Install on cloud providers
Prepare a VPS on DigitalOcean, Vultr, Hetzner, AWS, Google Cloud, Azure, Oracle Cloud, Linode or a local provider: ports, mail port 25, PTR, IPv6, ARM64 and cloud-init.
ZoPanel installs the same way on every provider: a fresh Ubuntu or Debian server and one command. What differs is the provider's network around the server: cloud firewalls, blocked mail ports, reverse DNS and, on Oracle Cloud, a host firewall that is already in place. This page lists what to prepare on each provider before you follow Install ZoPanel.
Checklist for every provider
- Image: a fresh Ubuntu 22.04/24.04 or Debian 12/13 image, amd64 or arm64, with nothing else installed. Avoid marketplace images that ship a web server or another panel: the installer stops when it finds Apache, cPanel, DirectAdmin or aaPanel. See System requirements.
- Size: at least 1 GB of RAM, 2 GB or more for production. Prefer a full virtual machine (KVM) to a container VPS: in a container the host's kernel is used, and disk quotas may not be available.
- Access: an SSH key for root, or for the image's default user with
sudo. Many cloud images log in asubuntu,adminor a user you chose, not as root; run the installer withsudo. - Provider firewall: open the ports below in the provider's firewall or security group before you install, or you will not reach the panel.
- Mail: if you will host email, check that outbound port 25 is open and that you can set reverse DNS (PTR) for the server's IP.
- DNS: a hostname for the server (for example
srv1.example.com) and, ideally, a panel domain pointing to the server's IP.
Ports to open
The installer turns on UFW on the server and opens the base ports. Your provider's firewall sits in front of UFW and must allow the same traffic.
| Port | Protocol | Needed for |
|---|---|---|
| Your SSH port (usually 22) | TCP | SSH and SFTP |
| 80 | TCP | Websites and Let's Encrypt validation |
| 443 | TCP | Websites over HTTPS |
| 8888 | TCP | The ZoPanel interface (https://IP:8888) and fleet connections |
Open these only when you install the matching component (ZoPanel opens them in UFW by itself):
| Component | Ports |
|---|---|
| Mail server | 25, 465, 587, 143, 993, 110, 995 (TCP) |
| Webmail | 2096 (TCP) |
| Calendars & contacts | 2080 (TCP) |
| DNS server | 53 (TCP and UDP) |
| FTP server | 21 and 30000-30100 (TCP) |
| Adminer | 8889 (TCP) |
Remote access to a database is opened in UFW only for the addresses you allow (see Databases); open the database port for the same addresses in the provider firewall.
The server also needs outbound HTTPS to download ZoPanel, system packages, PHP and certificates.
Mail: port 25 and reverse DNS
Most cloud providers block outbound port 25 on new servers to stop spam. Incoming mail still arrives, but your server cannot deliver mail to other servers. You have two options:
- Ask the provider to unblock port 25. Each provider has its own process (see below). Approval is usually case by case.
- Send through a relay with Outgoing mail relay (smarthost) on the Email page (SendGrid, Mailgun, Amazon SES, Brevo…). It uses port 587 unless you set another port. See Email.
Set the reverse DNS (PTR) of the server's IPv4 address (and IPv6, if you send over it) to your mail hostname, for example mail.example.com, and make sure that name has an A record pointing back to the same IP. Without it, much of your mail lands in spam. After installing, Run check in Mail delivery check tests PTR and outbound port 25 for you.
IPv6
ZoPanel's web server and panel listen on IPv6 as well as IPv4, and UFW applies its rules to both. If the provider gives the server an IPv6 address (some need you to enable it when creating the server), you can add AAAA records for your domains.
Only publish an AAAA record when IPv6 really reaches the server through the provider's firewall: Let's Encrypt and many visitors connect over IPv6 when an AAAA record exists, and certificate issuance fails if that path is closed.
ARM64 servers
ZoPanel runs on arm64 (Ampere, Graviton and similar) as well as amd64; the installer downloads the matching build. Keep in mind:
- The .NET SDK cannot be installed on Debian arm64. Use Ubuntu if you need .NET on ARM.
- Docker images you deploy yourself must be published for arm64.
Unattended install with cloud-init
Most providers accept a cloud-init script ("user data") when you create a server. Install ZoPanel from it so the server is ready when you first log in:
#cloud-config
runcmd:
- curl -fsSL https://get.zopanel.net | ZOPANEL_LICENSE_KEY=ZP-XXXX-XXXX-XXXX bash -s -- --yes --reboot --hostname srv1.example.com --admin-email admin@example.com
--yesanswers every question with its default;--rebootrestarts the server at the end when a new kernel or libraries need it (--no-rebootnever restarts).- Add any other installer flag, for example
--profile full,--php 8.3,8.2,--mail-hostname mail.example.comor--nameservers ns1.example.com,ns2.example.com. See the full list in Install ZoPanel. - Pass secrets as environment variables, not flags:
ZOPANEL_LICENSE_KEYfor the license andZOPANEL_ADMIN_PASSWORDfor a chosen admin password. - cloud-init runs as root, so
sudois not needed. WithoutZOPANEL_ADMIN_PASSWORD, the generated password is in the cloud-init log (usually/var/log/cloud-init-output.log). Reset it any time withzopanel ctl reset-password admin.
Important: cloud-init cannot open the provider's firewall for you. Create the server with a firewall or security group that already allows the ports above.
Provider notes
Each provider's policies change. The notes below follow the providers' own documentation at the time of writing; check the linked pages before you rely on them.
DigitalOcean
- SMTP ports 25, 465 and 587 are blocked on Droplets by default. DigitalOcean recommends a third-party email service. Since 587 is blocked too, configure the ZoPanel relay with another port your relay provider offers (many offer 2525). Why is SMTP blocked?
- The PTR record is created from the Droplet's name: name the Droplet with the fully qualified mail hostname (for example
mail.example.com). PTR records - If you use a DigitalOcean Cloud Firewall, add the ports above to its inbound rules.
Vultr
- Outbound port 25 is blocked on new instances; ports 465 and 587 remain open. Request unblocking with a support ticket that describes your use case, your anti-spam measures (SPF, DKIM, rate limits) and your expected volume. Why is SMTP blocked?
- Set reverse DNS in the instance's IPv4 section by replacing the default reverse DNS value. IPv4 networking
Hetzner Cloud
- Ports 25 and 465 are blocked by default on all cloud servers; port 587 is not. After you have been a customer for a month and paid your first invoice, you can send a limit request to unblock them for a valid use case. Cloud server FAQ
- Reverse DNS can be set per IP address of the server.
- If you attach a Hetzner Cloud Firewall, add the ports above to it.
AWS EC2
- Outbound port 25 is blocked by default. Submit the "Request to remove email sending limitations" form yourself (AWS Support cannot file it for you), once per Region; it can take up to 48 hours. Reverse DNS for an Elastic IP is requested in the same process, and the A record must already point to that IP. EC2 port 25
- Open the ports in the instance's security group.
- Official Ubuntu images log in as
ubuntu, Debian images asadmin. Install withsudo. - Use an Elastic IP: the public IP of an instance changes when it is stopped and started, which breaks DNS and SSL.
AWS Lightsail
- Outbound port 25 is blocked on all Lightsail instances by default. Request removal from the Lightsail console as the root user; include the instance name, Region and a static IP for the reverse DNS record. Lightsail port 25
- Attach a static IP and add the ports above to the instance's firewall on its Networking tab.
Google Cloud (Compute Engine)
- Connections to external port 25 are blocked (some older projects are exempt). Ports 465 and 587 are not restricted, so use a relay on 587. Sending email from an instance
- A PTR record can be set on the VM's primary network interface; the A record must point to the same reserved external IP. Create a PTR record
- Add VPC firewall rules for the ports above (8888 in particular), and reserve a static external IP.
Microsoft Azure
- Outbound port 25 is not blocked for Enterprise Agreement and MCA-E subscriptions. Enterprise Dev/Test subscriptions can request an exemption under Diagnose and solve problems of the virtual network. Other subscription types are blocked: send through an authenticated relay on port 587. Troubleshoot outbound SMTP
- Add inbound rules for the ports above to the VM's network security group.
Oracle Cloud (OCI)
Oracle's Ubuntu images come with their own iptables rules, saved in /etc/iptables/rules.v4. They accept SSH and end with a REJECT rule, so other ports are refused on the server itself even after you open them in the cloud. Oracle documents that new rules must go above that REJECT line.
-
In the VCN security list (or network security group) of the instance's subnet, add ingress rules for the ports above.
-
On the server, edit
/etc/iptables/rules.v4. Below the existing SSH line, add one line per port, above theREJECTline:-A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 8888 -j ACCEPT -
Apply the file:
sudo iptables-restore < /etc/iptables/rules.v4 -
Install ZoPanel. When you add a component later (mail, DNS, FTP…), add its ports to this file as well. Do not delete Oracle's other rules: some are needed by the instance's own services.
Also on Oracle Cloud:
- Tenancies created after June 23, 2021 cannot send to port 25 on the internet by default; request an exemption through a service limit request, or use a relay on 587. Release note
- Ampere A1 instances are arm64 and supported (see ARM64 servers).
Linode (Akamai)
- On accounts created since November 5, 2019, outbound ports 25, 465 and 587 are restricted. Set up the A record and reverse DNS for the Linode, then open a support ticket. A new policy to help fight spam
- If you use a Cloud Firewall, add the ports above.
Vietnamese and other local providers
Policies vary by provider and by plan, so ask before you order:
- Is the VPS a full virtual machine (KVM) with a fresh Ubuntu or Debian image, or a container?
- Is outbound port 25 open, and how do you request it?
- Can they set reverse DNS (PTR) for the IP, and is it done by ticket?
- Does the IP come with IPv6?
- Is there a network firewall in front of the VPS whose ports you must open?
Some local templates add software or custom repositories to the image. If the installer reports another web server or panel, reinstall the VPS from a clean image rather than using --force.
After installing
- Open
https://YOUR-IP:8888. If it does not load, the provider's firewall is the usual cause: check that 8888/TCP is open there, and on Oracle Cloud in/etc/iptables/rules.v4too. - Run
zopanel ctl doctoron the server to check services and configuration. - Follow the Quick start.