How to back up a cPanel & WHM server
In WHM, open Backup Configuration, turn backups on, choose a backup type and how many daily, weekly and monthly copies to keep, and add a remote destination such as Amazon S3, Backblaze B2 or SFTP. For one account, /usr/local/cpanel/scripts/pkgacct writes an archive that restorepkg restores on any cPanel & WHM server. Then prove a restore works on a test server.
How WHM backups are organized
An account backup is one archive per cPanel account: home directory (websites and mail), a dump of each MySQL or MariaDB database, DNS zones, SSL certificates, cron jobs and settings. A system backup holds the server's configuration, mostly from /etc, /var/cpanel and /var/named. Compressed backups land in /backup like this:
/backup/
2026-10-03/accounts/example.tar.gz daily, one file per account
2026-10-03/system/ system backup
weekly/2026-09-27/accounts/example.tar.gz
monthly/2026-10-01/accounts/example.tar.gz
.meta/example.db file index used by restoresUncompressed backups end in .tar; incremental ones are a directory named after the user.
Turn on scheduled backups
Open WHM » Backup » Backup Configuration. On the Backup Settings tab:
- Select Enable Backups. It starts off.
- Choose a Backup Type (table below).
- Keep Check the Available Disk Space on, with a minimum in
%orMB; below it, scheduled backups don't run. - Under Scheduling and Retention, pick Daily Backup days, a Weekly Backup day and Monthly Backup on the 1st, the 15th or both. Each has a Retention: how many to keep, 1 to 9999.
- Under Files, select Back up User Accounts and Back up System Files; you need the latter to rebuild the server.
- Leave Back up SQL Databases on Per Account Only, which runs
mysqldump. The Entire MySQL Directory options copy/var/lib/mysqlwhile MySQL runs; cPanel warns the copy may not restore, and WHM can't restore it for you. - Keep Default Backup Directory at
/backupor a separate disk. cPanel doesn't support NFS or CIFS here. - Keep Retain Backups in the Default Backup Directory on. Turned off, WHM deletes local copies after upload and disables File and Directory Restoration.
- Click Save Configuration.
| Backup Type | Trade-off | Note |
|---|---|---|
| Compressed | Least disk space, slowest | One .tar.gz per account; works with every destination |
| Uncompressed | More disk space, faster | One .tar per account |
| Incremental | Hard links between runs save time and space | Remote copies can only go to an Rsync destination |
After a failed run, WHM keeps old backups until the next success, so the count can go over. On a tight disk, select Strictly enforce retention, regardless of backup success, which still keeps one good backup.
Check the saved settings, then run a backup now:
grep -E 'BACKUPENABLE|BACKUPACCTS|BACKUPDIR|KEEPLOCAL|PSQLBACKUP' /var/cpanel/backups/config/usr/local/cpanel/bin/backup --force --debug--debug runs in the foreground and prints progress. --force runs even if today's backups exist. Logs go to /usr/local/cpanel/logs/cpbackup/.
Include PostgreSQL and exclude files
Scheduled backups skip PostgreSQL databases. To include them, change this line as root:
PSQLBACKUP: 'yes'To leave paths out, list them in /etc/cpbackup-exclude.conf for all accounts, or in cpbackup-exclude.conf in one user's home directory: one path per line, relative to the home directory, no leading or trailing slash.
public_html/wp-content/cache
tmpThe global file already excludes access-logs, .cpanel/caches and a few more. pkgacct ignores both files.
Send backups off the server
A backup in /backup dies with the disk. On the Additional Destinations tab, pick a type, click Create New Destination, fill in the form and click Save and Validate Destination:
- Amazon S3: an existing bucket, optional folder, access key ID and secret access key.
- S3 Compatible: the same plus the endpoint hostname, which must match its TLS certificate and support virtual-hosted-style URLs.
- Backblaze B2: bucket ID, bucket name, application key ID and application key.
- SFTP and Rsync: host, port (default 22), user, and a key (recommended; WHM can generate one) or password.
- Also Google Drive, FTP, WebDAV, Additional Local Directory and Custom (your own script).
Tick Transfer System Backups to this Destination, or only account backups go there. Timeout is 30 to 300 seconds; after two retries WHM emails you and tries again next run.
Destinations have no retention setting of their own: WHM prunes them too, deleting the oldest backups remotely. To keep remote copies longer, or to survive someone deleting them with the key WHM stores, turn on bucket versioning: see Amazon S3 or Backblaze B2.
Give WHM a key limited to its own bucket or prefix. It needs upload and delete rights, because it prunes.
Backups and uploads run in separate queues. If uploads are slower, archives pile up in /backup and can fill the disk.
Back up a single account
pkgacct packages one account into a cpmove archive. As root:
/usr/local/cpanel/scripts/pkgacct example /homeThis writes /home/cpmove-example.tar.gz; options go before the username. To move an account, both servers need free space of over twice its size, plus 1 GB.
| Option | Effect |
|---|---|
--skiphomedir | Leaves out the home directory, if you copy it separately with rsync |
--skipmail | Leaves out the mail directory |
--skipacctdb | Leaves out MySQL and PostgreSQL databases |
--split | Writes the archive in parts: cpmove-example.tar.gz.part00001 and so on |
--use_backups | Starts from the account's last successful backup, to save time |
In cPanel, Files » Backup and Backup Wizard give account owners a full backup (to the home directory, FTP or SCP) and partial downloads. cPanel restores partial backups; only WHM restores a full one.
Check a backup
Test the gzip stream, then list the database dumps inside:
gzip -t /backup/2026-10-03/accounts/example.tar.gz && echo OKtar -tzf /backup/2026-10-03/accounts/example.tar.gz | grep -E '(^|/)mysql/.+\.sql$'The archive holds the home directory under homedir/, one USER_database.sql per database under mysql/, grants in mysql.sql and zones under dnszones/. If an account has databases and the second command prints nothing, read the log in /usr/local/cpanel/logs/cpbackup/; an account near or over its quota can fail this way.
Restore an account or a file
- WHM » Backup » Backup Restoration restores whole accounts from local backups (or an FTP destination you added), by account or by date. Queue accounts, click Restore, and open View Log for any Completed with warnings.
- File and Directory Restoration, in WHM and in cPanel, restores single files or directories such as
public_html/wp-config.php. It reads local backups only, overwrites existing files, and can't restore.cpanelormail. - WHM » Transfers » Transfer or Restore a cPanel Account restores a
cpmovearchive or cPanel full backup, on the server or uploaded.
From the shell, restorepkg takes the archive's path or a username:
/usr/local/cpanel/scripts/restorepkg /home/cpmove-example.tar.gzGiven a username, it searches /home, /home2, /home3, /root, /usr, /usr/home and /web for cpmove-example.tar.gz, example.tar.gz or a backup-... archive. Don't rename the file or create the account first. --newuser=example2 restores under another name.
For a remote backup, download it (for example with rclone) to the matching dated path, such as /backup/2026-10-03/accounts/example.tar.gz, and it appears in Backup Restoration. With local retention off, use Transfer or Restore a cPanel Account instead.
A restore overwrites what is there. Take a fresh pkgacct archive of the live account first.
Move accounts to another server
On the new server, WHM » Transfers » Transfer Tool logs in to the old one over SSH (port 22, falling back to 2087) as root, or as a user who escalates with su or sudo. cPanel's order for a full move:
- Install cPanel & WHM with the same MySQL or MariaDB, PHP and Apache versions and extensions. Update after the move, not before.
- Transfer Service Configurations first: EasyApache, Exim, WHM settings (
whmconf), database server, Backups and the rest. - Transfer resellers, then other accounts. Live Transfer (on by default) points DNS and mail at the new server, proxies traffic and suspends the old accounts.
- After a Live Transfer, keep the old server up for two days.
Two-factor authentication and custom DNS zone templates don't move. Per-user PHP-FPM settings arrive as a .transferred file in /var/cpanel/userdata/USERNAME; rename it and run /scripts/php_fpm_config --rebuild.
The new server needs a valid license (a new installation can use a 15-day trial), and the old license is billed until you cancel it. For cutover timing, see moving a server to a new provider.
What an account backup leaves out
- Server software and settings: PHP, EasyApache, Exim, Tweak Settings. The system backup keeps many config files, but not the software, and cPanel has no interface to restore it.
- PostgreSQL databases in scheduled backups, unless
PSQLBACKUPis'yes'. - Two-factor authentication.
- Excluded paths, and files the account neither owns nor can read.
