VPS Snaps

How to back up a cPanel & WHM server

In WHM, open Backup Configuration, turn backups on, choose a backup type and how many daily, weekly and monthly copies to keep, and add a remote destination such as Amazon S3, Backblaze B2 or SFTP. For one account, /usr/local/cpanel/scripts/pkgacct writes an archive that restorepkg restores on any cPanel & WHM server. Then prove a restore works on a test server.

9 min readUpdated Checked against official documentation

How WHM backups are organized

An account backup is one archive per cPanel account: home directory (websites and mail), a dump of each MySQL or MariaDB database, DNS zones, SSL certificates, cron jobs and settings. A system backup holds the server's configuration, mostly from /etc, /var/cpanel and /var/named. Compressed backups land in /backup like this:

/backup
/backup/
  2026-10-03/accounts/example.tar.gz            daily, one file per account
  2026-10-03/system/                            system backup
  weekly/2026-09-27/accounts/example.tar.gz
  monthly/2026-10-01/accounts/example.tar.gz
  .meta/example.db                              file index used by restores

Uncompressed backups end in .tar; incremental ones are a directory named after the user.

Turn on scheduled backups

Open WHM » Backup » Backup Configuration. On the Backup Settings tab:

  1. Select Enable Backups. It starts off.
  2. Choose a Backup Type (table below).
  3. Keep Check the Available Disk Space on, with a minimum in % or MB; below it, scheduled backups don't run.
  4. Under Scheduling and Retention, pick Daily Backup days, a Weekly Backup day and Monthly Backup on the 1st, the 15th or both. Each has a Retention: how many to keep, 1 to 9999.
  5. Under Files, select Back up User Accounts and Back up System Files; you need the latter to rebuild the server.
  6. Leave Back up SQL Databases on Per Account Only, which runs mysqldump. The Entire MySQL Directory options copy /var/lib/mysql while MySQL runs; cPanel warns the copy may not restore, and WHM can't restore it for you.
  7. Keep Default Backup Directory at /backup or a separate disk. cPanel doesn't support NFS or CIFS here.
  8. Keep Retain Backups in the Default Backup Directory on. Turned off, WHM deletes local copies after upload and disables File and Directory Restoration.
  9. Click Save Configuration.
Backup TypeTrade-offNote
CompressedLeast disk space, slowestOne .tar.gz per account; works with every destination
UncompressedMore disk space, fasterOne .tar per account
IncrementalHard links between runs save time and spaceRemote copies can only go to an Rsync destination

After a failed run, WHM keeps old backups until the next success, so the count can go over. On a tight disk, select Strictly enforce retention, regardless of backup success, which still keeps one good backup.

Check the saved settings, then run a backup now:

Terminal
grep -E 'BACKUPENABLE|BACKUPACCTS|BACKUPDIR|KEEPLOCAL|PSQLBACKUP' /var/cpanel/backups/config
Terminal
/usr/local/cpanel/bin/backup --force --debug

--debug runs in the foreground and prints progress. --force runs even if today's backups exist. Logs go to /usr/local/cpanel/logs/cpbackup/.

Include PostgreSQL and exclude files

Scheduled backups skip PostgreSQL databases. To include them, change this line as root:

/var/cpanel/backups/config
PSQLBACKUP: 'yes'

To leave paths out, list them in /etc/cpbackup-exclude.conf for all accounts, or in cpbackup-exclude.conf in one user's home directory: one path per line, relative to the home directory, no leading or trailing slash.

/home/example/cpbackup-exclude.conf
public_html/wp-content/cache
tmp

The global file already excludes access-logs, .cpanel/caches and a few more. pkgacct ignores both files.

