Hosting Pages
Each sidebar section below is scoped to your account only — you cannot see or affect other tenants.
Your hosting administrator can switch a feature off for client accounts (client_features in the server configuration). A feature that is off is not listed in the sidebar or among the dashboard tiles, and its routes answer 409 FEATURE_DISABLED if the page is opened by address.
Domains
Add a subdomain (blog.example.com), parked domain (alias of an existing domain pointing at the same files), or addon domain (independent domain serving a separate folder).
- Subdomain limit: plan-defined, typically up to ~50
- Primary domain document root:
/home/{user}/public_html/ - Addon domain document root:
/home/{user}/{addon}/by default (for example/home/{user}/shop.example.com/); the add dialog's Custom document root option picks another folder inside your home directory (a name that is a link to a folder outside it is refused) - Deleting a subdomain: its DNS record and vhost are removed; the subdomain's own folder directly under your home directory is renamed
<folder>-removed-<timestamp>instead of being deleted (a folder inside another site's tree, or one another domain also serves, is left as it is). Remove the renamed folder from the file manager when you no longer need its files. - Parked vs Addon: a parked domain is just an alias — it serves the same files as the primary. An addon domain has its own separate folder and acts like a fully separate site. A new addon domain runs your account's PHP version; a parked domain runs the version of the domain it points at.
DNS: the panel adds a domain without checking where its DNS points. The site answers visitors, and a Let's Encrypt certificate can be issued for it, only once the domain's A record points to the server's IP address (Server IP on the dashboard).
Names already in use: a hostname another account on the server already serves is refused with DOMAIN_EXISTS, whether that account holds it as its primary, addon, parked or subdomain name. The refusal says the name is in use by another account without naming it; only the operator sees which account holds it. The server's own hostname is reserved and cannot be added to any account.
Redirect targets: a destination must be an absolute http:// or https:// URL. Characters the webserver's rewrite grammar reads as markup — $, {, }, ;, quotes, backticks, angle brackets and whitespace — are refused with a validation error.
Custom web server directives: your panel has no Custom config button — your hosting administrator can add Nginx or Apache directives to your primary domain for you. (Per-domain PHP settings such as memory_limit or upload_max_filesize are changed on the PHP page.)
- For Nginx, the snippet is placed inside the
server { ... }block. - For Apache, the snippet is placed inside the
<VirtualHost>block. - Validation runs
nginx -t/apachectl configtestbefore saving. Invalid config is rejected, the previous working config is restored, and the live site is never served from the rejected version. - Saving custom config keeps the domain's redirects, its PHP version and its SSL listener as they were.
Databases
Create a MariaDB database. Names are auto-prefixed with your account username ({user}_{db}) so collisions across tenants are impossible.
- Connection details:
- Host:
localhost(from your sites and scripts on this server); another machine can connect only when your hosting administrator has opened the database server to the network and that machine is added under Remote Access - Port:
3306 - User:
{user}_{dbuser}(also auto-prefixed) - Password: set when you create the user; can be reset later
- Host:
- Character set:
utf8mb4with collationutf8mb4_unicode_ciby default (full Unicode including emoji) - Database size: not limited by the panel and not counted in your disk quota (the disk figure covers your home directory only); your plan limits the number of databases
- Database users: each database lists the users granted on it, with their privileges. Deleting a database also removes the users that were granted only on it.
- Remote access: adding a remote host copies your local database users to that host. The database server accepts connections from the server itself unless your hosting administrator has opened it to the network — the panel tells you when that is the case.
- phpMyAdmin: the phpMyAdmin icon on a database's row, or the dashboard's phpMyAdmin shortcuts, open an SSO session — you never type the database root password
- Importing an SQL dump: the panel has no import of its own — use phpMyAdmin's Import tab, which shows the largest file it accepts; for a larger dump, contact your hosting administrator
Privileges available when adding a DB user, each limited to that database: ALL PRIVILEGES (selected by default) or any of SELECT, INSERT, UPDATE, DELETE, CREATE, DROP, ALTER, INDEX, REFERENCES, CREATE TEMPORARY TABLES, LOCK TABLES, EXECUTE, CREATE VIEW, SHOW VIEW, CREATE ROUTINE, ALTER ROUTINE, EVENT, TRIGGER. Privileges intentionally not offered: SUPER, FILE, GRANT, CREATE USER (these are server-wide).
