root is the account that can do anything on the server. Change its password regularly, and immediately if you think someone else has it.
If you can still sign in: use SSH
passwdType the new password twice. It takes effect at once, without a restart.
If you can't sign in: use the management panel
- Open the server's management panel — see Access your VPS or dedicated server.
- Open the options menu (top right) and choose Reset root password.
- Enter the new password and save.
If you run cPanel: use WHM
Sign in to WHM as root, then Server Configuration → Change Root Password.
Choosing the password
- 8 to 50 characters, with at least one uppercase letter, one lowercase letter, one number and one symbol.
- Never reuse a password from another system.
- Store it in a password manager, not in a text file on your desktop.
Important
Anyone with the root password owns the server: its data, its mail, its customers. If it has ever been shared — with a developer, an agency, in a ticket to another supplier — change it.