# Install on cloud providers

> Prepare a VPS on DigitalOcean, Vultr, Hetzner, AWS, Google Cloud, Azure, Oracle Cloud, Linode or a local provider: ports, mail port 25, PTR, IPv6, ARM64 and cloud-init.

Source: https://zopanel.net/docs/install-cloud-providers  
Updated: 2026-10-09

ZoPanel installs the same way on every provider: a fresh Ubuntu or Debian server and one command. What differs is the provider's network around the server: cloud firewalls, blocked mail ports, reverse DNS and, on Oracle Cloud, a host firewall that is already in place. This page lists what to prepare on each provider before you follow [Install ZoPanel](/docs/install).

## Checklist for every provider

1. **Image:** a fresh Ubuntu 22.04/24.04 or Debian 12/13 image, amd64 or arm64, with nothing else installed. Avoid marketplace images that ship a web server or another panel: the installer stops when it finds Apache, cPanel, DirectAdmin or aaPanel. See [System requirements](/docs/requirements).
2. **Size:** at least 1 GB of RAM, 2 GB or more for production. Prefer a full virtual machine (KVM) to a container VPS: in a container the host's kernel is used, and disk quotas may not be available.
3. **Access:** an SSH key for root, or for the image's default user with `sudo`. Many cloud images log in as `ubuntu`, `admin` or a user you chose, not as root; run the installer with `sudo`.
4. **Provider firewall:** open the ports below in the provider's firewall or security group *before* you install, or you will not reach the panel.
5. **Mail:** if you will host email, check that outbound port 25 is open and that you can set reverse DNS (PTR) for the server's IP.
6. **DNS:** a hostname for the server (for example `srv1.example.com`) and, ideally, a panel domain pointing to the server's IP.

## Ports to open

The installer turns on UFW on the server and opens the base ports. Your provider's firewall sits in front of UFW and must allow the same traffic.

| Port | Protocol | Needed for |
| --- | --- | --- |
| Your SSH port (usually 22) | TCP | SSH and SFTP |
| 80 | TCP | Websites and Let's Encrypt validation |
| 443 | TCP | Websites over HTTPS |
| 8888 | TCP | The ZoPanel interface (`https://IP:8888`) and [fleet](/docs/fleet) connections |

Open these only when you install the matching component (ZoPanel opens them in UFW by itself):

| Component | Ports |
| --- | --- |
| Mail server | 25, 465, 587, 143, 993, 110, 995 (TCP) |
| Webmail | 2096 (TCP) |
| Calendars & contacts | 2080 (TCP) |
| DNS server | 53 (TCP and UDP) |
| FTP server | 21 and 30000-30100 (TCP) |
| Adminer | 8889 (TCP) |

Remote access to a database is opened in UFW only for the addresses you allow (see [Databases](/docs/databases)); open the database port for the same addresses in the provider firewall.

The server also needs outbound HTTPS to download ZoPanel, system packages, PHP and certificates.

## Mail: port 25 and reverse DNS

Most cloud providers block **outbound** port 25 on new servers to stop spam. Incoming mail still arrives, but your server cannot deliver mail to other servers. You have two options:

- **Ask the provider to unblock port 25.** Each provider has its own process (see below). Approval is usually case by case.
- **Send through a relay** with **Outgoing mail relay (smarthost)** on the Email page (SendGrid, Mailgun, Amazon SES, Brevo…). It uses port 587 unless you set another port. See [Email](/docs/email).

Set the **reverse DNS (PTR)** of the server's IPv4 address (and IPv6, if you send over it) to your mail hostname, for example `mail.example.com`, and make sure that name has an A record pointing back to the same IP. Without it, much of your mail lands in spam. After installing, **Run check** in **Mail delivery check** tests PTR and outbound port 25 for you.

## IPv6

ZoPanel's web server and panel listen on IPv6 as well as IPv4, and UFW applies its rules to both. If the provider gives the server an IPv6 address (some need you to enable it when creating the server), you can add AAAA records for your domains.

Only publish an AAAA record when IPv6 really reaches the server through the provider's firewall: Let's Encrypt and many visitors connect over IPv6 when an AAAA record exists, and certificate issuance fails if that path is closed.

## ARM64 servers

ZoPanel runs on arm64 (Ampere, Graviton and similar) as well as amd64; the installer downloads the matching build. Keep in mind:

- The [.NET SDK](/docs/dotnet) cannot be installed on Debian arm64. Use Ubuntu if you need .NET on ARM.
- Docker images you deploy yourself must be published for arm64.

## Unattended install with cloud-init

Most providers accept a **cloud-init** script ("user data") when you create a server. Install ZoPanel from it so the server is ready when you first log in:

```yaml
#cloud-config
runcmd:
  - curl -fsSL https://get.zopanel.net | ZOPANEL_LICENSE_KEY=ZP-XXXX-XXXX-XXXX bash -s -- --yes --reboot --hostname srv1.example.com --admin-email admin@example.com
```

- `--yes` answers every question with its default; `--reboot` restarts the server at the end when a new kernel or libraries need it (`--no-reboot` never restarts).
- Add any other installer flag, for example `--profile full`, `--php 8.3,8.2`, `--mail-hostname mail.example.com` or `--nameservers ns1.example.com,ns2.example.com`. See the full list in [Install ZoPanel](/docs/install#installer-options).
- Pass secrets as environment variables, not flags: `ZOPANEL_LICENSE_KEY` for the license and `ZOPANEL_ADMIN_PASSWORD` for a chosen admin password.
- cloud-init runs as root, so `sudo` is not needed. Without `ZOPANEL_ADMIN_PASSWORD`, the generated password is in the cloud-init log (usually `/var/log/cloud-init-output.log`). Reset it any time with `zopanel ctl reset-password admin`.

**Important:** cloud-init cannot open the provider's firewall for you. Create the server with a firewall or security group that already allows the ports above.

## Provider notes

Each provider's policies change. The notes below follow the providers' own documentation at the time of writing; check the linked pages before you rely on them.

### DigitalOcean

- SMTP ports 25, 465 and 587 are blocked on Droplets by default. DigitalOcean recommends a third-party email service. Since 587 is blocked too, configure the ZoPanel relay with another port your relay provider offers (many offer 2525). [Why is SMTP blocked?](https://docs.digitalocean.com/support/why-is-smtp-blocked/)
- The PTR record is created from the Droplet's name: name the Droplet with the fully qualified mail hostname (for example `mail.example.com`). [PTR records](https://docs.digitalocean.com/glossary/ptr-record/)
- If you use a DigitalOcean Cloud Firewall, add the ports above to its inbound rules.

### Vultr

- Outbound port 25 is blocked on new instances; ports 465 and 587 remain open. Request unblocking with a support ticket that describes your use case, your anti-spam measures (SPF, DKIM, rate limits) and your expected volume. [Why is SMTP blocked?](https://docs.vultr.com/support/products/compute/why-is-smtp-blocked)
- Set reverse DNS in the instance's **IPv4** section by replacing the default reverse DNS value. [IPv4 networking](https://docs.vultr.com/products/compute/cloud-compute/networking/ipv4)

### Hetzner Cloud

- Ports 25 and 465 are blocked by default on all cloud servers; port 587 is not. After you have been a customer for a month and paid your first invoice, you can send a limit request to unblock them for a valid use case. [Cloud server FAQ](https://docs.hetzner.com/cloud/servers/faq/)
- Reverse DNS can be set per IP address of the server.
- If you attach a Hetzner Cloud Firewall, add the ports above to it.

### AWS EC2

- Outbound port 25 is blocked by default. Submit the "Request to remove email sending limitations" form yourself (AWS Support cannot file it for you), once per Region; it can take up to 48 hours. Reverse DNS for an Elastic IP is requested in the same process, and the A record must already point to that IP. [EC2 port 25](https://repost.aws/knowledge-center/ec2-port-25-throttle)
- Open the ports in the instance's **security group**.
- Official Ubuntu images log in as `ubuntu`, Debian images as `admin`. Install with `sudo`.
- Use an **Elastic IP**: the public IP of an instance changes when it is stopped and started, which breaks DNS and SSL.