- Suspended accounts, unless Back up Suspended Accounts is on, and a suspended user's
public_ftpalways. - Anything outside the accounts: root's scripts,
/opt, databases no account owns.
Cover those with restic or tar, and track them in a server checklist.
Test a restore
Restore onto a throwaway cPanel server, so nothing collides with live domains:
- Build a small server with production's cPanel and MySQL or MariaDB versions.
- From production, copy last night's archive to the test server's
/home; on the test server, restore it undertime. - Request the site from the test server without touching DNS. A
200or a redirect to HTTPS means it is served. - On the test server, list the databases, then log in to cPanel as the user and open a few files and an email.
- Terminate the account and the server.
scp /backup/2026-10-03/accounts/example.tar.gz [email protected]:/home/time /usr/local/cpanel/scripts/restorepkg /home/example.tar.gzcurl -sI --resolve example.com:80:203.0.113.10 http://example.com/mysql -e "SHOW DATABASES LIKE 'example%'"The time restorepkg took is the floor for recovering that account. More in testing a restore and RPO and RTO.
Common errors
| Error | Fix |
|---|---|
Error: Nowhere to back up: no enabled destinations found and retaining local copies is disabled. | Turn local retention back on, or enable a destination. |
You have enabled BACKUPMOUNT in the /var/cpanel/backups/config file, but there is no mount point that matches ... | Default Backup Directory must match the mount point in /etc/fstab exactly. |
The system could not prune the "..." directory due to an error. | Remote pruning hit its 300-second limit or lacked permission. Delete the directory by hand, use a faster destination, or fix permissions. |
The system did not find an account archive for the user "example" ... | Pass the full path, or move the file into /home under an accepted name. |
| One account's backup fails, the rest succeed | The account is near or over its quota. Raise it. |
| Account restores or transfers run into MySQL problems | Remove skip-name-resolve from the MySQL configuration; cPanel says it causes restore problems. |
Frequently asked questions
- Where does WHM store backups?
- In
/backupby default: daily ones in/backup/YYYY-MM-DD/accounts/, weekly and monthly ones underweekly/andmonthly/, oneUSERNAME.tar.gzper account with the compressed type. - Do cPanel backups include databases?
- MySQL and MariaDB, yes, one dump per database. PostgreSQL only with
PSQLBACKUP: 'yes'in/var/cpanel/backups/config;pkgacctincludes both. - Can I keep more backups on S3 than on the server?
- Not from WHM: destinations have no retention of their own, and WHM prunes them. Use bucket versioning with a lifecycle rule.
- Can a cPanel user restore a full backup?
- No. cPanel restores partial backups and single files; a full backup needs WHM or
restorepkg. - How do I back up one cPanel account over SSH?
- As root,
/usr/local/cpanel/scripts/pkgacct USERNAME /homewrites/home/cpmove-USERNAME.tar.gz.
How this was checked
Commands, limits and prices were checked against these official pages, on October 3, 2026:
- cPanel & WHM Documentation: Backup Configuration
- cPanel & WHM Documentation: Backup Retention Behavior
- cPanel & WHM Documentation: How to Troubleshoot a Remote Transport Pruning Failure
- cPanel & WHM Documentation: How to Manage Metadata Settings
- cPanel & WHM Documentation: Backup Tarball Contents
- cPanel & WHM Documentation: System Backups
- cPanel & WHM Documentation: How to Exclude Files From Backups
- cPanel & WHM Documentation: The backup Script
- cPanel & WHM Documentation: The pkgacct Script
- cPanel & WHM Documentation: The restorepkg Script
- cPanel & WHM Documentation: Backup for cPanel
- cPanel & WHM Documentation: Backup Wizard
- cPanel & WHM Documentation: Backup Restoration
- cPanel & WHM Documentation: File and Directory Restoration for WHM
- cPanel & WHM Documentation: Remote Restoration
- cPanel & WHM Documentation: Transfer or Restore a cPanel Account
- cPanel & WHM Documentation: Transfer Tool
- cPanel & WHM Documentation: Transfer Tool, Prepare a Source Server
- cPanel & WHM Documentation: Transfer Tool, Select What to Transfer
- cPanel & WHM Documentation: Transfer Tool, After the Transfer
- cPanel & WHM Documentation: How to Move All cPanel Accounts From One Server to Another