- Serve the terminal only over HTTPS, ideally with HSTS.
- An official branded domain helps clients spot fake terminals.
- Protect the domain itself: registrar lock and strong account security.
- Encourage two-factor authentication, which the MT5 web terminal supports.
1. Encrypt everything
- Serve the terminal over HTTPS only and redirect HTTP to HTTPS.
- Enable HSTS once HTTPS is stable.
- Use a minimum TLS version of 1.2.
Cloudflare issues and renews certificates automatically for domains it manages.
2. Use one official, branded domain
Fraudsters copy broker terminals on look-alike domains to steal credentials. A single, clearly branded address such as trade.yourbrand.com, linked from your website and emails, makes it easier for clients to recognise the genuine terminal. Tell clients which address is official.
3. Protect DNS and the registrar account
- Enable registrar lock and two-factor authentication on your registrar and Cloudflare accounts.
- Limit who can change DNS records.
- Consider CAA records to restrict which authorities may issue certificates.
4. Absorb attacks at the edge
Web terminals can be targeted during volatile markets. Serving the terminal through Cloudflare places network-level DDoS protection in front of it.
5. Protect client accounts
- Encourage two-factor authentication; MetaQuotes’ web terminal supports it.
- Limit which accounts can use each branded terminal with login range control.
- Never ask clients to share passwords by email or chat.
6. Monitor for clones
Periodically search for look-alike domains using your brand and report phishing sites to registrars and hosting providers.