### AWS Lightsail

- Outbound port 25 is blocked on all Lightsail instances by default. Request removal from the Lightsail console as the root user; include the instance name, Region and a static IP for the reverse DNS record. [Lightsail port 25](https://repost.aws/knowledge-center/lightsail-port-25-throttle)
- Attach a **static IP** and add the ports above to the instance's firewall on its **Networking** tab.

### Google Cloud (Compute Engine)

- Connections to external port 25 are blocked (some older projects are exempt). Ports 465 and 587 are not restricted, so use a relay on 587. [Sending email from an instance](https://docs.cloud.google.com/compute/docs/tutorials/sending-mail)
- A PTR record can be set on the VM's primary network interface; the A record must point to the same reserved external IP. [Create a PTR record](https://docs.cloud.google.com/compute/docs/instances/create-ptr-record)
- Add VPC firewall rules for the ports above (8888 in particular), and reserve a static external IP.

### Microsoft Azure

- Outbound port 25 is not blocked for Enterprise Agreement and MCA-E subscriptions. Enterprise Dev/Test subscriptions can request an exemption under **Diagnose and solve problems** of the virtual network. Other subscription types are blocked: send through an authenticated relay on port 587. [Troubleshoot outbound SMTP](https://learn.microsoft.com/azure/virtual-network/troubleshoot-outbound-smtp-connectivity)
- Add inbound rules for the ports above to the VM's **network security group**.

### Oracle Cloud (OCI)

Oracle's Ubuntu images come with their own **iptables rules**, saved in `/etc/iptables/rules.v4`. They accept SSH and end with a `REJECT` rule, so other ports are refused on the server itself even after you open them in the cloud. Oracle documents that new rules must go **above** that `REJECT` line.

1. In the VCN **security list** (or network security group) of the instance's subnet, add ingress rules for the ports above.
2. On the server, edit `/etc/iptables/rules.v4`. Below the existing SSH line, add one line per port, above the `REJECT` line:

   ```text
   -A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
   -A INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
   -A INPUT -p tcp -m state --state NEW -m tcp --dport 8888 -j ACCEPT
   ```

3. Apply the file:

   ```bash
   sudo iptables-restore < /etc/iptables/rules.v4
   ```

4. Install ZoPanel. When you add a component later (mail, DNS, FTP…), add its ports to this file as well. Do not delete Oracle's other rules: some are needed by the instance's own services.

Also on Oracle Cloud:

- Tenancies created after June 23, 2021 cannot send to port 25 on the internet by default; request an exemption through a service limit request, or use a relay on 587. [Release note](https://docs.oracle.com/en-us/iaas/releasenotes/changes/f7e95770-9844-43db-916c-6ccbaf2cfe24)
- Ampere A1 instances are arm64 and supported (see [ARM64 servers](#arm64-servers)).

### Linode (Akamai)

- On accounts created since November 5, 2019, outbound ports 25, 465 and 587 are restricted. Set up the A record and reverse DNS for the Linode, then open a support ticket. [A new policy to help fight spam](https://www.linode.com/blog/linode/a-new-policy-to-help-fight-spam/)
- If you use a Cloud Firewall, add the ports above.

### Vietnamese and other local providers

Policies vary by provider and by plan, so ask before you order:

- Is the VPS a full virtual machine (KVM) with a fresh Ubuntu or Debian image, or a container?
- Is outbound port 25 open, and how do you request it?
- Can they set reverse DNS (PTR) for the IP, and is it done by ticket?
- Does the IP come with IPv6?
- Is there a network firewall in front of the VPS whose ports you must open?

Some local templates add software or custom repositories to the image. If the installer reports another web server or panel, reinstall the VPS from a clean image rather than using `--force`.

## After installing

- Open `https://YOUR-IP:8888`. If it does not load, the provider's firewall is the usual cause: check that 8888/TCP is open there, and on Oracle Cloud in `/etc/iptables/rules.v4` too.
- Run `zopanel ctl doctor` on the server to check services and configuration.
- Follow the [Quick start](/docs/quick-start).

## Related

- [System requirements](/docs/requirements)
- [Install ZoPanel](/docs/install)
- [Quick start](/docs/quick-start)
- [Email](/docs/email)
- [Security](/docs/security)
- [Troubleshooting](/docs/troubleshooting)