Create mailboxes ([email protected]), set their storage limits, activate or deactivate a mailbox, change its password and configure forwarders. A deactivated mailbox neither logs in nor receives mail, and its forwarders pause with it. A forwarder always starts at one of your existing mailboxes. A mailbox's storage limit is between 1 MB and your plan's disk, and the limits of all your mailboxes together cannot exceed the plan's disk — the dialog shows how much is still free; a limit outside that range is refused (a mailbox without a limit can only be set up by your provider, and it keeps that setting until you give it a limit). The quota is enforced by the mail server: over the limit, incoming mail is refused until space is freed.
Mailbox storage: Maildir format, kept by the mail server outside your home directory.
Connection settings to give to mail clients (Outlook, Thunderbird, Apple Mail, Mailspring, K-9):
| Protocol | Host | Port | Encryption |
|---|---|---|---|
| IMAP (recommended for receiving) | mail.your-domain.com |
993 |
SSL/TLS |
| SMTP (sending) | mail.your-domain.com |
587 |
STARTTLS |
| SMTP (alternative) | mail.your-domain.com |
465 |
SSL |
| POP3 (legacy) | mail.your-domain.com |
995 |
SSL/TLS |
If mail.your-domain.com does not resolve, ask your hosting administrator for the correct mail server hostname (often the server hostname itself).
Webmail:
- URL:
https://your-server.example.com/webmail/ - Engine: Roundcube
- The Webmail button next to each mailbox on the Email page signs you in (no extra password); the dashboard's Webmail shortcut opens your first mailbox
- Deleting a mailbox also deletes its webmail address book, identities and settings
DKIM: while your account's mail DNS is on, the panel generates a DKIM key for your domain, registers it with the signer, signs your outgoing mail with it and publishes the record in your DNS zone. If your DNS is hosted elsewhere, publish the public part there as a TXT record so receivers can verify the signature:
default._domainkey.your-domain.com TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."
Hourly send limit: your plan sets how many messages your account may send per hour. The allowance belongs to the account as a whole, so it is shared by every mailbox and every domain and subdomain on it. Over the limit, the server turns further messages away with a temporary error (4xx) at the moment they are sent — they are not queued on the server, so your mail program or script has to send them again later; the count starts again at the top of each hour (UTC). Scripts on the server that send through SMTP on 127.0.0.1 must authenticate as one of your mailboxes when they send as an address of your domain; an unauthenticated submission that claims a hosted address is refused. PHP mail() (the sendmail path) is not affected.
SPF (declares who may send mail for your domain) — while your account's mail DNS is on, the server writes this record into your DNS zone itself:
your-domain.com TXT "v=spf1 a mx ip4:<server IP> ~all"
DMARC (tells receivers what to do with failures) — written the same way, with the policy your hosting administrator chose (p=none unless they changed it):
_dmarc.your-domain.com TXT "v=DMARC1; p=none; rua=mailto:[email protected]"
A domain may carry only one SPF record and one DMARC record — with a second SPF record, receivers treat SPF as broken (permerror). Do not add these records again: to change one (for example to allow another sending service), edit the existing record on the DNS page. If the DNS page shows no SPF or DMARC record (your hosting administrator can switch the automatic records off), add a single one. If your DNS is hosted elsewhere, copy the records from the DNS page to that provider.
Forwarders: redirect all mail for one address to another, locally or externally.
Autoresponders and server-side filters: not offered by the panel or by webmail (webmail has no Filters screen); use your mail client's rules for vacation replies and sorting.
Spam Filter page (Email → Spam Filter): whitelist senders, blacklist senders, switch filtering on or off per mailbox. An entry is a sender address ([email protected]) or a domain (example.com, which also covers its subdomains); up to 100 entries per list, other text is refused. The lists are applied by the mail filter when the message is addressed to your mailbox alone, or when the lists of every recipient of the message agree: a blacklisted sender's message is refused at delivery (the sender gets a bounce), a whitelisted sender's message is delivered without spam scoring, and a mailbox with filtering switched off receives its mail without scoring — unless the server-wide blacklist your provider keeps names the sender, which is refused in every case. Deleting a mailbox removes its lists. If a mailbox's lists cannot be read, its settings dialog shows an error state with a Retry button and Save stays off, so the stored lists are never replaced with empty ones.
FTP
Create FTP users, lock each user to a subdirectory under your home (chroot), reset passwords.
- Server: not shown on the FTP page — use the server hostname your hosting administrator gave you (typically
your-server.example.com) or the Server IP on the dashboard's Account Information card - Port:
21with explicit TLS (FTPS — in FileZilla "Require explicit FTP over TLS"). The server refuses cleartext logins, and there is no implicit FTPS on port990. - Certificate: unless your hosting administrator has installed a certificate of their own, the server's FTPS certificate is self-signed, so your FTP client shows a certificate warning on the first connection — accepting (trusting) it is expected.
- Username format:
{user}_{name}— your account username is put in front of the name you type (the create dialog previews the full name). The FTP user created with your account is{user}_{user}and opens your home directory. - Passive mode ports:
30000–30100by default (your hosting administrator can change them). Most clients negotiate this automatically. - Chroot path:
/home/{user}/{ftpuser_dir}/— the user cannot navigate above this directory
Recommended FTP clients:
- FileZilla — free, cross-platform (Windows / macOS / Linux). Beginner-friendly.
- WinSCP — free, Windows only. Powerful synchronisation features.
- Cyberduck — free, macOS / Windows. Clean UI.
SFTP note: SSH access is off for hosting accounts unless your administrator turns it on for yours, and without it SFTP (SSH-based) is not available. Use FTPS (FTP over TLS on port 21) — it provides the same encryption protections.
DNS
Manage your DNS zone — A, AAAA, CNAME, MX, TXT, NS, SRV, CAA records. Backed by PowerDNS with DNSSEC available.
- Default TTL:
3600(1 hour). Lower it (e.g.300) before planned changes to speed up propagation; raise it back after. - SOA record: the zone's SOA is managed by the server — the row is read-only in the table and the API refuses to edit or delete it (
409 DNS_RECORD_PROTECTED). The zone's last NS record cannot be deleted either (add another NS record first); editing it is allowed. - Record ids: a record's id is derived from its name, type and content, so it stays the same between reads; deleting a neighbouring record does not renumber the others.
Record examples:
your-domain.com A 1.2.3.4
your-domain.com AAAA 2001:db8::1
www A 1.2.3.4
@ MX 10 mail.your-domain.com.
@ TXT "v=spf1 a mx ip4:1.2.3.4 ~all"
@ CAA 0 issue "letsencrypt.org"
_sip._tcp SRV 10 60 5060 sip.your-domain.com.
The first A record, the www A record, the MX record and the SPF line have the form the server itself writes into your zone (MX and SPF while your account's mail DNS is on — see SPF under Email). To change one of them, edit the existing record rather than adding a second record with the same name: a domain carries only one SPF record, and a CNAME cannot share its name with any other record, so www cannot become a CNAME while its A record is there.
After creating a zone, the panel shows the NS values to set with your domain registrar (typically ns1.your-server, ns2.your-server — confirm with your hosting administrator).
Bulk operations: the panel has no zone file import or export; records are added and edited one at a time.
Propagation: typically 5–15 minutes locally, up to 24–48 hours globally. Use online tools like dig or whatsmydns.net to check.
SSL
Issue Let's Encrypt certificates per domain, upload custom certificates, view expiry dates.
- Let's Encrypt validation: HTTP-01 is used (the server places a file in its own challenge folder, which every site serves at
/.well-known/acme-challenge/, and Let's Encrypt fetches it; nothing is written into your site folders, and a.well-knownfolder of your own there is not used for it). - Auto-renewal: certbot renews every certificate with 30 days or less left — twice a day through its system timer on Debian and Ubuntu servers, daily at 03:00 server time on the RHEL family. A renewal sends you no notification; a certificate that is not renewed brings expiry warnings at 14, 7, 3 and 1 days left.
- Expiry warning: when a certificate one of your sites serves has 14, 7, 3 or 1 days left (a renewal that keeps failing, or an uploaded certificate), you get an SSL Expiry Warning at each of those steps, once per step.
- Wildcard certificates (
*.your-domain.com): not issued by the panel — a Let's Encrypt certificate covers the name and itswww.form (your-domain.comandwww.your-domain.com). A wildcard certificate obtained elsewhere can be installed with the custom certificate upload. - Custom certificate upload: paste the PEM certificate chain and the private key. The format must be plain text PEM (begins with
-----BEGIN CERTIFICATE-----). The domain picker of the install dialog offers every name the account serves: the primary domain, addon domains and subdomains. - HSTS: not a switch — once a site has a certificate, its HTTPS responses carry
Strict-Transport-Security: max-age=31536000; includeSubDomains(on Nginx and Apache servers), which tells browsers to always use HTTPS for your domain and all its subdomains (so your subdomains need certificates too). - HTTP → HTTPS: not a switch either. Where Nginx serves your sites (Web Server on the dashboard shows Nginx or Nginx + Apache — the default setup), a site with a certificate answers every
http://...request with a 301 redirect tohttps://...; other setups do not redirect by themselves. A request that arrives through a proxy or CDN sending anX-Forwarded-Protoheader (Cloudflare does) is not redirected — turn the redirect on at the proxy instead. - HTTPS as PHP sees it (Nginx + Apache): Nginx ends the HTTPS connection and passes the request on to Apache. PHP reads
$_SERVER['HTTPS']asonfor those requests, whileREQUEST_SCHEMEandSERVER_PORTdescribe that inner step (http,80) — testHTTPSwhen your code needs the visitor's scheme.