Send backups off the server

A backup in /backup dies with the disk. On the Additional Destinations tab, pick a type, click Create New Destination, fill in the form and click Save and Validate Destination:

  • Amazon S3: an existing bucket, optional folder, access key ID and secret access key.
  • S3 Compatible: the same plus the endpoint hostname, which must match its TLS certificate and support virtual-hosted-style URLs.
  • Backblaze B2: bucket ID, bucket name, application key ID and application key.
  • SFTP and Rsync: host, port (default 22), user, and a key (recommended; WHM can generate one) or password.
  • Also Google Drive, FTP, WebDAV, Additional Local Directory and Custom (your own script).

Tick Transfer System Backups to this Destination, or only account backups go there. Timeout is 30 to 300 seconds; after two retries WHM emails you and tries again next run.

Destinations have no retention setting of their own: WHM prunes them too, deleting the oldest backups remotely. To keep remote copies longer, or to survive someone deleting them with the key WHM stores, turn on bucket versioning: see Amazon S3 or Backblaze B2.

Give WHM a key limited to its own bucket or prefix. It needs upload and delete rights, because it prunes.

Backups and uploads run in separate queues. If uploads are slower, archives pile up in /backup and can fill the disk.

Back up a single account

pkgacct packages one account into a cpmove archive. As root:

Terminal
/usr/local/cpanel/scripts/pkgacct example /home

This writes /home/cpmove-example.tar.gz; options go before the username. To move an account, both servers need free space of over twice its size, plus 1 GB.

OptionEffect
--skiphomedirLeaves out the home directory, if you copy it separately with rsync
--skipmailLeaves out the mail directory
--skipacctdbLeaves out MySQL and PostgreSQL databases
--splitWrites the archive in parts: cpmove-example.tar.gz.part00001 and so on
--use_backupsStarts from the account's last successful backup, to save time

In cPanel, Files » Backup and Backup Wizard give account owners a full backup (to the home directory, FTP or SCP) and partial downloads. cPanel restores partial backups; only WHM restores a full one.

Check a backup

Test the gzip stream, then list the database dumps inside:

Terminal
gzip -t /backup/2026-10-03/accounts/example.tar.gz && echo OK
Terminal
tar -tzf /backup/2026-10-03/accounts/example.tar.gz | grep -E '(^|/)mysql/.+\.sql$'

The archive holds the home directory under homedir/, one USER_database.sql per database under mysql/, grants in mysql.sql and zones under dnszones/. If an account has databases and the second command prints nothing, read the log in /usr/local/cpanel/logs/cpbackup/; an account near or over its quota can fail this way.

Restore an account or a file

  • WHM » Backup » Backup Restoration restores whole accounts from local backups (or an FTP destination you added), by account or by date. Queue accounts, click Restore, and open View Log for any Completed with warnings.
  • File and Directory Restoration, in WHM and in cPanel, restores single files or directories such as public_html/wp-config.php. It reads local backups only, overwrites existing files, and can't restore .cpanel or mail.
  • WHM » Transfers » Transfer or Restore a cPanel Account restores a cpmove archive or cPanel full backup, on the server or uploaded.

From the shell, restorepkg takes the archive's path or a username:

Terminal
/usr/local/cpanel/scripts/restorepkg /home/cpmove-example.tar.gz

Given a username, it searches /home, /home2, /home3, /root, /usr, /usr/home and /web for cpmove-example.tar.gz, example.tar.gz or a backup-... archive. Don't rename the file or create the account first. --newuser=example2 restores under another name.

For a remote backup, download it (for example with rclone) to the matching dated path, such as /backup/2026-10-03/accounts/example.tar.gz, and it appears in Backup Restoration. With local retention off, use Transfer or Restore a cPanel Account instead.

A restore overwrites what is there. Take a fresh pkgacct archive of the live account first.

Move accounts to another server

On the new server, WHM » Transfers » Transfer Tool logs in to the old one over SSH (port 22, falling back to 2087) as root, or as a user who escalates with su or sudo. cPanel's order for a full move:

  1. Install cPanel & WHM with the same MySQL or MariaDB, PHP and Apache versions and extensions. Update after the move, not before.
  2. Transfer Service Configurations first: EasyApache, Exim, WHM settings (whmconf), database server, Backups and the rest.
  3. Transfer resellers, then other accounts. Live Transfer (on by default) points DNS and mail at the new server, proxies traffic and suspends the old accounts.
  4. After a Live Transfer, keep the old server up for two days.

