Hosting account guide
Your hosting account is its own isolated Linux user on the server. Your files, your databases and your PHP processes run as you, and nothing you do can reach another account.
The panel groups every tool the way you use it. The menu on the left is the map:
Domains, Databases, Email and Files for the site itself, then
Security, Applications, Metrics, Advanced and Billing. If
you know the name of the tool, the search box at the top of the page finds it —
press / to jump there.
Your hosting plan decides which tools appear. If something described here is not in your panel, your provider has not included it in your plan. The tiles you do see are the ones you have.
Domains
- Domains — add an addon domain (a separate website), a subdomain, an alias / parked domain (a second name for the same site) or a redirect (301 permanent or 302 temporary). Each one gets its web configuration and DNS zone created for you.
- Document root — the button on each domain row. It chooses which folder
that domain publishes. This is how a Laravel or Symfony site keeps its
.envabove the web root: see Publish from a folder other than public_html. - DNS Zone — a full record editor: A, AAAA, CNAME, MX, TXT, NS, SRV and CAA, with TTLs. There are ready-made presets for Google Workspace, Microsoft 365 and Zoho Mail if your mail lives elsewhere. The same page holds DNSSEC (with the DS record to hand to your registrar) and Dynamic DNS tokens for an address that changes.
- Apache / .htaccess — whether your
.htaccessis translated or read directly. If a rule of yours is being ignored, this is the page: .htaccess — the two modes.
- Email Accounts — create mailboxes with their own storage limit, reset passwords, and read the IMAP/SMTP connection settings. Your username for mail is always the full email address.
- Forwarders and a catch-all for any address without a mailbox of its own.
- Autoresponders — a holiday reply per mailbox, with a start and end date.
- Filters — per-mailbox rules for sorting mail as it arrives.
- Spam Filtering — on or off, with how strict it should be. Tagged mail is moved to Junk, never deleted.
- Import many at once — paste a list of mailboxes or forwarders from a spreadsheet, preview what will be created, then create them.
- Webmail — read and send in the browser, signing in with the mailbox address and password. It appears only if the server has it installed.
The MX, SPF, DKIM and DMARC records for your domains are published for you when the first mailbox is created, so outgoing mail is authenticated without you setting anything up.
Databases
- Databases — create MySQL/MariaDB databases, export them (plain or gzipped), and import or restore a dump. Restores stream straight into the database with no file-size limit.
- Database users — create users, change their passwords, and give one user access to several databases: One database user for several databases.
- Remote MySQL — allow a specific outside address, network or hostname to connect to your database. Empty means local connections only, which is the safe default.
- phpMyAdmin — opens signed in already, scoped to your own databases. It appears only if the server has it installed.
- PostgreSQL — databases and users, if your plan includes it.
Files
- File Manager — upload, edit, rename, change permissions, compress and extract, copy and move. Deleted items go to Trash and can be restored.
- File Access (SFTP/FTP) — one login for your account, locked to your own files. SFTP is encrypted and the one to use; FTP / FTPS is there for older clients that need it. Both use the same username and password. There are one-click downloads for a FileZilla profile and a WinSCP link.
- SSH Keys — add a public key for password-less SFTP. Keys apply once SFTP is switched on.
- Backups — take a full backup on demand, download it, or restore. Restore
can be selective: website files, databases, email, scheduled tasks and DNS
zones are separate checkboxes, so you can put one database back without
touching the site. A restore asks you to type
RESTOREto confirm, because it overwrites what is there now.
The panel has a Terminal that opens a shell in the browser as your own account — never as root (your host can turn it off per plan). The SSH keys above are for file transfer over SFTP, not for shell access.
Security
- HTTPS / SSL — a free Let's Encrypt certificate for each domain, issued automatically once the domain points at the server, and renewed before it expires. The card shows the expiry date. You can also upload your own certificate with its private key and chain.
- Two-factor auth — an authenticator app plus backup codes, for your panel login.
- Directory Privacy — put a username and password in front of a folder.
- IP Blocker — a deny list of addresses or ranges for your sites.
- Hotlink Protection — stop other sites embedding your images and files.
- Virus Scan — scan your files on demand. It reports what it finds and deletes nothing.
Applications
- App Installer — install WordPress and other applications in one step, each with its own isolated database.
- App Servers (Node/Python/Ruby) — run a Node.js, Python or Ruby application on a domain of yours. Choose the runtime and version, the app root and the startup file; then start, stop, restart or install dependencies from the same page.
- Perl Modules — install modules into your own
~/perl5.
Metrics
- Visitor Statistics — visits, pages, referrers, browsers and status codes.
- Logs — your raw access and error logs, most recent first.
Advanced
- Cron Jobs — schedule commands with a standard cron expression.
- PHP Version — choose the version for your sites.
- PHP Settings — edit the
php.inidirectives your plan allows. This is where PHP values belong; settings written into.htaccessare not applied unless the site is in full.htaccessmode. - PHP Extensions — switch optional extensions on and off.
- Error Pages — your own HTML for 404, 403 and the rest, with a live preview.
Billing
Your plan, your subscription and your invoices, read-only.
Usage
The dashboard shows disk and bandwidth against your plan's limits, plus the number of databases, mailboxes and visitors in the last seven days. Disk limits are enforced by the server, so it is worth watching the bar rather than discovering the ceiling.
If your tools are missing
If the panel says the account is not active yet, its tools are hidden until your provider activates it. Nothing is lost — the account and its files are there.
Related: .htaccess — the two modes · Publish from a folder other than public_html · One database user for several databases