source IP when practical. Avoid an unrestricted key unless the integration genuinely requires it.
  4. Store the key in a private configuration file or secret manager, never in website files, Git, chat, or screenshots.
  5. Test the required operation, record the expiry, and revoke the key when no longer needed. Deleting a key stops integrations using it.

Catch-all email

A catch-all accepts mail sent to addresses that do not otherwise exist at your domain. In Email Manager → Catch-All E-mail, choose the behavior you need. We recommend rejecting unknown recipients unless you have a clear use for a catch-all: accepting everything can attract spam and consume shared storage.

Enabling catch-all permission does not activate a catch-all mailbox automatically. Mailbox and sending limits still apply. For normal use, create explicit mailboxes or forwarders instead.