Web

What Is cPanel? A Beginner's Guide to Managing Your Website

Talha Aslan 18 min read 1 views

What is cPanel and what does it do for your website?

cPanel is a graphical control panel that lets you manage a web hosting account from your browser. From one dashboard you handle files, email accounts, databases, domains, SSL certificates, backups, scheduled tasks and the PHP version. In short, you run day to day site maintenance without touching the command line.

When you buy shared hosting, the welcome email usually includes a cPanel URL, a username and a password. From that moment, most of the technical work on your site runs through this panel. That is why the question "what is cPanel" matters to site owners, not only to developers.

We are a digital marketing and web team, not a hosting company. So we base the menu names and behavior in this guide on the official cPanel and CloudLinux documentation. Your host may configure the panel differently, hide some tools or rename them. If a section is missing on your screen, ask your provider first.

Which tasks can you handle yourself in cPanel?

cPanel manages the hosting account assigned to you, not the whole server. In other words, you control everything inside your own space, but you cannot change global server settings. This split also protects the other accounts that share the same machine on shared hosting.

These are the jobs you will reach for most often:

  • File management: upload, edit and compress site files, and check their permissions.
  • Email: create mailboxes on your domain and set up forwarders and autoresponders.
  • Databases: create MySQL or MariaDB databases and users, then inspect tables in phpMyAdmin.
  • Domains: add addon domains and subdomains, then edit DNS records.
  • Security: monitor SSL status, turn on two-factor authentication and block IP addresses.
  • Backups: back up all or part of the account and restore partial backups.
  • Scheduled tasks: run commands at set times with cron jobs.
  • Software settings: pick a PHP version per domain and adjust PHP settings.

For example, if a WordPress contact form stops sending mail, you can diagnose part of the problem yourself in the email and DNS sections. On the other hand, server-wide mail settings belong to your host, not to you.

What is the difference between cPanel and WHM?

cPanel works at the account level, while WHM (WebHost Manager) works at the server level. According to the official cPanel documentation, you must be the root user or a user with reseller privileges to log in to WHM. Put simply, WHM is the layer above that creates and manages many cPanel accounts.

FeaturecPanelWHM
Who uses it?The owner of a single hosting accountThe server administrator (root) or a reseller
ScopeOwn files, email and databasesAll accounts, packages and server settings
Default login port2083 (HTTPS)2087 (HTTPS)
Restore a full backupNot automaticallyYes
Two-factor authenticationUser turns it on for their own accountAdmin enables the feature server-wide
Typical userSite owner, agency, developerHosting company, VPS owner, reseller

If you use shared hosting, you most likely have cPanel access only. If you installed cPanel on your own VPS or bought a reseller plan, WHM is in your hands too. We explain what the reseller model means for agencies in our cPanel reseller hosting guide.

In practice, one question settles the split. Does the task affect only your account, or everyone on the server? In the first case, cPanel is enough. In the second case, you need WHM access or help from your host. For instance, you can raise the quota of your own mailbox, but you cannot change the server-wide sending limit.

How do you log in to cPanel?

The official cPanel documentation lists port 2083 for cPanel, 2087 for WHM and 2096 for Webmail, and all three use HTTPS. So you usually type an address like this into your browser:

https://example.com:2083
https://example.com:2087
https://example.com:2096

Many hosts spare you the port numbers and offer a one-click login link in their client area instead. Compare the address you use with the cPanel login documentation and with your welcome email.

Some office networks and corporate firewalls block these ports. If the login page will not load, first try another network, then contact your host. Also, do not leave your login details sitting in plain text in an email; change the password on first login and store it in a password manager.

After you log in, check the interface language and your contact details in the user menu. The panel can send alerts to that address, for example when your disk quota fills up. As a result, an outdated email address means you miss important warnings.

Which sections does the cPanel home screen show?

The current cPanel interface theme is Jupiter, and the home screen groups tools under headings. Your host may disable some tools, but the skeleton looks similar on most accounts.

  • Files: File Manager, Backup, Backup Wizard, Disk Usage, FTP Accounts.
  • Databases: phpMyAdmin, MySQL Databases, MySQL Database Wizard.
  • Domains: Domains, Redirects, Zone Editor.
  • Email: Email Accounts, Forwarders, Autoresponders, Spam Filters.
  • Metrics: Visitors, Errors, Bandwidth and statistics such as Awstats.
  • Security: SSL/TLS Status, Two-Factor Authentication, IP Blocker.
  • Software: MultiPHP Manager, MultiPHP INI Editor and, depending on the host, WP Toolkit.
  • Advanced: Cron Jobs and Terminal (if your host enables it).

Also, the search box at the top is the fastest route. For example, type "cron" and you land straight on the scheduled tasks screen. The statistics area beside the tools shows your plan limits, such as disk usage, the number of email accounts and the number of databases.

What does File Manager do, and what should you watch out for?

File Manager lets you manage site files in the browser without an FTP client. In most accounts, your main site files live in the public_html folder. Addon domains point to their own folders, and the Domains screen shows which folder belongs to which domain.

In practice, this tool is handy but unforgiving. That is why we recommend these habits:

  • Copy a file before you edit it; for instance, save a backup of .htaccess under a different name in the same folder.
  • Turn on "Show Hidden Files" in the settings to see files such as .htaccess.
  • Never set permissions to 777 for convenience; use the permissions your host recommends.
  • For large uploads, send a zip archive and extract it in the panel; this is faster than uploading files one by one.

If your site shows a blank page or a 500 error after a change, revert the last file you edited. Then check the error log before you try anything else.

How do you create a business email account in cPanel?

On the Email Accounts screen, you click "Create", choose the domain, then set the username and password. You can also set a mailbox quota. Once the account exists, you sign in through Webmail or add it to Outlook or your phone with the settings under "Connect Devices".

One point people often skip: email does not end with creating a mailbox. To keep your messages out of spam folders, your SPF, DKIM and DMARC records need to be correct. cPanel shows their status on the email deliverability screen. We cover the background in our business email on a custom domain guide.

On the other hand, if your domain email lives on an external service such as Google Workspace or Microsoft 365, creating a mailbox with the same name in cPanel causes confusion. That happens because the server may try to deliver internal mail for that address to its own mailbox. In that setup, review the MX settings with your host.

What does the Databases section give you?

Most dynamic sites, specifically CMS platforms, store their content in a database. In cPanel, the MySQL Database Wizard offers a three-step flow. First you create the database, then you add a user, and finally you grant that user privileges on the database. On shared hosting, your account name usually appears as a prefix on database and user names.

phpMyAdmin lets you browse tables, run queries and export data. That said, browser imports of large databases can time out. In that case, ask your host for help or use the official command line tools if you have shell access.

For security, create a separate database user for each site and grant only the privileges it needs. That way, a flaw in one site does not reach straight into the data of another site on the same account.

Also watch the connection settings. On most shared plans your site connects to the database through localhost. If you need a remote connection, allow only the IP address you need on the Remote Database Access screen. Leaving that screen wide open exposes your database to the internet for no reason.

Where do you manage domains and DNS records in cPanel?

Above all, the Domains screen lists your main domain, addon domains and subdomains in one place. When you add a new domain, the panel assigns it a document root folder. When you create a subdomain such as blog.example.com, you define a separate folder for it too.

Zone Editor is where you edit DNS records. However, it only takes effect if your domain nameservers point to this hosting account. If your DNS lives elsewhere, for example at Cloudflare, record changes in cPanel never reach the outside world. Check what a record actually returns with our DNS lookup tool.

In short, answer the question "where is my DNS?" before you change anything. This simple check prevents hours of email or website downtime.

How do you check SSL certificates in cPanel?

Many hosts use the cPanel AutoSSL feature to install and renew free domain-validated (DV) certificates automatically. Your host manages this feature on the server side. You, in turn, use the SSL/TLS Status screen under Security to see which domains have protection, which certificates expire soon and where AutoSSL runs into problems.

When AutoSSL cannot validate a domain, DNS is usually the reason, so start there. The domain may point to another server, or a subdomain record may be missing. Also note that an installed certificate does not mean every page loads over HTTPS. You still need to check redirects and mixed content warnings.

You can test how the certificate looks from the outside with our SSL checker. We explain why HTTPS is essential in our SSL certificate guide.

How much protection do cPanel backups give you?

The Backup Wizard screen lets you back up all or part of your account. The partial options cover the home directory, MySQL databases, and email forwarders and filters. A full backup, by contrast, packs the whole account into one archive.

There is a critical limit here. The cPanel Backup Wizard documentation states clearly that you cannot restore a full backup automatically in cPanel; only WHM offers that function. So you need your host to restore a full backup. Partial backups, on the other hand, you can restore yourself in the panel.

For that reason, never rely on a single backup source. Your host's automatic backup, a copy you download and an archive in a separate location together give you real protection. We cover where and how often to keep backups in our website backup strategy guide. Finally, do not stop at taking backups; test a restore now and then.

Where do cron jobs and PHP version settings live?

Next, the Cron Jobs screen runs a command automatically at set times. For example, you can schedule a store plugin's stock sync or a reporting script for the night. The time fields follow the standard cron format: minute, hour, day of month, month and day of week.

# Runs every day at 03:00 (example)
0 3 * * * php /home/username/public_html/task.php

The full path to the PHP binary differs from server to server. So check your host's documentation before you write the command. Also avoid tasks that run every minute, because on shared hosting they can hit process limits.