PHP
Each of your domains (primary, addon, subdomain) has its own row with a PHP version selector, limited to the versions installed on the server. The row's PHP Configuration action edits that domain's php.ini values (such as memory_limit or upload_max_filesize): only the values that differ from your account's defaults are written, into a .user.ini file in the domain's document root. A domain with its own values is marked Custom, and Reset to Defaults removes the file.
- Available versions: depends on your server. Typical:
5.6(legacy),7.4,8.0,8.1,8.2,8.3,8.4 - Default version: newest stable, usually
8.4 - Common
php.inisettings:memory_limit = 256Mupload_max_filesize = 64Mpost_max_size = 64Mmax_execution_time = 300display_errors = Off(production — neverOn)error_log = /home/{user}/logs/php-error.log
- PHP error log:
/home/{user}/logs/php-error.log - When changes apply: changing a domain's PHP version reloads the PHP-FPM service of the old and the new version. Saving
php.inivalues needs no reload — PHP reads the domain's.user.iniitself, and a change can take up to 5 minutes to show (PHP's defaultuser_ini.cache_ttl).
Files
Browse your account's home directory. Upload, download, edit (Monaco editor), chmod, rename, copy, move, archive (.tar.gz or .zip), extract.
- Account home:
/home/{user}/ - Web root:
/home/{user}/public_html/ - Logs directory:
/home/{user}/logs/— written by the server and readable by you; the directory itself is not writable, so log files cannot be added, renamed or removed from it - Upload limit: 256 MB per file via the panel UI (five uploads per minute); for larger files use FTP/FTPS
- chmod recommendations:
- Files:
644(rw-r--r--) - Directories:
755(rwxr-xr-x) - Sensitive (config, credentials):
600(rw-------) - Scripts: PHP runs through PHP-FPM as your account user, so PHP files need no execute bit (
644); the server sets up no CGI handling for your sites
- Files:
- Hidden files: shown by default (files beginning with
.like.htaccess,.env); the toolbar's Hide hidden files button hides them - Monaco editor support: syntax highlight for PHP, HTML, CSS, JS, JSON, YAML, Markdown, Python, shell, SQL — same engine as Visual Studio Code
- Archive formats on create:
.tar.gz,.zip - Archive formats on extract:
.tar.gz,.tar.bz2,.tar.xz,.tar,.zip - Extraction limits: every entry must stay inside the destination folder (entries with
..or absolute paths, links pointing outside it, device and fifo entries are refused with422 VALIDATION_ERROR); at most 100,000 entries, 512 MiB per file and 2 GiB in total, and a zip entry may not expand more than 200x. setuid/setgid bits are dropped. - Batch operations: deleting, copying or moving several items is reported per item. When some items are refused (for example a link that points outside your home directory), the panel shows how many succeeded and lists the failures instead of reporting a clean success.
Path traversal is blocked at the API layer — every path resolves through os.path.realpath and is verified to be inside /home/{your_user}/.
Backups
Create an on-demand backup of your files, databases and mailboxes (any combination), or schedule a recurring one. A backup can also be copied to one of your remote destinations (FTP / SFTP / Google Drive / Bunny Storage / Yandex Disk / OneDrive — managed on the Remote Storage tab).
- Storage on the server:
/var/whost/backups/{user}/— a.tar.gzarchive named{user}_YYYYMMDD_HHMMSS_{id}.tar.gz(scheduled ones carry asched_prefix) - Contents: your home directory's files (setuid and setgid bits are not kept: a file or folder that carries one is backed up without it; the PHP session files in your
tmpfolder are left out — the server removes them a day after their last use), one SQL dump per database, and your mailboxes (addresses, password hashes, quotas and the mail itself) - Retention: the operator's retention window applies to every backup (default 7 days); a schedule additionally keeps only its own last N runs (its retention count); it never removes another schedule's backups
- Remote copy failed: the backup stays on the server and the row's badge names the reason — also when the server stopped before the copy finished ("The remote copy did not finish: the agent stopped during the upload.")
