DocsGuide for hosting customers

Guide for hosting customers

Everything a hosting customer does in the panel: sign in, secure the account, create websites and WordPress, email, databases, files, SSL, backups, apps and limits.

This guide is for you if a hosting provider gave you an account on a ZoPanel server. It walks through the panel as you see it as a customer, in the order you usually need it, and links to the detailed page for each topic. Your provider decides what your package includes, so a menu item described here may be missing from your panel; in that case it is not part of your plan.

Sign in

Your provider sends you the panel address, your username and your password, often in a welcome email. The address usually ends in :8888, for example https://panel.example.com:8888.

  1. Open the panel address in your browser.
  2. Enter your Username and Password and click Sign in. You can switch the language between English and Vietnamese at the top of the page.
  3. If you turned on two-factor authentication, enter the 6-digit code from your app and click Verify.

There is no "forgot password" link on the sign-in page: if you lose your password, ask your provider to set a new one. After several wrong attempts the panel answers too many failed attempts, try again later; wait 15 minutes. If your account is suspended, the panel says account suspended with the reason; contact your provider.

The dashboard and the menu

Dashboard greets you and shows:

  • Getting started: four steps (add your website, point your domain and get SSL, create an email address, make your first backup). Close it once done.
  • Counters for websites, databases, Disk used and SSL expiring soon.
  • Your websites with their status (up, down, suspended) and whether SSL is on.
  • Package: {name}: how much of your websites, databases, disk, mailboxes and apps you use.
  • Backups: your last backup, with Back up now and Restore.
  • Recent tasks: installs, backups and other jobs. The Tasks button at the top shows all of them.

The menu groups your pages:

Group Pages
Hosting Websites, Databases, Email, DNS, File Manager, FTP / SFTP, Cron Jobs, Terminal (if your package includes it), Backups
Apps & tools App Store, S3 storage, Malware scan (each only when available)
Account Resources, Activity Log, My account, Contact support (when your provider set a support link)

Secure your account

Do this first, in My account:

  1. Change password: enter the Current password, a New password (at least 8 characters) and Confirm new password, then click Update password. Your other sessions are signed out. This changes the panel password only: the SFTP password stays the one your account was created with; ask your provider to change it.
  2. Two-factor authentication: enter your Current password, click Enable 2FA, scan the QR code with an authenticator app, enter the code and click Verify & enable. Save the Recovery codes somewhere safe. If you lose your phone, a recovery code signs you in, and another one lets you turn 2FA off and set it up on the new phone (see Two-factor authentication).
  3. Profile: keep your Email up to date; notifications go there.
  4. Notifications: choose the events you want by email or Telegram, such as a website going down, an SSL certificate that cannot be renewed, a failed backup or disk space almost full.
  5. Sessions: see the browsers signed in to your account and Sign out everywhere else if you see one you do not recognise.

If your provider requires two-factor authentication, the panel opens My account after sign-in and you must set it up before you can continue. Details: Two-factor authentication and account security.

Create a website

  1. Point your domain to the server first: at your DNS provider, create an A record for example.com and www with the server IP your provider gave you. SSL is issued only once the domain points to the server.
  2. Go to Websites and click New website.
  3. Enter the Domain without http://. Keep Also serve www.example.com ticked if you want both names.
  4. Choose the Website type: WordPress, PHP, Laravel, HTML, Node / Proxy or Git deploy.
  5. Choose the PHP version and keep Free SSL (Let's Encrypt) on.
  6. Click Create website.

Your files live in /home/<username>/domains/example.com/public_html. Open a website to manage it on its tabs: Overview, Deploy, WordPress, Domains, Tools, PHP & config, SSL, Analytics, Logs and Members. Full walkthrough: Your first website.

Install WordPress and open wp-admin

  • New website: choose the WordPress type and fill in WordPress settings: Site title, Admin email, Admin username and Admin password. Avoid admin as the username.
  • Existing PHP website: on its Overview tab, under Applications, click Install WordPress.

WordPress needs one free database in your package. When the install task finishes:

  • Click WP Admin at the top of the website page, or go to https://example.com/wp-admin, and sign in with the admin username and password you chose.
  • Or open the WordPress tab and click Log in to WordPress: it opens wp-admin directly with a one-time link, no password needed.

The WordPress tab also runs safe updates with automatic rollback, security hardening and staging copies. See WordPress Toolkit and Install WordPress.

Email

  1. Go to Email and click Enable email for a domain. Choose one of your websites' domains.
  2. Add the records listed under DNS records at your DNS provider so mail is delivered and not marked as spam.
  3. Click New mailbox, enter the address, a password and the Quota (MB).

To read mail:

  • In the browser: click the envelope icon Open webmail (no password needed) next to a mailbox, or open Webmail at the top of the page and sign in with the full email address and its password.
  • In an app (Outlook, Thunderbird, phone): use the settings shown under Email client settings. The username is the full email address. On iPhone and Mac, iPhone / Mac profile (sets up this mailbox) configures it for you.