You pick the PHP version per domain on the MultiPHP Manager screen under Software. If the server runs CloudLinux, your host may offer PHP Selector instead. We explain both routes and the pre-change checklist in our guide to changing the PHP version in cPanel, so we will not repeat it here.

How can you track site errors and traffic in cPanel?

The Metrics heading shows how your site behaves on the server side. The Errors screen lists recent error log entries; a missing file or a permission problem leaves a trace there. Visitors shows recent access entries, and Bandwidth shows your monthly data transfer.

This data does not replace marketing analytics, but it is valuable for technical diagnosis. For instance, if the site slowed down after a campaign, first look at the Resource Usage screen for limit hits. Then search the error log for repeated warnings. Finally, measure page speed with a separate tool.

We list the server-side causes of slow loading in our why is my website slow guide. In short, cPanel shows you the symptom; to find the root cause, you read these findings together with page speed tests.

What should you check when moving a site to another cPanel account?

When you switch hosts, you have two routes. First, if both providers run cPanel, you can ask the new host for a full account transfer. That process runs in WHM and usually moves email, databases and the DNS zone together. Second, you can move the files, database and mailboxes by hand.

Whichever route you choose, we recommend this order:

  1. Take a fresh full backup and a separate database dump on the old account before you move.
  2. Lower the TTL of your DNS records ahead of moving day, so the change spreads faster.
  3. Do not change the nameservers until you have tested the site on the new account.
  4. After the switch, verify email accounts, SSL status and cron jobs one by one.
  5. Keep the old account open for a few days as a safety margin for late email and forgotten files.

A migration is the most fragile moment in a site's life. So schedule it for a low-traffic hour on a live online store, and use your host's migration support if you can.

Which 10 tasks should beginners do first in cPanel?

When you open a new hosting account, finish the basic security and housekeeping steps before you explore. This is the order our team follows when we start a new project:

  1. Change the password from the welcome email and set a strong one.
  2. Turn on two-factor authentication on the Two-Factor Authentication screen.
  3. Add a current email address on the Contact Information screen, because panel alerts go there.
  4. Confirm on the SSL/TLS Status screen that every domain has a certificate.
  5. Check on the MultiPHP Manager screen that your site runs on a supported PHP version.
  6. Create your business mailboxes and fix any warnings on the email deliverability screen.
  7. Take your first backup and download it to your computer or to separate storage.
  8. Delete unused FTP accounts, old subdomains and test installs.
  9. Learn your plan limits from the disk and resource usage screens.
  10. Decide who needs panel access; instead of sharing the password, create separate FTP or email accounts where needed.

This list takes about an hour. In return, it can save you days if an account takeover or data loss ever happens.

How do you keep your cPanel account secure?

Put simply, your cPanel account is the key to your site. Anyone who takes it over reaches your files, database and email at once. So think about security in several layers.

  • Two-factor authentication: per the cPanel 2FA documentation, login then asks for a six-digit code from a phone app on top of your password. However, your host must enable the feature in WHM first.
  • A strong, unique password: never reuse a password from another service. Our password generator is a practical place to start.
  • Remove unused software: an old WordPress install, an inactive plugin or a forgotten test folder is an attacker's favorite way in.
  • Stay up to date: keep your CMS, themes and plugins current, and keep PHP on a supported version.
  • Limit access: use SFTP instead of FTP where possible and close accounts once the job ends.

Server firewall rules, however, are your host's job, not yours. If a form submission returns a 403 error, a web application firewall may be the cause. In that case, ask your host to review the matching rule.

What limits come with cPanel on shared hosting?

cPanel gives you a wide management area, but you share the server underneath with other accounts. That is why hosts set resource limits per account. On servers running CloudLinux, a mechanism called LVE enforces these limits. The CloudLinux limits documentation defines them like this:

  • SPEED: the CPU usage limit.
  • PMEM: the physical memory limit.
  • IO and IOPS: limits on disk throughput and on the number of disk operations.
  • EP: entry processes, which include concurrent connections to dynamic scripts, SSH sessions and cron jobs.
  • NPROC: the total number of processes within the account.

If your site throws an error like "508 Resource Limit Is Reached" during a traffic spike, you most likely hit one of these limits. You can see them on the Resource Usage screen.

CageFS, meanwhile, locks each user inside a virtual file system, so accounts cannot see each other's files. We cover it in our what is CageFS guide.

How does cPanel licensing work, and who pays for it?

cPanel is not free software. According to the official cPanel pricing page, licenses apply per server and come in tiers based on how many cPanel accounts you can host. The page lists tiers named Solo, Admin, Pro and Premier. On the top tier, an extra fee per account applies beyond a set number of accounts.

As a shared hosting customer, you do not pay this license yourself. Your host pays it and builds the cost into the plan price. If you install cPanel on your own VPS, however, the license becomes your direct cost. So when you weigh a VPS, look at the panel license as well as the server price.