- FTP / SFTP destinations: the server is checked before your password is sent. An FTP server's certificate must be valid for the host you entered; for a server with a self-signed certificate or one issued for another name, either enter the certificate's name as the host or turn on Accept an unverified certificate — the certificate of the first successful connection is then remembered and a different one is refused. An SFTP destination remembers the server's host key at its first successful connection and refuses a different key. If your backup server's key or certificate was replaced, edit the destination, tick Forget it on save and save; the next successful connection remembers the new one. An FTP destination that has connected over TLS once does not drop to plain FTP later: if its server then refuses TLS, tests and copies fail until you remove the destination and add it again
- Server update in progress: while the server installs a WHost update, starting a backup or a restore is refused with a message saying so — try again a few minutes later; a scheduled backup that falls due during the update runs right after it
- Large accounts: each step of a backup (the copy of your files, each database, each mailbox, the archive) runs as long as it keeps working; a step that does nothing for 10 minutes is stopped and the backup fails naming it, and no step runs longer than 6 hours
- No answer at all: a backup runs inside the request that starts it, so a large account can keep the request open for many minutes. When nothing comes back (a gateway timeout, a dropped connection) the panel says the backup may still be running and asks you to refresh the list and check your notifications — starting it again would make a second copy. A restore answers the same way. A refusal the server names keeps its own message
Schedules: daily, weekly (pick the weekday — the list starts on Sunday) or monthly (pick the day, 1–28), at the given time (the server's local clock; the Last Run and Next Run columns show the stamps in your own time zone), with a retention count and the contents to include. The operator caps the number of schedules per account; when the cap is reached the panel shows the server's refusal.
Restore: the row's Restore action asks for a confirmation and then puts back your sites, databases and mailboxes from the backup — there is no selective restore. Files go back into public_html, tmp, ssl, mail and the folders of your addon domains and subdomains (other folders of your home, log files and hidden files are not touched); each database in the backup is dropped and re-created from its dump and its users keep exactly the grants they had — the dump is imported by your account's own import user, which can write to your databases only, so a dump that names another database makes the restore fail, and views, triggers and routines come back under that user; mailboxes are re-created with their mail. The row shows Restoring until the server answers and its actions are locked meanwhile.
Download: the row's Download action opens the archive in a new tab; the download is resumable (the browser can pause and continue).
Cron Jobs
Add cron entries with full minute / hour / day / month / weekday syntax.
Cron syntax cheatsheet:
| Expression | Meaning |
|---|---|
* * * * * |
Every minute |
*/5 * * * * |
Every 5 minutes |
0 * * * * |
Every hour, at minute 0 |
0 3 * * * |
Every day at 03:00 |
0 3 * * 0 |
Every Sunday at 03:00 |
0 0 1 * * |
First day of every month, at midnight |
30 2 * * 1-5 |
Weekdays at 02:30 |
Command context:
- Runs as your account user (not root), with
/bin/shas the interpreter $HOME = /home/{user}$PATHis the standard non-interactive path; use absolute paths for commands you are unsure about (/usr/bin/php,/usr/local/bin/composer)- Run Now executes the command at once with the same interpreter and a login environment, and stops it after 85 seconds (the agent’s own limit is 90); the scheduled runs are not affected. The Last Manual Run column shows when the job was last started with Run Now; scheduled runs are not recorded there.
Output handling: whatever a job prints is delivered to your account's local mailbox on the server, which the panel does not show — redirect the output in the command (the logs/ directory is written by the server and is not writable by your jobs):
# Silent — discard all output
/usr/bin/php /home/{user}/public_html/cron.php > /dev/null 2>&1
# Append to a log file
/usr/bin/php /home/{user}/public_html/cron.php >> /home/{user}/cron.log 2>&1
What the panel checks: each schedule field must be a number, a range, a step or a list (*, 5, 1-5, */10, 1,15); named months and days (JAN, MON) and shortcuts such as @daily are not accepted. The command may not contain line breaks. The panel does not judge what the command does — it runs with your own account's permissions. Lines you add to the crontab by other means (MAILTO=, @reboot, entries without the panel's marker) are kept but not listed.
Logs
Per-domain access and error logs.
/home/{user}/logs/{domain}-access.log/home/{user}/logs/{domain}-error.log/home/{user}/logs/{domain}-apache-access.log/home/{user}/logs/php-error.log/home/{user}/cron.log (jobs cannot write under logs/); open it from the File Manager, the Logs page does not show it- Rotation: daily by
logrotate, with 14 days of retention - Format: Nginx combined log format (IP, timestamp, request, status, byte size, referer, user-agent)
- Real-time tail: the Logs page streams the latest lines live (SSE —
tail -fequivalent) so you can watch as a deploy or a request comes in - Scope: only the domains your account holds can be read; another account's domain answers
403 DOMAIN_NOT_OWNED
Our support team is here around the clock for anything you can't find above.