You can also add Forwarders, autoreplies and filters. If the page says Ask your administrator to enable email on this server., the mail server is not installed yet. See Email, Email clients and Mail rules and limits.

Databases

  1. Go to Databases and click New database.
  2. Enter the Database name (lowercase letters, digits and underscore) and optionally Link to website.
  3. Copy the details shown in Database credentials. The password is not shown again; Reset password makes a new one.

Use 127.0.0.1 as the host in your application; the menu item Connection info shows the host, port, name and user again. From a database's menu you can also open its Backups (scheduled backups and one-click restore), Export (backup) it, or Import / restore a .sql or .sql.gz dump. When your provider has installed Adminer, each MariaDB and PostgreSQL database has an Adminer link to browse its tables in the browser. See Databases.

Files, FTP and SFTP

  • File Manager works in the browser: open domains/example.com/public_html, drag files in or click Upload. Upload a .zip and click Extract to put a whole site in place. See File Manager.
  • SFTP (when your package includes it): connect with FileZilla, WinSCP or Cyberduck to the server on the SSH port (usually 22) with your username and SFTP password. You are kept inside your home folder. Add an SSH key under My account → SFTP & SSH keys to sign in without a password.
  • FTP accounts: on FTP / SFTP, New FTP account creates an extra login limited to one folder, for example for a designer. FTP uses explicit TLS on port 21.

See FTP and SFTP.

SSL certificates

With Free SSL (Let's Encrypt) on and the domain pointing to the server, the certificate is issued when the website is created and renews automatically. If DNS was not ready, ZoPanel retries every hour. To do it now, open the website's SSL tab and click Issue certificate, then turn on Redirect HTTP to HTTPS. See SSL certificates.

Backups and restore

On Backups:

  • Create backup → Start backup archives all your websites and databases, and your email domains, into ~/backups. Use Download to keep a copy on your computer.
  • Restore puts a backup back: files and databases are overwritten with its contents.
  • Upload a backup restores a .tar.gz account backup downloaded from this or another ZoPanel server.
  • Automatic backups runs daily or weekly at the hour you choose, keeps the number of copies you set, and can copy each backup to your own S3-compatible storage (Amazon S3, Cloudflare R2, Backblaze B2, Wasabi…).
  • Snapshots (incremental), when your provider runs them, let you browse a past day and restore a single file or folder.

Each database also has its own backups and one-click restore. See Backups.

App Store

If your package includes applications and the server runs Docker, App Store lists one-click apps such as n8n, Uptime Kuma, Nextcloud and Gitea. The page shows how many your plan allows: Your plan: {used} of {limit} applications. Pick an app, choose the domain, and click Install; the app runs behind that domain with SSL. If the page says Applications are not included in your plan, ask your provider. See What each app does.

Understand your limits

Resources shows each limit of your package next to what you use: disk space, files, emails sent this hour, CPU, memory, processes, websites, databases, mailboxes, FTP accounts, cron jobs and Bandwidth this month. A bar turns orange at 75% and red at 90%.

Limit What happens when you reach it
Websites, databases, mailboxes, FTP, cron jobs You cannot add another one; the panel names the limit, for example the package allows 5 mailboxes. Delete one or ask for a bigger package.
Disk space New files cannot be written, so uploads and backups fail. Use Disk usage on Resources to find large folders.
CPU, memory, processes Your websites slow down instead of affecting others; processes over the memory limit are stopped.
Emails per hour Sending is refused until the next hour.
Monthly bandwidth You are warned at 80% and 100%; depending on your provider's settings the account may be suspended until the next month.
A feature not in your package Its page is hidden, and the panel answers this feature is not included in your hosting package.

Traffic per website is on each website's Analytics tab. See Website statistics and Packages and limits.

Share a website with someone

To let a developer or a client work on one website without your password, open the website's Members tab and add them with Manage or View only access. They get their own login and see only that website. See Website members.

Get support

  • Click Contact support in the menu when your provider has set a support link.
  • Before you write, check the website's Logs tab (access and error logs) and the task log in Tasks; include the website, the time and the exact error message.
  • Your provider can open your panel to help you (Log in as this account). Such visits are recorded in your Activity Log, and they cannot change your password, two-factor authentication or API tokens during the visit.

Troubleshooting

Problem What to do
invalid username or password Check the username (lowercase) and password. Ask your provider for a new password if needed.
account suspended: … Contact your provider; the reason is shown after the colon.
The website shows a placeholder page Upload your files to public_html, with an index.php or index.html.
SSL is not issued The domain's A record must point to the server. Wait for DNS, then click Issue certificate.
A menu item from this guide is missing Your package or the server does not include it. Ask your provider.
Mail goes to spam Add every record listed under DNS records on the Email page.

← Fleet and multiple servers Operations and monitoring →