The account-based model matters for agencies. For example, keeping each client site in its own cPanel account is the right security choice, but it also pushes you into a higher tier. Prices change often, so we do not quote them here; check the official page for the current table.

Licensing also affects site owners indirectly. When panel costs rise, some hosts restructure their plans or move to a different panel. That is why it makes sense to ask your host about their panel policy on a long-term project and to think about a migration plan early.

What are the alternatives to cPanel?

That said, cPanel is not the only option. Your choice of control panel depends on the server type, the budget, your team's habits and the host's support. Here is a quick look at the main alternatives:

  • Plesk: supports both Linux and Windows servers. We compare the two in our Plesk vs cPanel guide.
  • DirectAdmin: a commercial panel known for a simpler interface and a lighter footprint.
  • aaPanel and other free panels: a low-cost option for experienced users who manage their own VPS. You will find setup and security notes in our aaPanel guide.

On shared hosting you rarely choose the panel yourself; when you pick a host, you pick its panel too. So in a hosting decision, the host's support quality and backup policy matter as much as the panel name. We list the criteria in our guide to choosing web hosting.

Which jobs should you leave to your hosting provider?

cPanel lets you do a lot on your own, but you do not have to do everything. Some jobs carry a high cost of error, and your host has tools you cannot see. To be honest, opening a support ticket is the better move in these cases:

  • Restoring the whole account from a full backup, since that function lives in WHM anyway.
  • Server-wide email blocks, blocklist entries and sending limits.
  • A firewall that blocks a legitimate request, or a block on your own IP address.
  • Resource limits that you exceed again and again; you may need a plan upgrade or a different setup.
  • A full account transfer when you move your domain to another host.

If you run cPanel and WHM on your own VPS, these jobs are yours. Then operating system updates, the firewall and the backup plan fall to you as well. If you do not want that load, compare a managed service with the other server options before you decide.

What are the most common cPanel mistakes?

The problems we see most often come from habits rather than missing technical knowledge. These mistakes look small but can lead to big losses:

  • Relying on one backup source and never testing a restore.
  • Editing files directly on the live site without making a copy first.
  • Changing records in Zone Editor without knowing where DNS actually lives.
  • Leaving old test installs and unused plugins on the server.
  • Switching the PHP version without checking site compatibility.
  • Sharing the panel password inside the team by email or chat.

What these mistakes have in common is simple: a few minutes of checking prevents all of them. Therefore, the best way to learn cPanel is to ask "how do I undo this?" before every change.

Conclusion: turn cPanel into a regular maintenance habit

cPanel is the control center of your hosting account. Files, email, databases, domains, SSL, backups and PHP settings all sit in one place. To use that power well, though, you need to know the difference between account level and server level, and you need to know your limits.

Our advice is simple. On day one, finish the security and backup steps. Once a month, check SSL, the PHP version and resource usage. Leave server-level work to your host. If you would like a second look at your site structure, performance or hosting choice, you can talk to our team through our web design service.

Frequently Asked Questions

Is cPanel free?
No, cPanel is licensed commercial software, and licenses apply per server. On shared hosting, your provider pays for the license and builds the cost into your plan price. If you install it on your own VPS, you pay the license fee yourself. Free open source panels such as aaPanel exist, but then security and maintenance fall entirely on you.
I forgot my cPanel password. What should I do?
First, try the password reset link on the cPanel login screen; it sends a message to the contact email stored in the panel. If your host has turned that option off, reset the password from your client area or open a support ticket. After you set the new password, turn on two-factor authentication and save the password in a password manager.
Can I install WordPress with cPanel?
Yes, you can. Most hosts offer WP Toolkit or a similar one-click installer inside cPanel. If no such tool exists, you upload the WordPress files with File Manager, create a database with the MySQL Database Wizard and finish the setup wizard in your browser. After installation, remember to check SSL, backups and update settings.
Do cPanel and WHM use the same password?
Usually not, because they are different account types. A cPanel login belongs to one hosting account, while root users or users with reseller privileges log in to WHM. On a reseller plan, your WHM username and the cPanel accounts you create for clients have separate credentials. Use a strong, separate password for each one.
Can I manage a website without cPanel?
Yes, you can use other panels such as Plesk, DirectAdmin or aaPanel, or work directly over SSH on the command line. Without a panel, though, you need to set up and monitor email, DNS, SSL and backups one by one. If you have no technical team, a hosting plan with a panel or a managed service is usually safer and takes less time.
  • cPanel
  • WHM
  • web hosting
  • control panel
  • shared hosting
  • website management
  • hosting security
Share:
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

Your brief goes straight to Talha Aslan and team: strategy led by Talha, delivery by an experienced team. The first consultation is free; we listen and come back with a clear roadmap.