Two-factor authentication and custom DNS zone templates don't move. Per-user PHP-FPM settings arrive as a .transferred file in /var/cpanel/userdata/USERNAME; rename it and run /scripts/php_fpm_config --rebuild.

The new server needs a valid license (a new installation can use a 15-day trial), and the old license is billed until you cancel it. For cutover timing, see moving a server to a new provider.

What an account backup leaves out

  • Server software and settings: PHP, EasyApache, Exim, Tweak Settings. The system backup keeps many config files, but not the software, and cPanel has no interface to restore it.
  • PostgreSQL databases in scheduled backups, unless PSQLBACKUP is 'yes'.
  • Two-factor authentication.
  • Excluded paths, and files the account neither owns nor can read.
  • Suspended accounts, unless Back up Suspended Accounts is on, and a suspended user's public_ftp always.
  • Anything outside the accounts: root's scripts, /opt, databases no account owns.

Cover those with restic or tar, and track them in a server checklist.

Test a restore

Restore onto a throwaway cPanel server, so nothing collides with live domains:

  1. Build a small server with production's cPanel and MySQL or MariaDB versions.
  2. From production, copy last night's archive to the test server's /home; on the test server, restore it under time.
  3. Request the site from the test server without touching DNS. A 200 or a redirect to HTTPS means it is served.
  4. On the test server, list the databases, then log in to cPanel as the user and open a few files and an email.
  5. Terminate the account and the server.
Terminal
scp /backup/2026-10-03/accounts/example.tar.gz [email protected]:/home/
Terminal
time /usr/local/cpanel/scripts/restorepkg /home/example.tar.gz
Terminal
curl -sI --resolve example.com:80:203.0.113.10 http://example.com/
Terminal
mysql -e "SHOW DATABASES LIKE 'example%'"

The time restorepkg took is the floor for recovering that account. More in testing a restore and RPO and RTO.

Common errors

ErrorFix
Error: Nowhere to back up: no enabled destinations found and retaining local copies is disabled.Turn local retention back on, or enable a destination.
You have enabled BACKUPMOUNT in the /var/cpanel/backups/config file, but there is no mount point that matches ...Default Backup Directory must match the mount point in /etc/fstab exactly.
The system could not prune the "..." directory due to an error.Remote pruning hit its 300-second limit or lacked permission. Delete the directory by hand, use a faster destination, or fix permissions.
The system did not find an account archive for the user "example" ...Pass the full path, or move the file into /home under an accepted name.
One account's backup fails, the rest succeedThe account is near or over its quota. Raise it.
Account restores or transfers run into MySQL problemsRemove skip-name-resolve from the MySQL configuration; cPanel says it causes restore problems.

Frequently asked questions

Where does WHM store backups?
In /backup by default: daily ones in /backup/YYYY-MM-DD/accounts/, weekly and monthly ones under weekly/ and monthly/, one USERNAME.tar.gz per account with the compressed type.
Do cPanel backups include databases?
MySQL and MariaDB, yes, one dump per database. PostgreSQL only with PSQLBACKUP: 'yes' in /var/cpanel/backups/config; pkgacct includes both.
Can I keep more backups on S3 than on the server?
Not from WHM: destinations have no retention of their own, and WHM prunes them. Use bucket versioning with a lifecycle rule.
Can a cPanel user restore a full backup?
No. cPanel restores partial backups and single files; a full backup needs WHM or restorepkg.
How do I back up one cPanel account over SSH?
As root, /usr/local/cpanel/scripts/pkgacct USERNAME /home writes /home/cpmove-USERNAME.tar.gz.

How this was checked

Commands, limits and prices were checked against these official pages, on October 3, 2026: