# Panel settings

> A tour of Settings in ZoPanel: panel domain and SSL, allowed IPs, required 2FA, alerts by Telegram, email or webhook, activity log shipping and account retention.

Source: https://zopanel.net/docs/panel-settings  
Updated: 2026-10-07

The **Settings** page holds the server-wide configuration of ZoPanel. Only administrators can open it. It is split into tabs: **General**, **Alerts**, **Remote backups**, **License**, **AI assistant**, **Hooks**, **Updates** and **System**. This page covers the settings you are most likely to change; licensing and updates have their own pages.

## General

### Basic settings

| Setting | What it does |
| --- | --- |
| **Administrator email** | Used for Let's Encrypt registration and notifications. Required before you can issue the panel certificate. |
| **Default PHP version** | The PHP version preselected for new websites. |
| **Panel name (white-label)** | Shown instead of "ZoPanel". Requires a Business license. |
| **Automatic backups** | Off, Daily or Weekly (Sunday). Runs at 02:00 server time. |
| **Backups to keep per account** | 1 to 90. |
| **Require two-factor authentication** | See below. |
| **Send the activity log to** | See below. |
| **Keep deleted accounts (days)** | See below. |
| **Let resellers oversell** | Off: a reseller's customers together stay within the reseller's own plan (disk and websites). On: each customer is only held to its own package. |

Click **Save** after changing them.

### Require two-factor authentication

Choose who must use 2FA:

| Option | Who |
| --- | --- |
| **Not required** | Nobody is forced (default) |
| **Administrators and resellers** | Every administrator and reseller |
| **Everyone** | All users, including customers |

Users without 2FA are asked to set it up at their next sign-in, and cannot continue until they do. Each user sets it up under **My account → Two-factor authentication** with an authenticator app, and gets recovery codes.

If an administrator loses both the phone and the recovery codes, root on the server can turn 2FA off for that user:

```bash
zopanel ctl disable-2fa USERNAME
```

### Send the activity log to (remote syslog)

Every entry of the **Activity Log** can also be sent to a syslog server outside this one. Someone who later takes over this server cannot change that copy.

Enter the target as `udp://host:port` or `tcp://host:port`:

```text
udp://logs.example.com:514
```

Leave the field empty to turn it off. If the syslog server is slow or unreachable, the panel is not held up; the local activity log and the system journal keep every entry.

### Keep deleted accounts (days)

When you delete a hosting account, its websites, databases and mailboxes stay recoverable for this many days (0 to 90, default 7). Set `0` to delete everything at once.

### Panel domain & SSL

By default the panel uses a self-signed certificate at `https://SERVER-IP:8888`. To use a trusted certificate:

1. Point a domain such as `panel.example.com` to the server (A record).
2. Make sure **Administrator email** is filled in and saved.
3. Enter the domain in **Panel domain**.
4. Click **Issue certificate**.

A task requests a Let's Encrypt certificate. The panel is then available at `https://panel.example.com:8888`, and the certificate renews automatically. The same certificate is also used by the mail server and webmail when they are installed.

### Restrict panel access

Limit the panel to your own addresses, such as your office or VPN.

1. In **Restrict panel access**, enter IP addresses or networks in CIDR notation, one per line:

   ```text
   203.0.113.10
   198.51.100.0/24
   ```

2. Click **Save**.

Leave the list empty to allow everyone. Include the address you are connecting from, or you will lock yourself out. If that happens, run on the server:

```bash
zopanel ctl allow-ip --clear
```

You can also replace the list with a single address: `zopanel ctl allow-ip 203.0.113.10`. Both commands restart the panel.

If another ZoPanel server manages this one (central management), add that server's IP to the list.

## Alerts

The **Alerts** tab sends notifications to administrators. Turn on one or more channels:

| Channel | Fields |
| --- | --- |
| **Telegram** | Bot token (create a bot with @BotFather) and Chat ID (from @userinfobot) |
| **Email (SMTP)** | SMTP host, Port, Username, Password, From, To (comma separated) |
| **Webhook (Discord / Slack)** | Type (Discord, Slack or JSON) and URL |

Then choose the **Events** that trigger an alert, such as:

- Website down, Service down or restarted, Fleet server unreachable
- SSL expiring soon, SSL renewal failed, Domain expiring soon
- High CPU usage, High memory usage, Disk almost full
- Failed panel logins, Login from a new IP
- Backup failed, Malware detected, Deployment failed
- Mail sending limit reached, Mail queue growing, Server IP on a blocklist
- Update available, Panel update failed or rolled back

Set the thresholds for the resource alerts in **CPU %**, **RAM %** and **Disk %**. Click **Save**, then **Send test** to check the channels.

Customers have their own notification settings for their websites, under **My account**.

## Other tabs

| Tab | What it holds |
| --- | --- |
| **Remote backups** | Copy every backup to S3-compatible storage (AWS S3, Cloudflare R2, Backblaze B2, Wasabi, DigitalOcean, MinIO). Requires a Pro license. |
| **License** | Plan, limits, activation and offline tokens. See [Licensing](/docs/licensing). |
| **AI assistant** | An optional assistant that answers questions about websites and the server using live panel data. It needs your own Anthropic API key, and changes only run after the user confirms. |
| **Hooks** | Event webhooks to your own HTTPS URLs (signed with HMAC-SHA256), and root-owned hook scripts that run after each event. |
| **Updates** | Version, channel and automatic updates. See [Updating ZoPanel](/docs/updating). |
| **System** | Hostname, OS, kernel and component versions; **PHP performance**; **Disk quotas**; **IP addresses** for dedicated IPs per account; and **Central management**. |

The **PHP performance** card is described in [PHP performance](/docs/php-performance). In **Disk quotas**, click **Enable quotas** if the installer could not turn them on; without quotas, disk and file limits are only measured, not enforced.

## Settings from the command line

A few settings can be fixed from the server when the panel is not reachable:

| Command | Effect |
| --- | --- |
| `zopanel ctl reset-password USER` | Sets a new random password (or `--password PASS`) and signs the user out everywhere |
| `zopanel ctl disable-2fa USER` | Turns off 2FA for the user |
| `zopanel ctl allow-ip IP` / `--clear` | Replaces or clears the panel IP restriction |
| `zopanel ctl info` | Version, Server ID, plan, websites and accounts |
| `zopanel ctl doctor` | Checks the server and says how to fix what is wrong |
